Hackers Abuse Signed Logitech Installer to Deploy TCLBANKER Banking Trojan
ID: 298c4cb8-5564-5bb4-883c-534ece6430a9
STIX ID: report--298c4cb8-5564-5bb4-883c-534ece6430a9
Feed Name: cybersecurityNews.com
**TCLBANKER (REF3076)** is a newly observed Brazilian-targeted banking trojan distributed via a trojanized, digitally signed Logitech MSI that uses DLL sideloading to load a malicious Flutter plugin; it monitors browsers for 59 financial domains, establishes live C2 connections to present fraudulent overlays and block remediation, and includes worm modules that abuse WhatsApp Web and Outlook to propagate, with command/file infrastructure hosted via Cloudflare Workers and multiple provided IoCs (SHA-256 hashes and domains).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
