TCLBANKER Brazilian Banking Trojan — Trojanized Logi AI Prompt Builder DLL Sideload with WhatsApp and Outlook Worm Modules (REF3076)

TCLBANKER Brazilian Banking Trojan (TL-2026-0469), also tracked as TCLBANKER, is a high-severity malware campaign, first published 2026-05-07. It is attributed to REF3076 operator with medium confidence, affects Logitech Logi AI Prompt Builder, maps to 25 MITRE ATT&CK techniques (T1010, T1027, T1053), and is covered by 9 detection rules and 31 indicators of compromise.

Key facts for TL-2026-0469

Threat ID
TL-2026-0469
Also known as
TCLBANKER, REF3076, MAVERICK (predecessor), SORVEPOTEL (predecessor)
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-05-07
Last reviewed
2026-05-07
Attribution
REF3076 operator
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
financial services, banking, fintech, cryptocurrency, consumer
Target regions
Brazil, South America
Detection rules
9
Indicators of compromise
31

Malware and tooling in TCLBANKER Brazilian Banking Trojan

Malware and tooling: MAVERICK, SORVEPOTEL, TCLBANKER, .NET Reactor, Selenium WebDriver / Selenium Manager, WPPConnect (WA-JS)

Elastic Security Labs disclosed TCLBANKER (REF3076), a major evolution of the MAVERICK/SORVEPOTEL Brazilian banking-trojan family that abuses DLL sideloading against the legitimate signed Logitech application Logi AI Prompt Builder via a malicious screen_retriever_plugin.dll. The loader is heavily environment-gated (anti-debug, anti-VM, ETW/NTDLL patching, Brazilian-Portuguese geo/locale checks) and decrypts two .NET Reactor-protected payloads: a UI Automation banking module that targets 59 Brazilian banking, fintech, and cryptocurrency domains using full-screen WPF social-engineering overlays, plus self-propagating WhatsApp Web (Selenium + WPPConnect) and Outlook (COM automation) worm modules. All C2 and distribution infrastructure is hosted on a single Cloudflare Workers account (ef971a42).

How TCLBANKER Brazilian Banking Trojan works

TCLBANKER is a Brazilian-targeted banking trojan tracked by Elastic Security Labs as campaign REF3076 and disclosed publicly on 2026-05-07. The campaign is a major iteration of the MAVERICK family (Kaspersky tracking) and SORVEPOTEL (TrendMicro tracking), and shares infrastructure overlap with the Water Saci campaign at the legacy IP 191.96.224.96. The operator demonstrates strong operational maturity through layered anti-analysis, environment-gated payload decryption, signed-binary abuse, and self-propagation across two messaging platforms.

Delivery: victims receive a ZIP (e.g., XXL_21042026-181516.zip) containing an MSI which drops a directory under %LocalAppData%\LogiAI containing a renamed legitimate copy of Logi AI Prompt Builder (LogiAiPromptBuilder.exe, a Flutter desktop application) alongside a malicious screen_retriever_plugin.dll. When the signed Logitech binary loads its DLL search path, the malicious DLL is sideloaded (T1574.002), inheriting the trust of the legitimate signed parent.

Loader anti-analysis: the sideloaded DLL implements six anti-debug checks (PEB BeingDebugged, heap flags, NtQueryInformationProcess ProcessDebugPort and ProcessDebugObjectHandle, hardware debug registers DR0-DR3, and QueryPerformanceCounter/RDTSC timing deltas), five sandbox/VM checks (hypervisor vendor signature for VMware/VirtualBox/KVM/Xen/Parallels/QEMU, ≥64GB disk, ≥2GB RAM, ≥2 logical processors, common analyst usernames), Brazilian geofencing (GetUserGeoID == 0x20, locale 0x0416 pt-BR, timezone offset -2.0), sleep-bypass detection, ETW patching of EtwEventWrite (xor eax,eax / ret), NTDLL unhooking via disk replacement, direct syscall trampolines, and a watchdog enumerating 14 analysis tool process names, 13 debugger/analysis window titles, 9 IDA/CheatEngine/etc. window classes, 12 sandbox modules (SbieDll.dll, cuckoomon.dll, dbeng.dll), and Frida/IDA named-pipes/mutexes, with .text section CRC32 integrity validation. Payload AES-256-CBC keys are derived from a fingerprint hash of the environment, so an incorrect host silently fails decryption.

