Close Menu
Simply Invest Asia
  • Home
  • About us
  • Explore industries/sectors
    • Automobile
    • Aviation
    • Banking
    • Biotechnology
    • Chemical & Fertilizer
    • Entertainment and Media
    • Food Processing
    • Healthcare
    • Iron and Steel
    • Leather
    • Mining
    • Oil and Gas
    • Pharmaceutical
  • Explore by countries
    • China
    • Dubai / UAE
    • Hong Kong
    • India
    • Indonesia
    • Japan
    • Malaysia
  • Explore cities
    • Bangkok
    • Beijing
    • Chongqing
    • Delhi
    • Dubai
    • Guangzhou
    • Jakarta
    • Kuala Lumpur
  • Why Asia
Facebook X (Twitter) Instagram Threads
Trending:
  • Hong Kong financial firm founder pleads guilty in US to tax fraud scheme | MLex
  • Are UAE Schools Opening on Monday 11th May? MOE: Decision Deferred until Sunday
  • Mining company pulls out of controversial Pe’ Sla drilling project
  • Industry representatives of Norway, China call for deeper EV cooperation-Xinhua
  • India Makes Digital e-Arrival Card Mandatory 72 Hours Before Entry
  • Virgin Atlantic cancels Dubai route until 2027
  • Spain, Norway and Japan top the medal count at the Youth Skyrunning World Championships VERTICAL
  • Pukhraj Singh Gill retains lead at ADT Players Championship in Kuala Lumpur
  • Does GE HealthCare’s New Advanced Imaging Segment and Executive Shuffle Change The Bull Case For GEHC?
  • Jackie Chan’s martial arts flair in Turandot
  • Mount Dukono: Massive volcano kills hikers in Indonesia sparking emergency rescue mission
  • DVIDS – Video – DOW-UAP-PR27, Unresolved UAP Report, United Arab Emirates, October 2023
  • U.S. Steel Shipments Up 4.4% in Q1 2026; Imports Fall 35% YoY | AISI Data – News and Statistics
  • Inaugural Global Mediation Summit Boosts Hong Kong’s Status as a Global Mediation Hub
  • China confirms helping Pakistan down Indian aircraft last year
  • Former Chongqing official sentenced to death for bribery with two-year reprieve -Xinhua
  • IPL | RCB 77/1 (6.3) vs DC 75 (Virat Kohli 23(15) Devdutt Padikkal 34(13)) | Delhi Capitals vs Royal Challengers Bengaluru, 39th Match, Indian Premier League 2026 Live Cricket Stream, live scores, ball-by-ball commentary, highlights, videos, news, and more – Cricbuzz
  • Why “feasibility” is a dangerous, slippery slope for chemical reviews
Friday, May 8
Facebook X (Twitter) Instagram
Simply Invest Asia
  • Home
  • About us
  • Explore industries/sectors
    • Automobile
    • Aviation
    • Banking
    • Biotechnology
    • Chemical & Fertilizer
    • Entertainment and Media
    • Food Processing
    • Healthcare
    • Iron and Steel
    • Leather
    • Mining
    • Oil and Gas
    • Pharmaceutical
  • Explore by countries
    • China
    • Dubai / UAE
    • Hong Kong
    • India
    • Indonesia
    • Japan
    • Malaysia
  • Explore cities
    • Bangkok
    • Beijing
    • Chongqing
    • Delhi
    • Dubai
    • Guangzhou
    • Jakarta
    • Kuala Lumpur
  • Why Asia
Simply Invest Asia
Home»Explore industries/sectors»Banking»TCLBANKER Banking Trojan Targets Financial Platforms via WhatsApp and Outlook Worms
Banking

TCLBANKER Banking Trojan Targets Financial Platforms via WhatsApp and Outlook Worms

By IslaMay 8, 20264 Mins Read
Share
Facebook Twitter Pinterest Threads Bluesky Copy Link


Threat hunters have flagged a previously undocumented Brazilian banking trojan dubbed TCLBANKER that’s capable of targeting 59 banking, fintech, and cryptocurrency platforms.

