TCLBANKER Brazilian Banking Trojan — Trojanized Logi AI Prompt Builder DLL Sideload with WhatsApp and Outlook Worm Modules (REF3076) — Threadlinqs Intelligence
As of 2026-05-30, TCLBANKER Brazilian Banking Trojan — Trojanized Logi AI Prompt Builder DLL Sideload with WhatsApp and Outlook Worm Modules (REF3076) is a high-severity malware threat attributed to REF3076 operator, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 31 indicators of compromise.
Threat ID: TL-2026-0469 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: REF3076 operator · FINANCIAL
Elastic Security Labs disclosed TCLBANKER (REF3076), a major evolution of the MAVERICK/SORVEPOTEL Brazilian banking-trojan family that abuses DLL sideloading against the legitimate signed Logitech
TCLBANKER is a Brazilian-targeted banking trojan tracked by Elastic Security Labs as campaign REF3076 and disclosed publicly on 2026-05-07. The campaign is a major iteration of the MAVERICK family (Kaspersky tracking) and SORVEPOTEL (TrendMicro tracking), and shares infrastructure overlap with the Water Saci campaign at the legacy IP 191.96.224.96. The operator demonstrates strong operational maturity through layered anti-analysis, environment-gated payload decryption, signed-binary abuse, and self-propagation across two messaging platforms.
Delivery: victims receive a ZIP (e.g., XXL_21042026-181516.zip) containing an MSI which drops a directory under %LocalAppData%\LogiAI containing a renamed legitimate copy of Logi AI Prompt Builder (LogiAiPromptBuilder.exe, a Flutter desktop application) alongside a malicious screen_retriever_plugin.dll. When the signed Logitech binary loads its DLL search path, the malicious DLL is sideloaded (T1574.002), inheriting the trust of the legitimate signed parent.
Loader anti-analysis: the sideloaded DLL implements six anti-debug checks (PEB BeingDebugged, heap flags, NtQueryInformationProcess ProcessDebugPort and ProcessDebugObjectHandle, hardware debug registers DR0-DR3, and QueryPerformanceCounter/RDTSC timing deltas), five sandbox/VM checks (hypervisor vendor signature for VMware/VirtualBox/KVM/Xen/Parallels/QEMU, ≥64GB disk, ≥2GB RAM, ≥2 logical processors, common analyst usernames), Brazilian geofencing (GetUserGeoID == 0x20, locale 0x0416 pt-BR, timezone offset -2.0), sleep-bypass detection, ETW patching of EtwEventWrite (xor eax,eax / ret), NTDLL unhooking via disk replacement, direct syscall trampolines, and a watchdog enumerating 14 analysis tool process names, 13 debugger/analysis window titles, 9 IDA/CheatEngine/etc. window classes, 12 sandbox modules (SbieDll.dll, cuckoomon.dll, dbeng.dll), and Frida/IDA named-pipes/mutexes, with .text section CRC32 integrity validation. Payload AES-256-CBC keys are derived from a fingerprint hash of the environment, so an incorrect host silently fails decryption.
Banking module (Tcl.Agent): a .NET Reactor-protected component that polls the foreground browser address bar every second using UI Automation (AutomationElement.FromHandle / ValuePattern.Current.Value) across Chrome, Firefox, Edge, Brave, Opera, and Vivaldi. When a victim navigates to one of 59 hard-coded Brazilian banking, fintech, or cryptocurrency domains (XOR+base64 encrypted), the operator is paged and a WPF full-screen, borderless, topmost overlay is rendered, hidden from screen capture via SetWindowDisplayAffinity(WDA_EXCLUDEFROMCAPTURE), with low-level keyboard/mouse hooks (WH_KEYBOARD_LL, WH_MOUSE_LL) blocking Tab/Esc/Alt+F4/Win/PrintScreen/Ctrl/Alt/nav keys plus right- and middle-clicks. Overlay variants include a credential prompt with Brazilian phone-number formatting and rejection of repeating/sequential digit patterns, a vishing screen with breathing animation, operator-templated 15-minute progress sequences, a fake Windows Update screen, and a transparent cutout overlay that exposes the underlying real banking window. Operator C2 opcodes cover registration (2), session control (4-7), screenshot/streaming (16-20), input injection and keylogging (32-41), and file/process/shell/window operations plus credential overlay (48-96).
Worm module (Tcl.WppBot): scans Chromium-family browser profiles for active WhatsApp Web sessions by detecting IndexedDB at https_web.whatsapp.com_0.indexeddb.leveldb, clones the profile to %TEMP%\<GUID>\, launches headless Chromium via Selenium WebDriver (chromedriver resolved by Selenium Manager via a hostfxr.exe binary disguised under %TEMP%\msvc-rt14\bin\), injects bot-detection bypasses (hides navigator.webdriver, fakes chrome.runtime, sets navigator.languages to pt-BR/pt/en-US/en), then injects WPPConnect (WA-JS) to harvest contacts (filtering groups, broadcasts, and non-Brazilian numbers) and broadcast a campaign message with the reconstructed
Weaknesses (CWE)
CWE-427, CWE-114
Target sectors: financial services, banking, fintech, cryptocurrency, consumer
Target regions: Brazil, South America
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 31 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1566, T1218, T1059, T1059, T1106, T1053, T1574, T1140, T1027, T1622