logo

Self-Propagating TCLBANKER Campaign Targets Users via WhatsApp and Outlook

ID: 29a0c50d-dd9c-534e-abf2-80e4b088ff77

STIX ID: report--29a0c50d-dd9c-534e-abf2-80e4b088ff77

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-05-11

Date Updated: 2026-05-11

Author: Varshini

...
...

**Executive Summary:** The report details TCLBANKER (REF3076), a sophisticated Brazilian banking trojan that uses DLL sideloading of a signed Logitech application, environment-gated payload decryption and sandbox detection to evade analysis, monitors browsers for banking sites to deploy full-screen overlays, and spreads rapidly via worm modules that hijack authenticated WhatsApp Web and Outlook sessions to send trojanized installers to victim contacts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.