logo

New TCLBanker malware self-spreads over WhatsApp and Outlook

ID: 9c53a459-660e-594a-b39f-d8744ea42d43

STIX ID: report--9c53a459-660e-594a-b39f-d8744ea42d43

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-05-07

Date Updated: 2026-05-07

Author: Bill Toulas

...
...

Elastic Security Labs discovered TCLBanker, a new banking trojan that sideloads into a legitimate Logitech MSI, employs strong anti‑analysis techniques and a persistent watchdog, and provides operators with remote access, keylogging, screen streaming and overlay-based credential theft. Notably, it includes worm modules that hijack WhatsApp Web and automate Outlook to harvest contacts and spread via phishing to Brazilian banking, fintech and cryptocurrency targets; researchers warn the threat could expand beyond LATAM.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.