216.73.216.226

TCLBANKER: Brazilian Banking Trojan Spreading via WhatsApp and Outlook

· Published 06/05/2026 19:35 · Modified 08/05/2026 08:47

Export JSON

Essential information

Published
06/05/2026 19:35
Modified
08/05/2026 08:47
Tags
2026-05-06 maverick sorvepotel tclbanker whatsapp worm
Related entities
4 observables, 1 intrusion sets (apt), 3 malware, 9 others

Description

A sophisticated Brazilian banking trojan named has been identified, representing a significant evolution of the / malware family. The campaign employs a trojanized Logitech installer that deploys two .NET Reactor-protected modules through DLL side-loading. The banking trojan monitors 59 Brazilian financial institutions using UI Automation and features a WPF-based full-screen overlay framework for operator-driven social engineering attacks, including credential harvesting and fake system screens. A secondary worm module enables self-propagation through WhatsApp session hijacking and Outlook COM automation, sending phishing messages from victims' own accounts. The malware implements robust anti-analysis capabilities including environment-gated payload decryption, comprehensive watchdog systems, and ETW patching. Infrastructure is hosted on Cloudflare Workers, with evidence suggesting the campaign was detected in early operational stages.

External references