TCLBANKER Brazilian Banking Trojan — Trojanized Logi AI Prompt Builder DLL Sideload with WhatsApp and Outlook Worm Modules (REF3076)
TCLBANKER Brazilian Banking Trojan (TL-2026-0469), also tracked as TCLBANKER, is a high-severity malware campaign, first published 2026-05-07. It is attributed to REF3076 operator with medium confidence, affects Logitech Logi AI Prompt Builder, maps to 25 MITRE ATT&CK techniques (T1010, T1027, T1053), and is covered by 9 detection rules and 31 indicators of compromise.
Key facts for TL-2026-0469
- Threat ID
- TL-2026-0469
- Also known as
- TCLBANKER, REF3076, MAVERICK (predecessor), SORVEPOTEL (predecessor)
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-05-07
- Last reviewed
- 2026-05-07
- Attribution
- REF3076 operator
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- financial services, banking, fintech, cryptocurrency, consumer
- Target regions
- Brazil, South America
- Detection rules
- 9
- Indicators of compromise
- 31
Malware and tooling in TCLBANKER Brazilian Banking Trojan
Malware and tooling: MAVERICK, SORVEPOTEL, TCLBANKER, .NET Reactor, Selenium WebDriver / Selenium Manager, WPPConnect (WA-JS)
Elastic Security Labs disclosed TCLBANKER (REF3076), a major evolution of the MAVERICK/SORVEPOTEL Brazilian banking-trojan family that abuses DLL sideloading against the legitimate signed Logitech application Logi AI Prompt Builder via a malicious screen_retriever_plugin.dll. The loader is heavily environment-gated (anti-debug, anti-VM, ETW/NTDLL patching, Brazilian-Portuguese geo/locale checks) and decrypts two .NET Reactor-protected payloads: a UI Automation banking module that targets 59 Brazilian banking, fintech, and cryptocurrency domains using full-screen WPF social-engineering overlays, plus self-propagating WhatsApp Web (Selenium + WPPConnect) and Outlook (COM automation) worm modules. All C2 and distribution infrastructure is hosted on a single Cloudflare Workers account (ef971a42).
How TCLBANKER Brazilian Banking Trojan works
TCLBANKER is a Brazilian-targeted banking trojan tracked by Elastic Security Labs as campaign REF3076 and disclosed publicly on 2026-05-07. The campaign is a major iteration of the MAVERICK family (Kaspersky tracking) and SORVEPOTEL (TrendMicro tracking), and shares infrastructure overlap with the Water Saci campaign at the legacy IP 191.96.224.96. The operator demonstrates strong operational maturity through layered anti-analysis, environment-gated payload decryption, signed-binary abuse, and self-propagation across two messaging platforms.
Delivery: victims receive a ZIP (e.g., XXL_21042026-181516.zip) containing an MSI which drops a directory under %LocalAppData%\LogiAI containing a renamed legitimate copy of Logi AI Prompt Builder (LogiAiPromptBuilder.exe, a Flutter desktop application) alongside a malicious screen_retriever_plugin.dll. When the signed Logitech binary loads its DLL search path, the malicious DLL is sideloaded (T1574.002), inheriting the trust of the legitimate signed parent.
Loader anti-analysis: the sideloaded DLL implements six anti-debug checks (PEB BeingDebugged, heap flags, NtQueryInformationProcess ProcessDebugPort and ProcessDebugObjectHandle, hardware debug registers DR0-DR3, and QueryPerformanceCounter/RDTSC timing deltas), five sandbox/VM checks (hypervisor vendor signature for VMware/VirtualBox/KVM/Xen/Parallels/QEMU, ≥64GB disk, ≥2GB RAM, ≥2 logical processors, common analyst usernames), Brazilian geofencing (GetUserGeoID == 0x20, locale 0x0416 pt-BR, timezone offset -2.0), sleep-bypass detection, ETW patching of EtwEventWrite (xor eax,eax / ret), NTDLL unhooking via disk replacement, direct syscall trampolines, and a watchdog enumerating 14 analysis tool process names, 13 debugger/analysis window titles, 9 IDA/CheatEngine/etc. window classes, 12 sandbox modules (SbieDll.dll, cuckoomon.dll, dbeng.dll), and Frida/IDA named-pipes/mutexes, with .text section CRC32 integrity validation. Payload AES-256-CBC keys are derived from a fingerprint hash of the environment, so an incorrect host silently fails decryption.
