Briefing

New Brazilian Banking Trojan TCLBANKER Targets 59 Platforms

security
by [email protected] (The Hacker News) ·

Patch anti‑malware signatures to detect TCLBANKER and block the SORVEPOTEL worm.

What to do now

Patch anti‑malware signatures to detect TCLBANKER and block the SORVEPOTEL worm.

Summary

Threat hunters have identified a previously undocumented trojan dubbed TCLBANKER that is actively targeting 59 banking, fintech, and cryptocurrency platforms across Brazil.

The malware is a major update of the Maverick family, which has historically leveraged the SORVEPOTEL worm to spread through compromised systems. Elastic Security Labs tracks the activity under the moniker REF3076, noting that TCLBANKER can exfiltrate credentials and sensitive financial data. The trojan’s propagation mechanism relies on the SORVEPOTEL worm, allowing it to move laterally within networks with minimal user interaction. Analysts report that TCLBANKER has already infected several high‑profile institutions, raising concerns about potential data breaches. The threat is considered active, with ongoing monitoring by security teams worldwide. Organizations are urged to update anti‑malware signatures and implement network segmentation to contain the spread. Regular audits of authentication logs can help detect early signs of compromise.

Key changes

  • New trojan TCLBANKER discovered targeting 59 banking, fintech, and crypto platforms
  • Based on Maverick family, major update
  • Uses SORVEPOTEL worm for lateral propagation
  • Elastic Security Labs tracks it as REF3076
  • Capable of credential theft and data exfiltration
  • Active monitoring indicates ongoing infections

Affects

internal

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting