typeentityconfidencemediumcreated2026-08-07updated2026-08-07malware-familydelphibanking-trojanlatamratscreen-captureqr-codessl-c2persistence

bromechokucom

Delphi/Embarcadero PE32 banking trojan / remote-access tool targeting Latin American victims (Portuguese-language internal naming, PIX QR-code generation, synthetic input). OpenCTI-derived family label; first confirmed sample in corpus.

Overview

  • First observed: 2026-05-25 (compilation timestamp of first sample)
  • Platform: Windows PE32 GUI
  • Language: Delphi/Embarcadero RAD Studio
  • Region: Latin America (LatAm tag from OpenCTI; Portuguese unit names)
  • Distribution label: bromechoku-com, remoto-ddins-click (OpenCTI)

Build Stack

  • Compiler: Delphi/Embarcadero (PE32, 11 sections, ImageBase 0x400000)
  • No packer or obfuscation observed
  • Version-info masquerade: Microsoft Edge / Mcrosoft Corporaton / ProgramID com.embarcadero.misge
  • Light anti-analysis: IsDebuggerPresent, GetTickCount, QueryPerformanceCounter, wine_get_version string

Capabilities

  • screen-capture-dxgi-wgc — Desktop Duplication API + Windows Graphics Capture dual-engine
  • screen-capture-gdi-fallback — BitBlt/GetDIBits fallback
  • qr-code-generation-zxing — Full ZXing QR encoder with Reed-Solomon, mask patterns, error correction
  • synthetic-input-sendinput — SendInput, tagMOUSEINPUT, tagKEYBDINPUT
  • keylogging-setwindowshookex — SetWindowsHookExW + GetKeyState
  • registry-run-persistence — RegSetValueExW / RegCreateKeyExW
  • c2-indy-tcp-ssl — TIdTCPClient + TIdSSLIOHandlerSocketOpenSSL
  • c2-winhttp — Full WinHttp* API surface
  • downloader-validate-exe-zip — TDownloader with EXE/ZIP validation
  • av-enumeration — TAvProduct / TAvList
  • clipboard-manipulation — SetClipboardData / GetClipboardData / EmptyClipboard
  • window-enumeration — EnumWindows, FindWindowW, GetForegroundWindow, GetWindowTextW

Deploy / TTPs

  • Screen capture: Professional-grade DXGI/WGC delta capture with JPEG dirty-rectangle encoding
  • QR generation: Likely hijacks PIX instant-payment QR codes for bank-transfer fraud
  • Synthetic input: Mouse and keyboard injection to interact with banking web interfaces
  • Keylogging: Windows hook-based keystroke capture
  • C2: Dual HTTP stack — Indy TCP/SSL (OpenSSL-backed) and system WinHTTP with proxy detection and authentication
  • Persistence: Registry Run keys (inferred from imports; no hardcoded key path observed)
  • Downloader: EXE/ZIP payload fetch and validation

Variants / Aliases

  • OpenCTI: bromechoku-com
  • OpenCTI: remoto-ddins-click
  • No confirmed siblings in corpus yet.

Notable Analyses

  • 36a4bca2 — First confirmed sample (4.7 MB, May 2026, Microsoft Edge masquerade) ^[/intel/analyses/36a4bca295060d1d96f7ac3c65462f581823d74cd4cceac9ae5b3f660341de9a.html]

Related