TCLBANKER Malware Targets Users Through Self-Propagating WhatsApp and Outlook Worm Modules
ID: 64309cab-eda5-5c06-bcd3-2d60e5f02ca5
STIX ID: report--64309cab-eda5-5c06-bcd3-2d60e5f02ca5
Feed Name: cybersecurityNews.com
**TCLBANKER** is a sophisticated Brazilian banking trojan (campaign REF3076) that infects systems via a fake, digitally signed Logitech installer using DLL side‑loading, evades sandboxes and geofencing, spreads automatically by cloning WhatsApp Web sessions and abusing Outlook via COM automation, and uses full‑screen overlays to harvest credentials from 59 targeted banks/fintech/crypto sites; researchers recovered multiple loader SHA‑256 hashes and malicious domains and observed Cloudflare Workers used for C2 and file hosting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
