Briefing

Brazilian Banking Trojan TCLBANKER Targets 59 Platforms, Spreads via WhatsApp and Outlook

security
by Bill Toulas ·

Detect and block TCLBanker by monitoring for DLL side‑loading of Logitech AI Prompt Builder and blocking its WebSocket C2 connections.

What to do now

Implement endpoint detection to block DLL side‑loading of Logitech AI Prompt Builder and block outbound WebSocket connections to known C2 domains.

Summary

A newly identified banking trojan, dubbed TCLBANKER, has been uncovered by threat hunters and is already showing signs of self‑propagation through popular messaging and email services such as WhatsApp and Outlook. The malware, tracked by Elastic Security Labs under the code name REF3076, is believed to be a major evolution of the Maverick family, which previously relied on the SORVEPOTEL worm to spread through network shares and removable media. Unlike its predecessor, TCLBANKER adds sophisticated banking‑stealing modules that can harvest credentials and financial data from a wide range of banking, fintech, and cryptocurrency platforms.

The trojan’s reach is alarming: it can target 59 different financial services, including major banks, payment processors, and crypto exchanges. Analysts warn that the threat is still in the early stages of deployment, but its extensive target list raises concerns for institutions worldwide. Security teams are urged to monitor for the SORVEPOTEL worm’s activity and block known TCLBANKER indicators, such as malicious file hashes and suspicious network traffic patterns. Early detection and containment are critical, as the malware’s ability to exfiltrate sensitive data could lead to significant financial losses and reputational damage for affected organizations.

The discovery of TCLBANKER underscores the growing sophistication of cybercriminals in the financial sector. By leveraging widely used communication platforms for distribution, the attackers can bypass traditional security controls and reach a broader audience. The incident highlights the need for continuous threat intelligence sharing and robust endpoint protection, especially for institutions that handle high volumes of digital transactions. As the threat landscape evolves, cybersecurity professionals must remain vigilant and adapt their defenses to counter emerging malware families like TCLBANKER.

Key changes

  • Uses trojanized MSI installer for Logitech AI Prompt Builder to DLL side‑load malware
  • Self‑spreading worm modules for WhatsApp and Outlook harvest contacts and send spam from victim’s account
  • Persistent watchdog thread hunts for debugging tools (x64dbg, IDA, Frida, etc.) and uses environment‑dependent payload decryption that fails in sandboxes
  • Spoofs Windows Update, bank support, and other fake credential prompts via WPF overlay with cut‑out windows
  • Monitors browser address bar for 59 targeted banking, fintech, crypto platforms and opens WebSocket to C2 for remote control
  • Propagates via WhatsApp Web IndexedDB data and Outlook COM automation
  • Development appears to use AI‑generated code, indicated by sophisticated obfuscation and anti‑analysis techniques
  • Targets Brazilian numbers, focusing on Brazil but with potential to expand

Affects

none

Source angles · 2 perspectives

Bleeping Computer
Independent angle

New TCLBanker malware self-spreads over WhatsApp and Outlook

Open
The Hacker News
Independent angle

Brazilian Banking Trojan TCLBANKER Targets 59 Platforms

Open

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting