typeconceptconfidencemediumcreated2026-08-07updated2026-08-07malware-familybanking-trojanlatamscreen-captureqr-codesynthetic-inputpersistence

latam-banking-trojan

Cross-family pattern for banking trojans targeting Latin American financial institutions, especially Brazilian banks. Characterized by PIX QR-code hijacking, screen-capture overlays, and synthetic input to manipulate online banking sessions.

Pattern Definition

Latin American banking trojans (often Brazilian, Portuguese-language, or Spanish-language) share a common operational model distinct from European or North American banking malware:

  1. PIX QR-code hijacking — Brazil's instant-payment system (PIX) uses QR codes. Trojans generate attacker-controlled QR codes via embedded ZXing or custom encoders, tricking victims into transferring funds to attacker accounts.
  2. Screen-capture overlays — Professional-grade capture (DXGI Desktop Duplication, Windows Graphics Capture, or GDI) to monitor the victim's banking session in real time.
  3. Synthetic input injection — SendInput, mouse/keyboard hooks, or SetCursorPos to interact with banking web apps and approve transactions.
  4. Click helpers / value helpers — Banking-specific UI overlay classes (e.g., TValorClickHelper) that intercept or redirect user clicks toward attacker-controlled fields.
  5. Remote module architecture — Modular design with remote-downloadable plugins (TModuloRemoto, downloader classes with EXE/ZIP validation).
  6. Registry persistence — Standard Run keys or scheduled tasks.
  7. C2 over TLS — Indy TCP/SSL, WinHTTP, or both; often runtime-resolved endpoints.

Variants Observed

  • Delphi/Embarcadero builds — bromechokucom (first sample 36a4bca2, May 2026) ^[/intel/analyses/36a4bca295060d1d96f7ac3c65462f581823d74cd4cceac9ae5b3f660341de9a.html]
  • Other families may use AutoIt, .NET, or Go; the pattern is behavioral, not toolchain-specific.

Cross-References