# TCLBANKER: New Brazilian Banking Trojan Weaponizes WhatsApp and Outlook for Mass Financial Theft


A previously undocumented Brazilian banking trojan has emerged as a sophisticated threat to financial institutions and customers across Latin America and beyond. Dubbed TCLBANKER and tracked by Elastic Security Labs under the designation REF3076, the malware represents a significant evolution of the Maverick banking trojan family and demonstrates the continued sophistication of financially motivated threat actors.


## The Threat


Threat hunters have confirmed that TCLBANKER targets at least 59 banking, fintech, and cryptocurrency platforms, making it one of the more ambitious banking trojans observed in recent campaigns. The malware combines a multi-layered infection architecture with advanced evasion techniques, leveraging both worm-like propagation capabilities and interactive remote access functionality to drain victim accounts and steal credentials.


The most alarming feature is its self-propagating mechanism: TCLBANKER uses compromised WhatsApp Web sessions and Microsoft Outlook access to spread itself automatically to a victim's contacts, creating a viral distribution channel that bypasses traditional security perimeters. This worm component, inherited from its Maverick predecessor, ensures that initial compromises can rapidly expand into wider organizational and personal network infections.


## Background and Context


TCLBANKER is assessed as a major update to Maverick, a banking trojan family previously documented by threat intelligence researchers. The malware campaign is attributed to Water Saci, a threat cluster identified by Trend Micro that has maintained consistent focus on financial targets across Brazilian institutions.


The evolution from Maverick to TCLBANKER reflects a pattern common among financially motivated threat groups: incremental improvements in evasion, anti-analysis capabilities, and target coverage. Previous versions of Maverick relied on the SORVEPOTEL worm component to spread via WhatsApp. TCLBANKER incorporates similar spreading functionality while adding Outlook propagation and more robust defensive mechanisms designed to evade detection and analysis.


This generational update suggests an active, well-resourced threat actor with continued investment in banking malware development—typical of organized cybercriminal operations operating from or targeting Brazilian financial systems.


## Technical Details: A Multi-Layered Attack Chain


Security researchers from Elastic Security Labs—Jia Yu Chan, Daniel Stepanic, Seth Goodwin, and Terrance DeJesus—documented the complete infection chain and highlighted the trojan's sophisticated architecture.


### Initial Infection and DLL Side-Loading


The attack begins with a malicious MSI installer bundled inside a ZIP file. The MSI package abuses a legitimately signed Logitech program called Logi AI Prompt Builder to achieve execution. This technique, known as DLL side-loading, exploits the trust placed in legitimate signed executables by Windows security mechanisms.


The malicious DLL ("screen_retriever_plugin.dll") acts as a loader and incorporates a comprehensive anti-analysis subsystem. The loader includes multiple defensive checks:


| Defense Mechanism | Purpose |

|---|---|

| Loader validation | Only executes if loaded by logiaipromptbuilder.exe or tclloader.exe |

| Hook removal | Strips usermode hooks from ntdll.dll placed by endpoint security |

| ETW disabling | Disables Event Tracing for Windows telemetry collection |

| Debugger detection | Identifies active debuggers and analysis tools |

| Sandbox detection | Detects virtual environments and analysis sandboxes |

| Antivirus evasion | Identifies and avoids running in monitored environments |


### Environment Fingerprinting and Decryption


The loader generates three separate fingerprints based on:

  • Anti-debugging and anti-virtualization checks
  • System disk information
  • System language verification (specifically targeting Brazilian Portuguese)

  • These fingerprints are combined to create an environment hash value used to decrypt the embedded payload. If analysis tools are detected (such as a debugger), the hash becomes incorrect, and the payload fails to decrypt—effectively killing execution in analysis environments. This technique is highly effective at preventing automated sandbox analysis and manual reverse engineering.


    ### The Banking Trojan Module


    Once the environmental checks pass, TCLBANKER's main banking trojan module activates. The malware:


    1. Verifies Brazilian system location before proceeding with infection

    2. Establishes persistence via Windows scheduled tasks

    3. Beacons to command servers with system information via HTTP POST requests

    4. Monitors browser activity in real-time using UI Automation to capture URLs from popular browsers (Chrome, Firefox, Edge, Brave, Opera, Vivaldi)

    5. Compares URLs against a hard-coded list of targeted financial institutions


    When a targeted banking URL is detected, TCLBANKER establishes a WebSocket connection to a remote command server and enters a dispatch loop, enabling operators to execute extensive capabilities:


