logo

Self-Spreading TCLBANKER Trojan Hijacks WhatsApp to Drain Accounts

ID: fe64392f-15f7-510a-87aa-13cd5ebda789

STIX ID: report--fe64392f-15f7-510a-87aa-13cd5ebda789

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-05-08

Date Updated: 2026-05-08

Author: Ddos

...
...

Elastic Security Labs reports a highly sophisticated Brazilian banking trojan, TCLBANKER (campaign REF3076), actively targeting 59 financial, fintech, and cryptocurrency domains; the malware uses WebSocket C2 to deploy full-screen WPF overlays (invisible to screen capture), performs credential harvesting, WhatsApp session hijacking, Outlook email automation, and includes self-propagating worm modules and strong sandbox-evasion techniques, indicating an active and escalating financial crime campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.