Home Cyber Security News Self-Propagating TCLBANKER Campaign Targets Users via WhatsApp and Outlook

Self-Propagating TCLBANKER Campaign Targets Users via WhatsApp and Outlook

0
TCLBANKER Spreads Through WhatsApp

A sophisticated new Brazilian banking trojan that uses advanced evasion techniques and self-propagating worm modules to target financial platforms.

Tracked under the REF3076 campaign, this malware represents a major evolution of the older MAVERICK and SORVEPOTEL families, leveraging trusted communication channels such as WhatsApp and Microsoft Outlook to distribute its payload rapidly.

TCLBANKER Spreads Through WhatsApp

The infection sequence begins by abusing a legitimately signed Logitech application, the Logi AI Prompt Builder, to execute a malicious payload via DLL sideloading.

Once active, the TCLBANKER loader heavily relies on environment-gated payload decryption to evade detection.

By evaluating system disk information, running processes, debugging tools, and verifying that the system language is set to Brazilian Portuguese, the malware generates a unique environment hash.

File directory contents showing a malicious DLL (Source: elastic)

If the malware detects a security sandbox or analysis tool, the generated hash will be incorrect, causing the payload to fail to decrypt and halt execution entirely silently.

Furthermore, a dedicated watchdog subsystem continuously scans for analysis frameworks, ensuring the malware remains hidden from researchers while establishing persistence through hidden scheduled tasks.

Patching via EtwEventWrite (Source: elastic)

Once the primary banking trojan is deployed, it actively monitors the victim’s foreground web browser using user interface automation.

The URL monitor specifically targets major browsers, including Google Chrome, Mozilla Firefox,

Microsoft Edge, Brave, Opera, and Vivaldi the malware searches for connections to 59 different Brazilian banking, cryptocurrency, and financial technology domains.

When a victim navigates to one of these targeted sites, the malware initializes a secure WebSocket command-and-control session.

Decryption derivation function using gated hash value (Source: elastic)

The most dangerous feature of this stage is its custom full-screen overlay framework, designed to execute operator-driven social engineering attacks.

According to Elastic research, the rapid spread of TCLBANKER is driven by its secondary worm module which operates through two distinct spam agents that abuse trusted communication channels.

The first agent functions as a WhatsApp bot that specifically targets Chromium-based browsers on the infected machine.

It searches for authenticated WhatsApp Web sessions and clones the necessary browser profiles. It uses a hidden browser instance to hijack the account silently. To ensure success, it injects JavaScript to bypass bot-detection frameworks.

OpcodeCapability SummaryTechnical Description
2InitializationRegistration ACK, starts the Task Manager killer to prevent victim interference.
4DisconnectGraceful WebSocket disconnect.
5Suicide (Kill All)Kills all sibling processes and exits.
6Reboot SystemForced reboot (shutdown.exe /r /t 0 /f).

It waits to verify that the chat interface loads correctly without prompting for a QR code scan.

The malware then harvests the victim’s contacts and dispatches localized phishing messages containing the trojanized installer.

By sending malicious links directly from the victim’s account to their personal contacts, attackers bypass traditional security gateways and leverage the existing trust between individuals.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

NO COMMENTS

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Exit mobile version