logo

Signed Logitech Installer Abused to Drop TCLBANKER Banking Trojan

ID: cb61554f-1733-5196-91fe-05aab205cac4

STIX ID: report--cb61554f-1733-5196-91fe-05aab205cac4

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-05-08

Date Updated: 2026-05-08

Author: Mayura Kathir

...
...

TCLBANKER is a feature-rich Brazilian banking trojan distributed via a trojanized signed Logitech installer that uses DLL sideloading, advanced anti-analysis techniques, and environment-gated decryption to avoid detection; once active it monitors browser navigation to 59 Brazilian financial domains, establishes WebSocket C2 connections, deploys full-screen overlays for real-time social engineering, and can self-propagate using WhatsApp and Outlook modules (campaign REF3076).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.