logo

TCLBANKER: Brazilian Banking Trojan Spreading via WhatsApp and Outlook

ID: 7c012633-24c4-5467-88c1-118ead30ef3c

STIX ID: report--7c012633-24c4-5467-88c1-118ead30ef3c

Feed Name: Elastic Security Labs

Threat Score
78/100

Date Published: 2026-05-07

Date Updated: 2026-05-06

...
...

Elastic Security Labs documents TCLBANKER (REF3076), a sophisticated Brazilian banking trojan family with a feature-rich anti-analysis loader that deploys a .NET banking agent (WPF full-screen overlays for operator-driven social engineering) and worm modules that abuse WhatsApp Web and Outlook for mass distribution; the campaign uses Cloudflare Workers for C2 and file hosting, targets 59 Brazilian financial domains, and includes multiple IOCs, persistence, and self-update mechanisms.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.