Banking module (Tcl.Agent): a .NET Reactor-protected component that polls the foreground browser address bar every second using UI Automation (AutomationElement.FromHandle / ValuePattern.Current.Value) across Chrome, Firefox, Edge, Brave, Opera, and Vivaldi. When a victim navigates to one of 59 hard-coded Brazilian banking, fintech, or cryptocurrency domains (XOR+base64 encrypted), the operator is paged and a WPF full-screen, borderless, topmost overlay is rendered, hidden from screen capture via SetWindowDisplayAffinity(WDA_EXCLUDEFROMCAPTURE), with low-level keyboard/mouse hooks (WH_KEYBOARD_LL, WH_MOUSE_LL) blocking Tab/Esc/Alt+F4/Win/PrintScreen/Ctrl/Alt/nav keys plus right- and middle-clicks. Overlay variants include a credential prompt with Brazilian phone-number formatting and rejection of repeating/sequential digit patterns, a vishing screen with breathing animation, operator-templated 15-minute progress sequences, a fake Windows Update screen, and a transparent cutout overlay that exposes the underlying real banking window. Operator C2 opcodes cover registration (2), session control (4-7), screenshot/streaming (16-20), input injection and keylogging (32-41), and file/process/shell/window operations plus credential overlay (48-96).

Worm module (Tcl.WppBot): scans Chromium-family browser profiles for active WhatsApp Web sessions by detecting IndexedDB at https_web.whatsapp.com_0.indexeddb.leveldb, clones the profile to %TEMP%\<GUID>\, launches headless Chromium via Selenium WebDriver (chromedriver resolved by Selenium Manager via a hostfxr.exe binary disguised under %TEMP%\msvc-rt14\bin\), injects bot-detection bypasses (hides navigator.webdriver, fakes chrome.runtime, sets navigator.languages to pt-BR/pt/en-US/en), then injects WPPConnect (WA-JS) to harvest contacts (filtering groups, broadcasts, and non-Brazilian numbers) and broadcast a campaign message with the reconstructed TCLBANKER payload as a File object — no disk drop. The Outlook variant attaches via COM (Marshal.GetActiveObject("Outlook.Application")), validates account presence, drops a PowerShell contact harvester at %TEMP%\oc<guid>.ps1, and sends a Portuguese-language NF-e-themed phishing email ("Prezado(a), NFe disponível para impressão") with an HTML "Abrir Nota Fiscal" button linking to arquivos-omie.com. Captured campaign config caps WhatsApp at 3000 messages/session (1-3s delay) and Outlook at 100 messages/session (30-90s delay), and reports progress to /api/progress with control polling at /api/control.

Infrastructure: the entire campaign is hosted on Cloudflare Workers under account ef971a42 — campagna1-api.ef971a42.workers.dev (C2 backend with HMAC-SHA256 handshake key 70e4f943-e323-4484-97d7-35401bf6812c), documents.ef971a42.workers.dev (payload CDN), and mxtestacionamentos.com (WebSocket C2) — alongside phishing/staging domains arquivos-omie.com, documentos-online.com, afonsoferragista.com, doccompartilhe.com, and recebamais.com (registered between 2026-04-11 and 2026-04-22). Persistence is established via a hidden logon-triggered scheduled task named RuntimeOptimizeService and configuration files flutter_engine.cfg / version.hash. Developer artifacts (debug logging at C: emp cl-debug.txt and a tclloader.exe reference in allowlists) suggest the campaign was identified during early operational stages.

MITRE ATT&CK techniques used in TL-2026-0469

Discovery

T1010 Application Window Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1614 System Location Discovery

Defense Evasion

T1027 Obfuscated Files or Information; T1055 Process Injection; T1140 Deobfuscate/Decode Files or Information; T1497 Virtualization/Sandbox Evasion; T1574 Hijack Execution Flow; T1622 Debugger Evasion

Persistence

T1053 Scheduled Task/Job

Collection

T1056 Input Capture; T1113 Screen Capture; T1114 Email Collection; T1115 Clipboard Data; T1185 Browser Session Hijacking

Execution

T1059 Command and Scripting Interpreter; T1106 Native API

Command and Control

T1071 Application Layer Protocol; T1102 Web Service; T1105 Ingress Tool Transfer

stealth

T1218 System Binary Proxy Execution

Impact

T1529 System Shutdown/Reboot

Initial Access

T1566 Phishing

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in TCLBANKER Brazilian Banking Trojan

  • Logitech — Logi AI Prompt Builder
    Vulnerable versions: abused as signed sideload host (no version disclosed)
  • Microsoft — Outlook (Desktop)
    Vulnerable versions: any version with COM automation enabled
  • Multiple — Chromium browsers (Chrome, Edge, Brave, Opera, Vivaldi) and Firefox
    Vulnerable versions: all current versions — abused via UI Automation and profile cloning