Banking module (Tcl.Agent): a .NET Reactor-protected component that polls the foreground browser address bar every second using UI Automation (AutomationElement.FromHandle / ValuePattern.Current.Value) across Chrome, Firefox, Edge, Brave, Opera, and Vivaldi. When a victim navigates to one of 59 hard-coded Brazilian banking, fintech, or cryptocurrency domains (XOR+base64 encrypted), the operator is paged and a WPF full-screen, borderless, topmost overlay is rendered, hidden from screen capture via SetWindowDisplayAffinity(WDA_EXCLUDEFROMCAPTURE), with low-level keyboard/mouse hooks (WH_KEYBOARD_LL, WH_MOUSE_LL) blocking Tab/Esc/Alt+F4/Win/PrintScreen/Ctrl/Alt/nav keys plus right- and middle-clicks. Overlay variants include a credential prompt with Brazilian phone-number formatting and rejection of repeating/sequential digit patterns, a vishing screen with breathing animation, operator-templated 15-minute progress sequences, a fake Windows Update screen, and a transparent cutout overlay that exposes the underlying real banking window. Operator C2 opcodes cover registration (2), session control (4-7), screenshot/streaming (16-20), input injection and keylogging (32-41), and file/process/shell/window operations plus credential overlay (48-96).
Worm module (Tcl.WppBot): scans Chromium-family browser profiles for active WhatsApp Web sessions by detecting IndexedDB at https_web.whatsapp.com_0.indexeddb.leveldb, clones the profile to %TEMP%\<GUID>\, launches headless Chromium via Selenium WebDriver (chromedriver resolved by Selenium Manager via a hostfxr.exe binary disguised under %TEMP%\msvc-rt14\bin\), injects bot-detection bypasses (hides navigator.webdriver, fakes chrome.runtime, sets navigator.languages to pt-BR/pt/en-US/en), then injects WPPConnect (WA-JS) to harvest contacts (filtering groups, broadcasts, and non-Brazilian numbers) and broadcast a campaign message with the reconstructed TCLBANKER payload as a File object — no disk drop. The Outlook variant attaches via COM (Marshal.GetActiveObject("Outlook.Application")), validates account presence, drops a PowerShell contact harvester at %TEMP%\oc<guid>.ps1, and sends a Portuguese-language NF-e-themed phishing email ("Prezado(a), NFe disponível para impressão") with an HTML "Abrir Nota Fiscal" button linking to arquivos-omie.com. Captured campaign config caps WhatsApp at 3000 messages/session (1-3s delay) and Outlook at 100 messages/session (30-90s delay), and reports progress to /api/progress with control polling at /api/control.
Infrastructure: the entire campaign is hosted on Cloudflare Workers under account ef971a42 — campagna1-api.ef971a42.workers.dev (C2 backend with HMAC-SHA256 handshake key 70e4f943-e323-4484-97d7-35401bf6812c), documents.ef971a42.workers.dev (payload CDN), and mxtestacionamentos.com (WebSocket C2) — alongside phishing/staging domains arquivos-omie.com, documentos-online.com, afonsoferragista.com, doccompartilhe.com, and recebamais.com (registered between 2026-04-11 and 2026-04-22). Persistence is established via a hidden logon-triggered scheduled task named RuntimeOptimizeService and configuration files flutter_engine.cfg / version.hash. Developer artifacts (debug logging at C: emp cl-debug.txt and a tclloader.exe reference in allowlists) suggest the campaign was identified during early operational stages.
MITRE ATT&CK techniques used in TL-2026-0469
Discovery
T1010 Application Window Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1614 System Location Discovery
Defense Evasion
T1027 Obfuscated Files or Information; T1055 Process Injection; T1140 Deobfuscate/Decode Files or Information; T1497 Virtualization/Sandbox Evasion; T1574 Hijack Execution Flow; T1622 Debugger Evasion
Persistence
Collection
T1056 Input Capture; T1113 Screen Capture; T1114 Email Collection; T1115 Clipboard Data; T1185 Browser Session Hijacking
Execution
T1059 Command and Scripting Interpreter; T1106 Native API
Command and Control
T1071 Application Layer Protocol; T1102 Web Service; T1105 Ingress Tool Transfer
stealth
T1218 System Binary Proxy Execution
Impact
Initial Access
defense-impairment
Affected products and versions in TCLBANKER Brazilian Banking Trojan
- Logitech — Logi AI Prompt Builder
Vulnerable versions: abused as signed sideload host (no version disclosed) - Microsoft — Outlook (Desktop)
Vulnerable versions: any version with COM automation enabled - Multiple — Chromium browsers (Chrome, Edge, Brave, Opera, Vivaldi) and Firefox
Vulnerable versions: all current versions — abused via UI Automation and profile cloning
Remediation for TCLBANKER Brazilian Banking Trojan
Patches
- No vendor patch — TCLBANKER abuses a legitimate signed Logitech application; track Logitech for any future hardening of its DLL search behavior
Immediate actions
- Block all Cloudflare Workers domains under account ef971a42 at perimeter and DNS (campagna1-api.ef971a42.workers.dev, documents.ef971a42.workers.dev) and the WebSocket C2 mxtestacionamentos.com
