#TCLBANKER
A new trojan named TCLBanker, which targets 59 banking, fintech, and cryptocurrency platforms, uses a trojanized MSI installer for Logitech AI Prompt Builder to infect systems.
New TCLBanker malware self-spreads over WhatsApp and Outlook
A new trojan named TCLBanker, which targets 59 banking, fintech, and cryptocurrency platforms, uses a trojanized MSI installer for Logitech AI Prompt Builder to infect systems.
www.bleepingcomputer.com
May 7, 2026 at 10:07 PM
Ein ausgeklügelter Trojaner, der sich selber über #Whatsapp & #Microsoft #Outlook verbreitet!

Juck mich als #Threema Userin überhaupt nicht!

#Banking #Trojaner #TCLBanker #Malware #Fintech #Krypto #Spionage #Wurm #Maverick #Sorvepotel #Spyware
May 13, 2026 at 11:30 AM
New TCLBanker malware self-spreads over WhatsApp and Outlook

A new trojan named TCLBanker, which targets 59 banking, fintech, and cryptocurrency platforms, uses a trojanized MSI installer for Logitech AI Prompt Builder to infect systems. [...]
#hackernews #news
New TCLBanker malware self-spreads over WhatsApp and Outlook
A new trojan named TCLBanker, which targets 59 banking, fintech, and cryptocurrency platforms, uses a trojanized MSI installer for Logitech AI Prompt Builder to infect systems. [...]
www.bleepingcomputer.com
May 8, 2026 at 11:20 PM
-German domains go down in massive outage
-GothFerrari sentenced to prison
-Two more DPRK laptop farmers sentenced to prison
-Swatter arrested in Hungary
-Malicious NuGet packages
-New PCPJack attacks
-New CallPhantom campaign
-New TCLBANKER malware
-New Contagious Interview tactics
May 8, 2026 at 7:42 AM
Hackers Abuse Signed Logitech Installer to Deploy TCLBANKER Banking Trojan
Hackers Abuse Signed Logitech Installer to Deploy TCLBANKER Banking Trojan
A new banking trojan known as TCLBANKER has been quietly making rounds, and its delivery method is as clever as it is concerning. Attackers are using a trojanized version of a legitimate, digitally signed installer to slip malware onto victims’ machines without raising immediate suspicion. The campaign, tracked as REF3076, bundles a malicious MSI installer inside a ZIP file and exploits the trust people place in recognizable software names. The infection begins when a victim runs what appears to be a legitimate Logitech application installer. Inside the package, threat actors have weaponized the Logi AI Prompt Builder, abusing a technique called DLL sideloading to sneak a malicious file into the process. Once the application starts, it automatically loads the harmful DLL without the user ever knowing anything went wrong. Analysts at Elastic Security Labs identified this new Brazilian banking trojan , assessing it to be a significant evolution of an older malware family known as MAVERICK and SORVEPOTEL. The campaign appears to be in its early stages, with developer artifacts and an incomplete phishing page suggesting the attackers are still actively building out their infrastructure. File directory contents showing a malicious DLL (Source – Elastic) TCLBANKER primarily targets users in Brazil, specifically those who visit banking, fintech, and cryptocurrency websites. The trojan monitors the victim’s browser in real time, watching for visits to any of 59 targeted financial domains. Hackers Abuse Signed Logitech Installer When a match is found, it opens a live connection to the attacker’s command server and puts the operator in full control. The scope of potential damage goes well beyond simple credential theft. The malware can display fake full-screen overlays that look like real banking interfaces, freeze the apparent desktop to confuse victims, and kill the Task Manager to prevent users from ending the malicious process. It is a coordinated operation designed to make fraud feel seamless from the attacker’s side. Targeted process names decrypted by TCLBANKER (Source – Elastic) The attackers took care to make the infection chain look as normal as possible. The malicious ZIP file contains an MSI installer that mimics the legitimate Logi AI Prompt Builder, a real Flutter-based application. When installed, the trojanized package drops a fake DLL called screen_retriever_plugin.dll, which masquerades as a genuine Flutter plugin and gets loaded automatically at startup. The loader inside this DLL is packed with tricks to avoid detection. It checks whether the system is running inside a sandbox or virtual machine, verifies that the user’s default language is Brazilian Portuguese, and even measures timing to catch emulation frameworks that speed up sleep calls. Register task for persistence (Source – Elastic) If anything seems off, the malware simply stops running without leaving obvious traces. This environment-gating approach means the payload only decrypts itself on real, qualifying machines. Self-Spreading Worm Modules Amplify the Threat What makes TCLBANKER particularly dangerous is not just what it does on a single machine, but how far it can spread from there. The malware comes with two worm modules designed to send itself to the victim’s contacts using channels those contacts already trust. The first hijacks the victim’s active WhatsApp Web session in the browser, silently messaging Brazilian contacts with a link to download the malware. The second abuses Microsoft Outlook through automation, sending phishing emails directly from the victim’s own email account. Because these messages come from real, known senders, they are far harder for security filters to catch. The Outlook bot first harvests the victim’s contact list, then sends targeted emails that look completely authentic. Elastic researchers noted that all command and file-serving infrastructure runs on Cloudflare Workers under a single account, making it easy for operators to rotate infrastructure quickly when needed. Organizations and individuals can take several steps to reduce exposure. Keeping security software updated ensures the latest detection signatures are in place. Being cautious about ZIP files or MSI installers received through messaging apps or email, even from known contacts, is critical given this trojan’s self-spreading behavior. Monitoring for unusual scheduled tasks, unexpected DLL loads alongside legitimate software, and suspicious outbound connections can also help flag infections early. Indicators of Compromise (IoCs):- Type Indicator Description SHA-256 701d51b7be8b034c860bf97847bd59a87dca8481c4625328813746964995b626 TCLBanker loader component (screen_retriever_plugin.dll) SHA-256 8a174aa70a4396547045aef6c69eb0259bae1706880f4375af71085eeb537059 TCLBanker loader component (screen_retriever_plugin.dll) SHA-256 668f932433a24bbae89d60b24eee4a24808fc741f62c5a3043bb7c9152342f40 TCLBanker loader component (screen_retriever_plugin.dll) SHA-256 63beb7372098c03baab77e0dfc8e5dca5e0a7420f382708a4df79bed2d900394 TCLBanker initial ZIP file (XXL_21042026-181516.zip) Domain campanha1-api.ef971a42[.]workers.dev TCLBanker C2 Domain mxtestacionamentos[.]com TCLBanker C2 Domain documents.ef971a42.workers[.]dev TCLBanker file server Domain arquivos-omie[.]com TCLBanker phishing page (under development) Domain documentos-online[.]com TCLBanker phishing page (under development) Domain afonsoferragista[.]com TCLBanker phishing page (under development) Domain doccompartilhe[.]com TCLBanker phishing page (under development) Domain recebamais[.]com TCLBanker phishing page (under development) Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . Follow us on  Google News ,  LinkedIn , and  X  to Get More Instant Updates ,  Set CSN as a Preferred Source in  Google . The post Hackers Abuse Signed Logitech Installer to Deploy TCLBANKER Banking Trojan appeared first on Cyber Security News .
cybersecuritynews.com
May 8, 2026 at 1:31 PM
New TCLBanker malware self-spreads over WhatsApp and Outlook
New TCLBanker malware self-spreads over WhatsApp and Outlook
A new trojan named TCLBanker, which targets 59 banking, fintech, and cryptocurrency platforms, uses a trojanized MSI installer for Logitech AI Prompt Builder to infect systems.
www.bleepingcomputer.com
May 7, 2026 at 11:01 PM
🇧🇷 New Banking Trojan 'TCLBANKER' targets 59 Brazilian financial apps! The malware spreads like a worm via WhatsApp & Outlook, using DLL side-loading to evade detection. Stay vigilant! 💻 #Malware #BankingTrojan #Brazil #Cybersecurity