  • Run arbitrary shell commands
  • Capture screenshots and stream video from the screen
  • Manage clipboard contents
  • Launch keystroke logging
  • Remotely control mouse and keyboard
  • Manage files and processes
  • Enumerate running processes and visible windows

  • ### Credential Harvesting Through Full-Screen Overlays


    TCLBANKER deploys a Windows Presentation Foundation (WPF)-based overlay framework to conduct sophisticated social engineering attacks. The overlays are designed to:


  • Display fake credential-stealing prompts
  • Show vishing (voice phishing) wait screens
  • Present bogus progress bars
  • Simulate legitimate Windows Update dialogs
  • Hide overlays from standard screen capture tools

  • This layered approach combines technical remote access with social engineering, significantly increasing the likelihood of successful credential theft.


    ### Worm Propagation Module


    Simultaneously with banking operations, the loader's worm component propagates TCLBANKER through:


  • WhatsApp Web: Accesses compromised WhatsApp sessions to send malicious messages to a victim's contact list
  • Microsoft Outlook: Leverages email accounts to send phishing messages with malicious attachments to contacts

  • This dual-vector propagation mechanism ensures rapid spread within both personal and professional networks, creating exponential growth in the infection footprint.


    ## Implications for Financial Institutions and Users


    TCLBANKER represents a significant threat to multiple sectors:


    For Banks and Financial Services: The targeting of 59+ financial institutions indicates systematic reconnaissance and continued development against specific targets. The combination of remote access and social engineering makes traditional security controls insufficient.


    For Cryptocurrency Platforms: Inclusion of crypto exchanges in the target list demonstrates threat actor interest in high-value digital asset theft, a growing trend among financially motivated groups.


    For Enterprise Organizations: The worm propagation via Outlook means that compromised corporate email systems could rapidly distribute TCLBANKER across entire organizations, affecting both employees and business partners.


    For Individual Users: End users in Brazil and potentially other regions are at risk of financial account compromise, credential theft, and identity fraud.


    ## Recommendations


    Organizations and individuals should implement the following defensive measures:


    For Financial Institutions:

  • Deploy behavioral analytics to detect unusual account access patterns
  • Implement device fingerprinting to identify unauthorized logins
  • Conduct targeted phishing awareness training focused on vishing attacks and fake update dialogs
  • Monitor for suspicious scheduled task creation

  • For Enterprise Security Teams:

  • Review email and messaging logs for suspicious propagation patterns
  • Scan systems for the specific indicators of compromise (Logitech program abuse, screen_retriever_plugin.dll, scheduled task artifacts)
  • Isolate systems showing signs of compromise immediately
  • Enforce application whitelisting to prevent DLL side-loading attacks

  • For End Users:

  • Enable multi-factor authentication on all financial accounts
  • Avoid downloading files from untrusted sources
  • Verify update dialogs directly through banking applications rather than clicking overlays
  • Monitor account statements for unauthorized transactions

  • ---


    ## HackWire Analysis


    TCLBANKER's emergence highlights a critical shift in banking trojan sophistication: the integration of legitimate software exploitation with industrial-scale social engineering. The abuse of Logitech's signed executable is particularly significant because it demonstrates threat actors' understanding that organizations increasingly trust supply chains—and legitimate software becomes the primary attack surface when malicious binaries are blocked.


    The worm propagation via WhatsApp and Outlook is the real story here. While previous banking trojans focused on individual compromise, TCLBANKER's design patterns suggest operators expect exponential spread. This isn't a boutique espionage tool; it's built for volume. A single compromised corporate email account could infect dozens of employees and hundreds of external contacts within hours.


    What's striking is the environment fingerprinting technique. By ensuring the malware only operates on Brazilian systems, threat actors are maximizing their target precision while simultaneously frustrating researchers who might analyze the sample from outside Brazil. This level of operational security suggests a mature threat group with sufficient resources to maintain separate Brazilian testing infrastructure.


    For defenders, the most actionable insight is that overlay-based social engineering remains devastatingly effective. The fake Windows Update prompts will work. Technical controls alone won't stop determined users from entering credentials into convincing fake login screens. This isn't a technology problem requiring a technical solution—it's a human problem requiring behavioral training, and organizations investing heavily in technical controls while neglecting security culture will lose.


    The timing also matters: as Latin American crypto adoption accelerates and regional fintech innovation intensifies, banking trojans are rapidly evolving to match the attack surface expansion. Water Saci and similar groups are clearly monitoring what targets are most valuable and adapting their tools accordingly. Organizations in Brazil and neighboring countries should expect this threat to persist and evolve for the foreseeable future.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Malware](https://www.hackwire.news/category/malware) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)