logo

Signed Logitech Installer Used In TCLBANKER Banking Trojan Attacks

ID: 3f2261b1-9879-5a24-948e-949fe8462098

STIX ID: report--3f2261b1-9879-5a24-948e-949fe8462098

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-05-11

Date Updated: 2026-05-22

Author: Varshini

...
...

TCLBANKER is a newly observed, sophisticated Brazilian banking trojan campaign that targets 59 banking, fintech, and cryptocurrency platforms by abusing a legitimately signed Logitech MSI via DLL sideloading to execute malicious code. The malware performs strong sandbox/VM detection and environmental hashing, patches ETW to evade telemetry, establishes persistence via Task Scheduler, monitors browser URLs and uses UI Automation to present full-screen overlays for credential theft, and includes self-propagating worm modules that abuse WhatsApp and Outlook to spread and exfiltrate contacts and session data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.