🌐 cyber[.]netsecops[.]io
New TCLBANKER Trojan Spreads via WhatsApp and Outlook, Targeting 59 Brazilian Financial Apps
A new Brazilian banking trojan, TCLBANKER, is targeting 59 financial platforms with a worm-like component that spreads via WhatsApp and Outlook, using advanced anti-analysis techniques.
cyber.netsecops.io
June 7, 2026 at 5:13 PM
TCLBankerという新たなマルウェア、WhatsAppとOutlookを介して自己拡散
#CybersecurityNews
www.bleepingcomputer.com/news/securit...
New TCLBanker malware self-spreads over WhatsApp and Outlook
A new trojan named TCLBanker, which targets 59 banking, fintech, and cryptocurrency platforms, uses a trojanized MSI installer for Logitech AI Prompt Builder to infect systems.
www.bleepingcomputer.com
May 8, 2026 at 8:09 AM
Die neue Malware TCLBanker attackiert 59 Finanzplattformen. Der Trojaner nutzt eine Logitech-App zur Infektion und verbreitet sich autonom über WhatsApp und Outlook.

www.it-daily.net/shortnews/ma...
Malware TCLBanker: Banking-Trojaner nutzt WhatsApp-Wurm
Die neue Malware TCLBanker attackiert 59 Finanzplattformen. Der Trojaner nutzt eine Logitech-App zur Infektion und verbreitet sich autonom über WhatsApp und Outlook.
www.it-daily.net
May 13, 2026 at 6:26 AM
TCLBANKER Banking Trojan Threatens 59 Financial Platforms Through WhatsApp and Outlook Worms TCLBANKER Banking Trojan Threatens 59 Financial Platforms Through WhatsApp and Outlook Worms A newly ide...

#Global #Global #Cybersecurity #Ransomware […]

[Original post on cyberwarriorsmiddleeast.com]
Original post on cyberwarriorsmiddleeast.com
cyberwarriorsmiddleeast.com
May 9, 2026 at 1:39 PM
TCLBANKER Banking Trojan Targets Financial Platforms via WhatsApp and Outlook Worms

Threat hunters have flagged a previously undocumented Brazilian banking trojan dubbed TCLBANKER that's capable of targeting 59 banking, fintech, and cryptocurrency platforms.
The activity is being…
#hackernews #news
TCLBANKER Banking Trojan Targets Financial Platforms via WhatsApp and Outlook Worms
Threat hunters have flagged a previously undocumented Brazilian banking trojan dubbed TCLBANKER that's capable of targeting 59 banking, fintech, and cryptocurrency platforms. The activity is being tracked by Elastic Security Labs under the moniker REF3076. The malware family is assessed to be a major update of the Maverick, which is known to leverage a worm called SORVEPOTEL to spread via
thehackernews.com
May 10, 2026 at 4:30 AM
TCLBANKER Banking Trojan Targets Financial Platforms via WhatsApp and Outlook Worms #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
May 9, 2026 at 11:54 PM
Elastic Security Labs uncovers new Brazilian banking trojan TCLBANKER. The campaign uses a heavily protected loader to deploy a banking trojan & a self-propagating worm module. A key feature is browser address-bar monitoring via UI automation across 59 domains. www.elastic.co/security-lab...
May 7, 2026 at 9:18 AM
ブラジルのトロイの木馬がWhatsAppを乗っ取り、暗号通貨フィッシングを拡散 - Cryptopolitan

Elastic Security Labsのセキュリティ研究者らは、TCLBANKERという名のブラジル発の新たなバンキング型トロイの木馬を発見した。 このマルウェアは、感染した ...
www.cryptopolitan.com/ja/brazilian...
ブラジルのトロイの木馬がWhatsAppを乗っ取り、暗号通貨フィッシングを拡散 - Cryptopolitan
セキュリティ研究者らは、ブラジル発のバンキング型トロイの木馬「TCLBANKER」を発見した。このトロイの木馬は、WhatsAppとOutlookのアカウントを乗っ取り、被害者の連絡先に暗号通貨フィッシング詐欺を拡散させる。.
www.cryptopolitan.com
May 10, 2026 at 10:39 PM
Vírus bancário usa WhatsApp para roubar dados de brasileiros
Pesquisadores da empresa de segurança Elastic identificaram um novo trojan bancário voltado exclusivamente para usuários brasileiros. O malware, chamado TCLBANKER, se instala disfarçado de um programa legítimo da Logitech e só age em máquinas configuradas em português do Brasil. Assim que detecta o acesso a um dos 59 sites financeiros monitorados, incluindo bancos, fintechs e corretoras de criptomoedas, abre uma conexão com os criminosos e passa a receber comandos em tempo real. Durante o golpe, o malware cobre todos os monitores da vítima com janelas falsas que não aparecem em capturas de tela. Uma dessas telas imita a atualização do Windows. Outra exibe uma mensagem de espera enquanto um cúmplice liga para a vítima se passando por funcionário do banco. O TCLBANKER também se propaga sozinho: ele acessa sessões ativas do WhatsApp Web e do Outlook instalados na máquina e envia mensagens para os contatos da vítima com links para baixar o próprio malware.
www.tecmundo.com.br
May 6, 2026 at 10:07 PM
📰 Waspada TCLBanker: Malware Perbankan Baru yang Menyebar Otomatis via WhatsApp dan Outlook

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/05/08/tclbanker-malware-perbankan-baru-menyebar-otomatis-via-whatsapp-dan-outlook/

#ahm
an#ahmandonkTechNewst#beritaTeknologit#elasticSecurity#info
May 8, 2026 at 8:44 AM
cybersecuritynews.com/tclbanker-ma...

TCLBANKER Malware Targets Users Through Self-Propagating WhatsApp and Outlook Worm Modules
TCLBANKER Malware Targets Users Through Self-Propagating WhatsApp and Outlook Worm Modules
A highly sophisticated Brazilian banking trojan named TCLBANKER, tracked under the campaign REF3076. a major update to the older Maverick.
cybersecuritynews.com
May 11, 2026 at 1:45 PM