Self-Propagating TCLBANKER Campaign Targets Users via WhatsApp and Outlook
ID: 29a0c50d-dd9c-534e-abf2-80e4b088ff77
STIX ID: report--29a0c50d-dd9c-534e-abf2-80e4b088ff77
Feed Name: Cyber Press
Threat Score
**Executive Summary:** The report details TCLBANKER (REF3076), a sophisticated Brazilian banking trojan that uses DLL sideloading of a signed Logitech application, environment-gated payload decryption and sandbox detection to evade analysis, monitors browsers for banking sites to deploy full-screen overlays, and spreads rapidly via worm modules that hijack authenticated WhatsApp Web and Outlook sessions to send trojanized installers to victim contacts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
