logo

TCLBANKER Malware Leverages WhatsApp and Outlook Worm Features in Active Attacks

ID: a7da6597-c3e9-5c84-9c0c-39cabfd8a03a

STIX ID: report--a7da6597-c3e9-5c84-9c0c-39cabfd8a03a

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-05-09

Date Updated: 2026-07-21

Author: Divya

...
...

**Executive summary:** The report analyzes REF3076, a campaign distributing TCLBANKER — a sophisticated Brazilian-targeted banking trojan delivered via a trojanized Logitech MSI and DLL sideloading — which deploys .NET Reactor-protected banking and worm modules, uses environment-based payload decryption and anti-analysis techniques, performs geofencing and active browser URL monitoring to target Brazilian banks, and self-propagates by harvesting contacts and sending phishing via WhatsApp and Outlook; the report includes hashes, domains, developer artifacts, and evidence of active C2 infrastructure hosted under a Cloudflare Workers account.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.