logo

New TCLBanker Malware Self-Spreads Over WhatsApp and Outlook

ID: 4bf989d0-6b6d-562a-9b94-f89e588cd91e

STIX ID: report--4bf989d0-6b6d-562a-9b94-f89e588cd91e

Feed Name: Security Boulevard

Threat Score
75/100

Date Published: 2026-05-10

Date Updated: 2026-05-11

Author: Evan Rowe

...
...

Elastic Security Labs documented TCLBanker, a sophisticated Brazilian-focused banking trojan delivered through a trojanized MSI and a sideloaded malicious DLL; it deploys a banking trojan with WPF overlays for credential theft and worm modules that clone WhatsApp Web sessions and automate Outlook to send phishing messages from victims' own accounts, enabling rapid self-propagation to contacts and posing significant risk to Brazilian banking, fintech, and crypto users as well as organizations whose employees use WhatsApp Web or Outlook on Windows.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.