- Block phishing/staging domains arquivos-omie.com, documentos-online.com, afonsoferragista.com, doccompartilhe.com, recebamais.com
- Block legacy infrastructure IP 191.96.224.96 at egress
- Hash-block the four screen_retriever_plugin.dll and ZIP SHA-256 indicators in EDR/NGAV
- Quarantine any %LocalAppData%\LogiAI directory not deployed by IT
- Disable or uninstall Logi AI Prompt Builder where it is not required
- Force-close active WhatsApp Web sessions on user endpoints and rotate web sessions for users in Brazil
- Alert on creation of scheduled task RuntimeOptimizeService with logon trigger
- Reset banking/fintech/crypto credentials for any Brazil-resident user with confirmed exposure
Workarounds
- Where Logi AI Prompt Builder is required, enforce installation only under %ProgramFiles% (admin-writable) and deny execution from %LocalAppData%
- Restrict outbound HTTPS to *.workers.dev to a minimum allowlist or full block for endpoints that do not require it
Longer-term hardening
- Deploy EDR with behavioral detection for DLL sideloading against signed third-party binaries (parent = signed vendor EXE, child loads unsigned DLL from user-writable path)
- Application allowlisting (WDAC / AppLocker) to deny execution of unsigned DLLs from %LocalAppData% by signed vendor binaries
- Block msiexec.exe execution of MSI files from user-writable paths via attack-surface-reduction rules
- Monitor UI Automation API usage by non-accessibility processes targeting browser windows
- Enable PowerShell Script Block Logging and alert on COM automation of Outlook.Application from non-Office parents
- Roll out browser policies that disable Selenium-style automation extensions on managed endpoints
- Deploy DNS-layer detection for newly observed Cloudflare Workers subdomains used as C2
- User awareness training on Brazilian NF-e and orçamento (quotation) phishing lures
Weaknesses (CWE) in TCLBANKER Brazilian Banking Trojan
CWE-427, CWE-114
Timeline of TCLBANKER Brazilian Banking Trojan
- TrendMicro publishes analysis of self-propagating WhatsApp banking malware family later linked as a predecessor to TCLBANKER, tracked as SORVEPOTEL.
- Kaspersky publishes analysis of the MAVERICK Brazilian banking trojan distributed via WhatsApp — the direct lineage of TCLBANKER.
- First REF3076 phishing/staging domain documentos-online.com first observed in passive DNS.
- Phishing landing arquivos-omie.com registered; doccompartilhe.com first seen the same day.
- Captured TCLBANKER campaign configuration last updated (15:54:07 UTC) — message templates, file URL on documents.ef971a42.workers.dev, and rate limits set.
- Phishing/staging domain recebamais.com first observed.
- Sample lure archive XXL_21042026-181516.zip built (date encoded in filename).
- Phishing/staging domain afonsoferragista.com first observed.
- Threat ingested into Threadlinqs Intelligence as TL-2026-0469 for blue-team detection authoring.
- Elastic Security Labs publishes the TCLBANKER REF3076 report by Jia Yu Chan, Daniel Stepanic, Seth Goodwin, and Terrance DeJesus, including IOCs and YARA rule Windows.Trojan.TCLBanker.
- As of 2026-05-29, TCLBANKER (REF3076) remains an active financial threat: disclosed by Elastic on 2026-05-07 and confirmed as the Water Saci actor, whose MAVERICK/SORVEPOTEL WhatsApp/Outlook banking-trojan campaign against Brazil is still ongoing and evolving with no takedown, arrest, or patch (signed Logitech sideload, rotating Cloudflare Workers C2).
Sources cited for TCLBANKER Brazilian Banking Trojan
- TCLBANKER: Brazilian Banking Trojan Spreading via WhatsApp and Outlook
- TCLBANKER IOC and target domain gist (Jia Yu Chan)
- MAVERICK banker distributing via WhatsApp
- Self-propagating malware spreads via WhatsApp (SORVEPOTEL)
- MITRE ATT&CK T1574.002 — Hijack Execution Flow: DLL Side-Loading
- MITRE ATT&CK T1218.007 — System Binary Proxy Execution: Msiexec
- MITRE ATT&CK T1497 — Virtualization/Sandbox Evasion
Threats related to TCLBANKER Brazilian Banking Trojan
- The TTF Trap: Global Phishing Campaign Delivers Lua-Based Loader for Agent Tesla, Remcos RAT, XWorm
- MedusaHVNC: Malware-as-a-Service RAT Uses Hidden Desktop (hVNC) to Hijack Live Browser Sessions and Steal Credentials
- MLTBackdoor (Backdoor.Mistic): KongTuke-Linked Windows Backdoor Delivered via ClickFix and mpextms.exe DLL Sideloading
- OnionDrop Loader Campaign Delivers LegionLoader/CurlyGate, CGrabber, and Vidar via DLL Sideloading and gainmsg[.]com C2
- MedusaHVNC — Hidden Virtual Desktop RAT with AMSI/ETW Bypass and Multi-Browser Session Hijacking
- Horabot 'Sapecar' Banking Trojan Campaign Targeting Mexico with Multi-Stage Loader and Email Spreader
Detection coverage for TL-2026-0469
As of 2026-05-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0469 across Splunk SPL, Microsoft KQL and Sigma, covering 31 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.