The activity is being tracked by Elastic Security Labs under the moniker REF3076. The malware family is assessed to be a major update of the Maverick, which is known to leverage a worm called SORVEPOTEL to spread via WhatsApp Web to a victim’s contacts. The Maverick campaign is attributed to a threat cluster that Trend Micro calls Water Saci.

At the core of the attack chain is a loader with robust anti-analysis capabilities that deploys two embedded modules: a full-featured banking trojan and a worm component that uses WhatsApp and Microsoft Outlook for propagation.

“The observed infection chain bundles a malicious MSI installer inside a ZIP file,” security researchers Jia Yu Chan, Daniel Stepanic, Seth Goodwin, and Terrance DeJesus said. “These MSI installer packages are abusing a signed Logitech program called Logi AI Prompt Builder.”

The malware leverages DLL side-loading against the application to launch a malicious DLL (“screen_retriever_plugin.dll”), which functions as a loader with a “comprehensive watchdog subsystem” that continuously keeps an eye out for analysis tools, sandboxes, debuggers, disassemblers, instrumentation tools, and antivirus software to sidestep detection.

Specifically, the malicious DLL will only execute if it was loaded by either “logiaipromptbuilder.exe” (the Logitech program) or “tclloader.exe” (likely a reference to an executable used during testing). It also removes any usermode hooks placed by endpoint security software within “ntdll.dll” by replacing the library and disables Event Tracing for Windows (ETW) telemetry.

What’s more, the malware generates three fingerprints based on anti-debugging and anti-virtualization checks, system disk information checks, and language checks, using them to create an environment hash value that’s used to decrypt the embedded payload. The system language check ensures that the user’s default language is Brazilian Portuguese.

“For example, if a debugger is present, it will produce an incorrect hash, so when the malware attempts to derive the decryption keys from the hash, the payload will not decrypt correctly, and TCLBANKER will stop executing,” Elastic explained.

The main component launched following these checks is the banking trojan that once again verifies if it’s running on a Brazilian system, and then proceeds to establish persistence using a scheduled task.Subsequently, it beacons out to an external server with an HTTP POST request containing basic system information.

TCLBANKER also incorporates a self-update mechanism and a URL monitor that extracts the current URL from the foreground browser’s address bar using UI Automation. This step targets popular browsers like Google Chrome, Mozilla Firefox, Microsoft Edge, Brave, Opera, and Vivaldi.

The extracted URL is matched against a hard-coded list of targeted financial institutions. If there is a match, it establishes a WebSocket connection to a remote server and enters into a command dispatch loop, enabling the operator to perform a broad range of tasks –

  • Run shell commands
  • Capture screenshots
  • Start/stop screen streaming
  • Manipulate clipboard
  • Launch a keylogger
  • Remotely control mouse/keyboard
  • Manage files and processes
  • Enumerate running processes
  • List visible windows
  • Serve fake credential-stealing overlays

To conduct data theft, TCLBANKER relies on a Windows Presentation Foundation (WPF)-based full-screen overlay framework to conduct social engineering using credential harvesting prompts, vishing wait screens, bogus progress bars, and fake Windows Updates, all while hiding overlays from screen capture tools.

In tandem, the loader invokes the worming module to propagate the trojan via spam and phishing messages at scale. It employs a two-pronged approach that involves a WhatsApp Web worm that hijacks authenticated browser sessions and an Outlook email bot that abuses Microsoft Outlook to send fake emails to the victim’s contacts.

Like in the case of SORVEPOTEL, the WhatsApp worm retrieves a messaging template from the server and leverages the open-source project WPPConnect to automate the sending of messages to other users, while filtering out groups, broadcasts, and non-Brazilian numbers.

The Outlook agent, on the other hand, is an email spambot that abuses the victim’s installed Microsoft Outlook application to send phishing emails from the victim’s email address, thereby bypassing spam filters and giving the messages an illusion of trust.

