TCLBANKER Malware Leverages WhatsApp and Outlook Worm Features in Active Attacks
ID: a7da6597-c3e9-5c84-9c0c-39cabfd8a03a
STIX ID: report--a7da6597-c3e9-5c84-9c0c-39cabfd8a03a
Feed Name: GBHackers
**Executive summary:** The report analyzes REF3076, a campaign distributing TCLBANKER — a sophisticated Brazilian-targeted banking trojan delivered via a trojanized Logitech MSI and DLL sideloading — which deploys .NET Reactor-protected banking and worm modules, uses environment-based payload decryption and anti-analysis techniques, performs geofencing and active browser URL monitoring to target Brazilian banks, and self-propagates by harvesting contacts and sending phishing via WhatsApp and Outlook; the report includes hashes, domains, developer artifacts, and evidence of active C2 infrastructure hosted under a Cloudflare Workers account.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
