logo

TCLBANKER Banking Trojan Targets Financial Platforms via WhatsApp and Outlook Worms

ID: 21ca775f-7ec7-50a4-a645-352a53789a85

STIX ID: report--21ca775f-7ec7-50a4-a645-352a53789a85

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-05-08

Date Updated: 2026-05-11

Author: [email protected] (The Hacker News)

...
...

TCLBANKER is a newly documented Brazilian banking trojan (tracked as REF3076) that combines a loader with strong anti-analysis checks, a full-featured banking trojan (credential-stealing overlays, keylogging, remote control) and a worming module that propagates via WhatsApp Web and Microsoft Outlook. The malware abuses a signed Logitech installer for DLL side-loading, environment-gated payload decryption that favors Brazilian Portuguese systems, and uses WebSocket C2 for real-time social engineering; the campaign is in early operational stages but is capable of mass distribution and sophisticated fraud against banking, fintech, and crypto platforms.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.