# TCLBANKER: New Brazilian Banking Trojan Weaponizes WhatsApp and Outlook for Mass Financial Theft
A previously undocumented Brazilian banking trojan has emerged as a sophisticated threat to financial institutions and customers across Latin America and beyond. Dubbed TCLBANKER and tracked by Elastic Security Labs under the designation REF3076, the malware represents a significant evolution of the Maverick banking trojan family and demonstrates the continued sophistication of financially motivated threat actors.
## The Threat
Threat hunters have confirmed that TCLBANKER targets at least 59 banking, fintech, and cryptocurrency platforms, making it one of the more ambitious banking trojans observed in recent campaigns. The malware combines a multi-layered infection architecture with advanced evasion techniques, leveraging both worm-like propagation capabilities and interactive remote access functionality to drain victim accounts and steal credentials.
The most alarming feature is its self-propagating mechanism: TCLBANKER uses compromised WhatsApp Web sessions and Microsoft Outlook access to spread itself automatically to a victim's contacts, creating a viral distribution channel that bypasses traditional security perimeters. This worm component, inherited from its Maverick predecessor, ensures that initial compromises can rapidly expand into wider organizational and personal network infections.
## Background and Context
TCLBANKER is assessed as a major update to Maverick, a banking trojan family previously documented by threat intelligence researchers. The malware campaign is attributed to Water Saci, a threat cluster identified by Trend Micro that has maintained consistent focus on financial targets across Brazilian institutions.
The evolution from Maverick to TCLBANKER reflects a pattern common among financially motivated threat groups: incremental improvements in evasion, anti-analysis capabilities, and target coverage. Previous versions of Maverick relied on the SORVEPOTEL worm component to spread via WhatsApp. TCLBANKER incorporates similar spreading functionality while adding Outlook propagation and more robust defensive mechanisms designed to evade detection and analysis.
This generational update suggests an active, well-resourced threat actor with continued investment in banking malware development—typical of organized cybercriminal operations operating from or targeting Brazilian financial systems.
## Technical Details: A Multi-Layered Attack Chain
Security researchers from Elastic Security Labs—Jia Yu Chan, Daniel Stepanic, Seth Goodwin, and Terrance DeJesus—documented the complete infection chain and highlighted the trojan's sophisticated architecture.
### Initial Infection and DLL Side-Loading
The attack begins with a malicious MSI installer bundled inside a ZIP file. The MSI package abuses a legitimately signed Logitech program called Logi AI Prompt Builder to achieve execution. This technique, known as DLL side-loading, exploits the trust placed in legitimate signed executables by Windows security mechanisms.
The malicious DLL ("screen_retriever_plugin.dll") acts as a loader and incorporates a comprehensive anti-analysis subsystem. The loader includes multiple defensive checks:
| Defense Mechanism | Purpose |
|---|---|
| Loader validation | Only executes if loaded by logiaipromptbuilder.exe or tclloader.exe |
| Hook removal | Strips usermode hooks from ntdll.dll placed by endpoint security |
| ETW disabling | Disables Event Tracing for Windows telemetry collection |
| Debugger detection | Identifies active debuggers and analysis tools |
| Sandbox detection | Detects virtual environments and analysis sandboxes |
| Antivirus evasion | Identifies and avoids running in monitored environments |
### Environment Fingerprinting and Decryption
The loader generates three separate fingerprints based on:
These fingerprints are combined to create an environment hash value used to decrypt the embedded payload. If analysis tools are detected (such as a debugger), the hash becomes incorrect, and the payload fails to decrypt—effectively killing execution in analysis environments. This technique is highly effective at preventing automated sandbox analysis and manual reverse engineering.
### The Banking Trojan Module
Once the environmental checks pass, TCLBANKER's main banking trojan module activates. The malware:
1. Verifies Brazilian system location before proceeding with infection
2. Establishes persistence via Windows scheduled tasks
3. Beacons to command servers with system information via HTTP POST requests
4. Monitors browser activity in real-time using UI Automation to capture URLs from popular browsers (Chrome, Firefox, Edge, Brave, Opera, Vivaldi)
5. Compares URLs against a hard-coded list of targeted financial institutions
When a targeted banking URL is detected, TCLBANKER establishes a WebSocket connection to a remote command server and enters a dispatch loop, enabling operators to execute extensive capabilities:
### Credential Harvesting Through Full-Screen Overlays
TCLBANKER deploys a Windows Presentation Foundation (WPF)-based overlay framework to conduct sophisticated social engineering attacks. The overlays are designed to:
This layered approach combines technical remote access with social engineering, significantly increasing the likelihood of successful credential theft.
### Worm Propagation Module
Simultaneously with banking operations, the loader's worm component propagates TCLBANKER through:
This dual-vector propagation mechanism ensures rapid spread within both personal and professional networks, creating exponential growth in the infection footprint.
## Implications for Financial Institutions and Users
TCLBANKER represents a significant threat to multiple sectors:
For Banks and Financial Services: The targeting of 59+ financial institutions indicates systematic reconnaissance and continued development against specific targets. The combination of remote access and social engineering makes traditional security controls insufficient.
For Cryptocurrency Platforms: Inclusion of crypto exchanges in the target list demonstrates threat actor interest in high-value digital asset theft, a growing trend among financially motivated groups.
For Enterprise Organizations: The worm propagation via Outlook means that compromised corporate email systems could rapidly distribute TCLBANKER across entire organizations, affecting both employees and business partners.
For Individual Users: End users in Brazil and potentially other regions are at risk of financial account compromise, credential theft, and identity fraud.
## Recommendations
Organizations and individuals should implement the following defensive measures:
For Financial Institutions:
For Enterprise Security Teams:
For End Users:
---
## HackWire Analysis
TCLBANKER's emergence highlights a critical shift in banking trojan sophistication: the integration of legitimate software exploitation with industrial-scale social engineering. The abuse of Logitech's signed executable is particularly significant because it demonstrates threat actors' understanding that organizations increasingly trust supply chains—and legitimate software becomes the primary attack surface when malicious binaries are blocked.
The worm propagation via WhatsApp and Outlook is the real story here. While previous banking trojans focused on individual compromise, TCLBANKER's design patterns suggest operators expect exponential spread. This isn't a boutique espionage tool; it's built for volume. A single compromised corporate email account could infect dozens of employees and hundreds of external contacts within hours.
What's striking is the environment fingerprinting technique. By ensuring the malware only operates on Brazilian systems, threat actors are maximizing their target precision while simultaneously frustrating researchers who might analyze the sample from outside Brazil. This level of operational security suggests a mature threat group with sufficient resources to maintain separate Brazilian testing infrastructure.
For defenders, the most actionable insight is that overlay-based social engineering remains devastatingly effective. The fake Windows Update prompts will work. Technical controls alone won't stop determined users from entering credentials into convincing fake login screens. This isn't a technology problem requiring a technical solution—it's a human problem requiring behavioral training, and organizations investing heavily in technical controls while neglecting security culture will lose.
The timing also matters: as Latin American crypto adoption accelerates and regional fintech innovation intensifies, banking trojans are rapidly evolving to match the attack surface expansion. Water Saci and similar groups are clearly monitoring what targets are most valuable and adapting their tools accordingly. Organizations in Brazil and neighboring countries should expect this threat to persist and evolve for the foreseeable future.
— HackWire Editorial
---
## Related Coverage