logo

Hackers Abuse Signed Logitech Installer to Deploy TCLBANKER Banking Trojan

ID: 298c4cb8-5564-5bb4-883c-534ece6430a9

STIX ID: report--298c4cb8-5564-5bb4-883c-534ece6430a9

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-05-08

Date Updated: 2026-05-14

Author: Tushar Subhra Dutta

...
...

**TCLBANKER (REF3076)** is a newly observed Brazilian-targeted banking trojan distributed via a trojanized, digitally signed Logitech MSI that uses DLL sideloading to load a malicious Flutter plugin; it monitors browsers for 59 financial domains, establishes live C2 connections to present fraudulent overlays and block remediation, and includes worm modules that abuse WhatsApp Web and Outlook to propagate, with command/file infrastructure hosted via Cloudflare Workers and multiple provided IoCs (SHA-256 hashes and domains).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.