Remediation for TCLBANKER Brazilian Banking Trojan

Patches

  • No vendor patch — TCLBANKER abuses a legitimate signed Logitech application; track Logitech for any future hardening of its DLL search behavior

Immediate actions

  • Block all Cloudflare Workers domains under account ef971a42 at perimeter and DNS (campagna1-api.ef971a42.workers.dev, documents.ef971a42.workers.dev) and the WebSocket C2 mxtestacionamentos.com
  • Block phishing/staging domains arquivos-omie.com, documentos-online.com, afonsoferragista.com, doccompartilhe.com, recebamais.com
  • Block legacy infrastructure IP 191.96.224.96 at egress
  • Hash-block the four screen_retriever_plugin.dll and ZIP SHA-256 indicators in EDR/NGAV
  • Quarantine any %LocalAppData%\LogiAI directory not deployed by IT
  • Disable or uninstall Logi AI Prompt Builder where it is not required
  • Force-close active WhatsApp Web sessions on user endpoints and rotate web sessions for users in Brazil
  • Alert on creation of scheduled task RuntimeOptimizeService with logon trigger
  • Reset banking/fintech/crypto credentials for any Brazil-resident user with confirmed exposure

Workarounds

  • Where Logi AI Prompt Builder is required, enforce installation only under %ProgramFiles% (admin-writable) and deny execution from %LocalAppData%
  • Restrict outbound HTTPS to *.workers.dev to a minimum allowlist or full block for endpoints that do not require it

Longer-term hardening

  • Deploy EDR with behavioral detection for DLL sideloading against signed third-party binaries (parent = signed vendor EXE, child loads unsigned DLL from user-writable path)
  • Application allowlisting (WDAC / AppLocker) to deny execution of unsigned DLLs from %LocalAppData% by signed vendor binaries
  • Block msiexec.exe execution of MSI files from user-writable paths via attack-surface-reduction rules
  • Monitor UI Automation API usage by non-accessibility processes targeting browser windows
  • Enable PowerShell Script Block Logging and alert on COM automation of Outlook.Application from non-Office parents
  • Roll out browser policies that disable Selenium-style automation extensions on managed endpoints
  • Deploy DNS-layer detection for newly observed Cloudflare Workers subdomains used as C2
  • User awareness training on Brazilian NF-e and orçamento (quotation) phishing lures

Weaknesses (CWE) in TCLBANKER Brazilian Banking Trojan

CWE-427, CWE-114

Timeline of TCLBANKER Brazilian Banking Trojan

  • TrendMicro publishes analysis of self-propagating WhatsApp banking malware family later linked as a predecessor to TCLBANKER, tracked as SORVEPOTEL.
  • Kaspersky publishes analysis of the MAVERICK Brazilian banking trojan distributed via WhatsApp — the direct lineage of TCLBANKER.
  • First REF3076 phishing/staging domain documentos-online.com first observed in passive DNS.
  • Phishing landing arquivos-omie.com registered; doccompartilhe.com first seen the same day.
  • Captured TCLBANKER campaign configuration last updated (15:54:07 UTC) — message templates, file URL on documents.ef971a42.workers.dev, and rate limits set.
  • Phishing/staging domain recebamais.com first observed.
  • Sample lure archive XXL_21042026-181516.zip built (date encoded in filename).
  • Phishing/staging domain afonsoferragista.com first observed.
  • Threat ingested into Threadlinqs Intelligence as TL-2026-0469 for blue-team detection authoring.
  • Elastic Security Labs publishes the TCLBANKER REF3076 report by Jia Yu Chan, Daniel Stepanic, Seth Goodwin, and Terrance DeJesus, including IOCs and YARA rule Windows.Trojan.TCLBanker.
  • As of 2026-05-29, TCLBANKER (REF3076) remains an active financial threat: disclosed by Elastic on 2026-05-07 and confirmed as the Water Saci actor, whose MAVERICK/SORVEPOTEL WhatsApp/Outlook banking-trojan campaign against Brazil is still ongoing and evolving with no takedown, arrest, or patch (signed Logitech sideload, rotating Cloudflare Workers C2).

Sources cited for TCLBANKER Brazilian Banking Trojan

Threats related to TCLBANKER Brazilian Banking Trojan

Detection coverage for TL-2026-0469

As of 2026-05-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0469 across Splunk SPL, Microsoft KQL and Sigma, covering 31 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats