latam-banking-trojan
Cross-family pattern for banking trojans targeting Latin American financial institutions, especially Brazilian banks. Characterized by PIX QR-code hijacking, screen-capture overlays, and synthetic input to manipulate online banking sessions.
Pattern Definition
Latin American banking trojans (often Brazilian, Portuguese-language, or Spanish-language) share a common operational model distinct from European or North American banking malware:
- PIX QR-code hijacking — Brazil's instant-payment system (PIX) uses QR codes. Trojans generate attacker-controlled QR codes via embedded ZXing or custom encoders, tricking victims into transferring funds to attacker accounts.
- Screen-capture overlays — Professional-grade capture (DXGI Desktop Duplication, Windows Graphics Capture, or GDI) to monitor the victim's banking session in real time.
- Synthetic input injection —
SendInput, mouse/keyboard hooks, orSetCursorPosto interact with banking web apps and approve transactions. - Click helpers / value helpers — Banking-specific UI overlay classes (e.g.,
TValorClickHelper) that intercept or redirect user clicks toward attacker-controlled fields. - Remote module architecture — Modular design with remote-downloadable plugins (
TModuloRemoto, downloader classes with EXE/ZIP validation). - Registry persistence — Standard
Runkeys or scheduled tasks. - C2 over TLS — Indy TCP/SSL, WinHTTP, or both; often runtime-resolved endpoints.
Variants Observed
- Delphi/Embarcadero builds —
bromechokucom(first sample36a4bca2, May 2026) ^[/intel/analyses/36a4bca295060d1d96f7ac3c65462f581823d74cd4cceac9ae5b3f660341de9a.html] - Other families may use AutoIt, .NET, or Go; the pattern is behavioral, not toolchain-specific.
Cross-References
- bromechokucom — confirmed Delphi family in this cluster
- delphi-screen-capture-dxgi-wgc — technique for the capture stack
- pix-qr-code-fraud — concept for PIX-specific QR hijacking
- synthetic-input-manipulation — concept for
SendInput-based banking session manipulation