“TCLBANKER reflects a broader maturation happening across the Brazilian banking trojan ecosystem,” Elastic concluded. “Techniques that were once the hallmark of more sophisticated threat actors: environment-gated payload decryption, direct syscall generation, real-time social engineering orchestration over WebSocket, are now being packaged into commodity crimeware.”

“The campaign inherits the trust and deliverability of legitimate communications by hijacking victims’ WhatsApp sessions and Outlook accounts. This is a distribution model that traditional email gateways and reputation-based defenses are ill-equipped to catch.”



Source link

Related Posts

Hostage situation unfolds at German bank

May 8, 2026

Kyndryl: The agentic AI shortcut to faster, cheaper and safer bank IT overhauls

May 8, 2026

Citi’s Investment Banking Boss: ‘We Can Get Whoever We Want’

May 7, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Abandoned malls, whispers of nuclear war and young foreigners detained. This is what’s REALLY going on in Dubai… and the chilling warning one taxi driver gave to the Mail’s IAN BIRRELL

April 11, 2026

Dubai food conglomerate IFFCO set to go into provisional liquidation – Financial Times

May 3, 2026

Asian Angle | Why Japan-China ties can benefit from promoting people-to-people exchanges

May 3, 2026
Don't Miss

Hong Kong financial firm founder pleads guilty in US to tax fraud scheme | MLex

By IslaMay 8, 2026

( May 8, 2026, 19:04 GMT | Official Statement) — MLex Summary: Roderic Sage, the founder and…

Are UAE Schools Opening on Monday 11th May? MOE: Decision Deferred until Sunday

May 8, 2026

Mining company pulls out of controversial Pe’ Sla drilling project

May 8, 2026

Industry representatives of Norway, China call for deeper EV cooperation-Xinhua

May 8, 2026
SUBSCRIBE TO OUR NEWSLETTER

Get our latest downloads and information first. Complete the form below to subscribe to our weekly newsletter.


I consent to being contacted via telephone and/or email and I consent to my data being stored in accordance with European GDPR regulations and agree to the terms of use and privacy policy.

Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Top Trending

U.S. Steel Shipments Up 4.4% in Q1 2026; Imports Fall 35% YoY | AISI Data – News and Statistics

By IslaMay 8, 2026

Inaugural Global Mediation Summit Boosts Hong Kong’s Status as a Global Mediation Hub

By IslaMay 8, 2026

China confirms helping Pakistan down Indian aircraft last year

By IslaMay 8, 2026
Most Popular

Indonesia Stock Exchange Sees 15 Firms Lined Up for IPOs

May 3, 2026

Mainland’s Victory Giant seeks up to $2.2b in HKSAR listing

April 13, 2026

Guangzhou historic district comes into focus through films, food

May 2, 2026
Our Picks

Lodhi Garden at 90: Delhi’s timeless green haven blends history, heritage and urban calm

April 9, 2026

Sheikh Mohammed Honours Erth Dubai Awards Winners for Preserving City’s Heritage and Living Memory

April 30, 2026

Eco (Atlantic) Oil and Gas Ltd. Announces JHI Acquisition

April 30, 2026
SUBSCRIBE TO OUR NEWSLETTER

Get our latest downloads and information first. Complete the form below to subscribe to our weekly newsletter.


I consent to being contacted via telephone and/or email and I consent to my data being stored in accordance with European GDPR regulations and agree to the terms of use and privacy policy.

© 2026 Simply Invest Asia.
  • Get In Touch
  • Cookie Policy
  • Privacy policy
  • Terms & Conditions

Type above and press Enter to search. Press Esc to cancel.

SUBSCRIBE TO OUR NEWSLETTER

Get our latest downloads and information first.

Complete the form below to subscribe to our weekly newsletter.


I consent to being contacted via telephone and/or email and I consent to my data being stored in accordance with European GDPR regulations and agree to the terms of use and privacy policy.