TCLBANKER is a Windows-focused Brazilian banking trojan tracked as REF3076 and assessed as a major evolution of the MAVERICK/SORVEPOTEL ecosystem. It targets Brazilian banking, fintech, and cryptocurrency services. Initial infection uses a trojanized installer masquerading as Logitech Logi AI Prompt Builder, which abuses DLL sideloading to execute a protected loader and deploy banking and self-propagating worm components.
The loader performs extensive anti-debugging, anti-virtualization, sandbox, and security-tool checks, geofences execution to Brazilian victim environments, removes user-mode hooks, suppresses user-mode ETW telemetry, and uses environment-derived payload decryption. The banking component persists via a scheduled task, monitors browser URLs in major Windows browsers, and activates remote command-and-control when a targeted financial service is visited. Operator capabilities include screen capture and streaming, remote mouse and keyboard control, keylogging, clipboard manipulation, filesystem and process enumeration, shell execution, window management, reboot, and self-removal.
TCLBANKER employs full-screen WPF overlays that impersonate banking prompts, support interactions, software-update screens, and other workflow elements to collect credentials, PINs, telephone numbers, and security codes. Some overlays are excluded from local screen capture, allowing operators to observe the real desktop while reducing visibility of the fraudulent interface in screenshots or screen-sharing sessions.
Its worm functionality propagates through hijacked authenticated WhatsApp Web sessions and Microsoft Outlook automation. The WhatsApp component clones browser session data and automates messaging to contacts, while the Outlook component harvests contacts and recent correspondents and sends phishing messages from the victim's configured account. This propagation model abuses trusted victim identities to distribute malicious links or attachments. The campaign relies on cloud-hosted infrastructure for command and control, payload delivery, updates, and message campaign configuration.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Elastic Security Labs identified a new Brazilian banking trojan that we are tracking as TCLBANKER... The campaign... features a loader... that deploys two embedded .NET Reactor-protected modules: a full-featured banking trojan and a worm module for self-propagation.
37 distinct techniques documented for this family, organized by ATT&CK tactic.
It then opens a hidden browser window, bypasses bot detection, and sends phishing messages and the malware file directly to the victim’s contacts.
the banking trojan ... proceeds to establish persistence using a scheduled task
Opcode 67 provides shell command execution through cmd.exe /c; the updater also launches a self-deleting batch script through hidden cmd.exe.
The loader generates syscall trampolines for NtQueryInformationProcess, NtSetInformationThread, NtAllocateVirtualMemory, and NtProtectVirtualMemory.
The loader implements string encryption and encrypted payloads, while Tcl.Agent and Tcl.WppBot are protected with .NET Reactor.
The observed infection chain bundles a malicious MSI installer inside a ZIP file. These MSI installer packages are abusing a signed Logitech program called Logi AI Prompt Builder.
Process Injection is listed in the campaign's MITRE ATT&CK technique mapping.
TCLBANKER derives an AES-256 CBC key and IV using hard-coded constants and the environmental hash, decrypts the embedded payload with BCryptDecrypt(), and decompresses it with LZNT1.
The self-update batch script executes msiexec /i /qn REINSTALLMODE=amus for silent installation.
Before it fully unpacks, it checks whether the computer is running in a security sandbox. It looks for debugging tools, virtual machines, and specific antivirus software.
The malware checks hypervisor vendor signatures, disk capacity, RAM, processor count, and generic sandbox or malware-analysis usernames.
TCLBANKER sleeps for 500 ms and exits if fewer than 450 ms elapsed, detecting sandboxes or emulation frameworks that accelerate Sleep.
The watchdog uses GetWindowTextW() and FindWindowW() to identify analyst tool titles and window classes; opcode 80 enumerates visible windows.
The watchdog performs process enumeration via CreateToolhelp32Snapshot() and searches for analysis-tool process names; opcode 65 retrieves running-process information.
The environment checks retrieve system disk, memory, CPU, username, geographic, and locale information; the initial beacon includes machine name and OS version.
enabling the operator to perform a broad range of tasks - Manage files and processes Enumerate running processes List visible windows
Before it fully unpacks, it checks whether the computer is running in a security sandbox. It looks for debugging tools, virtual machines, and specific antivirus software.
The malware checks hypervisor vendor signatures, disk capacity, RAM, processor count, and generic sandbox or malware-analysis usernames.
TCLBANKER sleeps for 500 ms and exits if fewer than 450 ms elapsed, detecting sandboxes or emulation frameworks that accelerate Sleep.
a URL monitor that extracts the current URL from the foreground browser's address bar using UI Automation
The user is forced to enter their security codes or personal identification numbers directly into the hacker’s fake screen.
enabling the operator to perform a broad range of tasks - ... Launch a keylogger
enabling the operator to perform a broad range of tasks - Capture screenshots Start/stop screen streaming
enabling the operator to perform a broad range of tasks - Manipulate clipboard
When a match is found, the malware connects to a remote server.
When a victim opens a monitored banking domain, the agent establishes a WebSocket connection to wss://mxtestacionamentos[.]com/ws; campaign APIs use HTTPS endpoints.
20 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android banking trojan family targeting banking and cryptocurrency users in Brazil, using self-propagation, evasion, and MaaS-style distribution.
Android banking trojan family targeting banking and cryptocurrency users in Brazil, using self-propagation, evasion, and MaaS-style distribution.
Named in the malware/tools list as a RAT; no further detail is provided in the content.
Brazilian banking trojan that uses DLL side-loading via a legitimate signed Logitech application to load a malicious component, performs anti-sandbox and anti-analysis checks, verifies the victim is in Brazil, monitors browsers for targeted banking, fintech, and cryptocurrency sites, and steals credentials/PINs through full-screen phishing overlays. It also includes worm-like propagation through WhatsApp Web session cloning and Microsoft Outlook COM automation, while using Cloudflare Workers and related cloud infrastructure for C2 and file hosting.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.