Close Menu
Simply Invest Asia
  • Home
  • About us
  • Explore industries/sectors
    • Automobile
    • Aviation
    • Banking
    • Biotechnology
    • Chemical & Fertilizer
    • Entertainment and Media
    • Food Processing
    • Healthcare
    • Iron and Steel
    • Leather
    • Mining
    • Oil and Gas
    • Pharmaceutical
  • Explore by countries
    • China
    • Dubai / UAE
    • Hong Kong
    • India
    • Indonesia
    • Japan
    • Malaysia
  • Explore cities
    • Bangkok
    • Beijing
    • Chongqing
    • Delhi
    • Dubai
    • Guangzhou
    • Jakarta
    • Kuala Lumpur
  • Why Asia
Facebook X (Twitter) Instagram Threads
Trending:
  • Jackie Chan’s martial arts flair in Turandot
  • Mount Dukono: Massive volcano kills hikers in Indonesia sparking emergency rescue mission
  • DVIDS – Video – DOW-UAP-PR27, Unresolved UAP Report, United Arab Emirates, October 2023
  • U.S. Steel Shipments Up 4.4% in Q1 2026; Imports Fall 35% YoY | AISI Data – News and Statistics
  • Inaugural Global Mediation Summit Boosts Hong Kong’s Status as a Global Mediation Hub
  • China confirms helping Pakistan down Indian aircraft last year
  • Former Chongqing official sentenced to death for bribery with two-year reprieve -Xinhua
  • IPL | RCB 77/1 (6.3) vs DC 75 (Virat Kohli 23(15) Devdutt Padikkal 34(13)) | Delhi Capitals vs Royal Challengers Bengaluru, 39th Match, Indian Premier League 2026 Live Cricket Stream, live scores, ball-by-ball commentary, highlights, videos, news, and more – Cricbuzz
  • Why “feasibility” is a dangerous, slippery slope for chemical reviews
  • Forget Phuket, Malaysia is where the in-the-know are heading
  • How Next Gen Beijing Cup boosts development for Premier League academies and Chinese game
  • TCLBANKER Banking Trojan Targets Financial Platforms via WhatsApp and Outlook Worms
  • China payments firm chases LatAm trade boom – BNamericas
  • The Proposed European Biotech Act, 100 Days On | Jones Day
  • My Dubai Salary: ‘I earn Dh20,000 a month sailing Dubai’s waters’
  • HabitTrade denies doing regulated business in Hong Kong after SFC warning
  • Blake Lively Litigation Highlights Workplace Compliance Risks for Entertainment and Media Employers: 7 Practical Tips | Fisher Phillips
  • CE-SDS / icIEF Systems Market in Japan | Report – IndexBox
Friday, May 8
Facebook X (Twitter) Instagram
Simply Invest Asia
  • Home
  • About us
  • Explore industries/sectors
    • Automobile
    • Aviation
    • Banking
    • Biotechnology
    • Chemical & Fertilizer
    • Entertainment and Media
    • Food Processing
    • Healthcare
    • Iron and Steel
    • Leather
    • Mining
    • Oil and Gas
    • Pharmaceutical
  • Explore by countries
    • China
    • Dubai / UAE
    • Hong Kong
    • India
    • Indonesia
    • Japan
    • Malaysia
  • Explore cities
    • Bangkok
    • Beijing
    • Chongqing
    • Delhi
    • Dubai
    • Guangzhou
    • Jakarta
    • Kuala Lumpur
  • Why Asia
Simply Invest Asia
Home»Explore industries/sectors»Banking»TCLBANKER Banking Trojan Targets Financial Platforms via WhatsApp and Outlook Worms
Banking

TCLBANKER Banking Trojan Targets Financial Platforms via WhatsApp and Outlook Worms

By IslaMay 8, 20264 Mins Read
Share
Facebook Twitter Pinterest Threads Bluesky Copy Link


Threat hunters have flagged a previously undocumented Brazilian banking trojan dubbed TCLBANKER that’s capable of targeting 59 banking, fintech, and cryptocurrency platforms.

The activity is being tracked by Elastic Security Labs under the moniker REF3076. The malware family is assessed to be a major update of the Maverick, which is known to leverage a worm called SORVEPOTEL to spread via WhatsApp Web to a victim’s contacts. The Maverick campaign is attributed to a threat cluster that Trend Micro calls Water Saci.

At the core of the attack chain is a loader with robust anti-analysis capabilities that deploys two embedded modules: a full-featured banking trojan and a worm component that uses WhatsApp and Microsoft Outlook for propagation.

“The observed infection chain bundles a malicious MSI installer inside a ZIP file,” security researchers Jia Yu Chan, Daniel Stepanic, Seth Goodwin, and Terrance DeJesus said. “These MSI installer packages are abusing a signed Logitech program called Logi AI Prompt Builder.”

The malware leverages DLL side-loading against the application to launch a malicious DLL (“screen_retriever_plugin.dll”), which functions as a loader with a “comprehensive watchdog subsystem” that continuously keeps an eye out for analysis tools, sandboxes, debuggers, disassemblers, instrumentation tools, and antivirus software to sidestep detection.

Specifically, the malicious DLL will only execute if it was loaded by either “logiaipromptbuilder.exe” (the Logitech program) or “tclloader.exe” (likely a reference to an executable used during testing). It also removes any usermode hooks placed by endpoint security software within “ntdll.dll” by replacing the library and disables Event Tracing for Windows (ETW) telemetry.

What’s more, the malware generates three fingerprints based on anti-debugging and anti-virtualization checks, system disk information checks, and language checks, using them to create an environment hash value that’s used to decrypt the embedded payload. The system language check ensures that the user’s default language is Brazilian Portuguese.

“For example, if a debugger is present, it will produce an incorrect hash, so when the malware attempts to derive the decryption keys from the hash, the payload will not decrypt correctly, and TCLBANKER will stop executing,” Elastic explained.

The main component launched following these checks is the banking trojan that once again verifies if it’s running on a Brazilian system, and then proceeds to establish persistence using a scheduled task.Subsequently, it beacons out to an external server with an HTTP POST request containing basic system information.

TCLBANKER also incorporates a self-update mechanism and a URL monitor that extracts the current URL from the foreground browser’s address bar using UI Automation. This step targets popular browsers like Google Chrome, Mozilla Firefox, Microsoft Edge, Brave, Opera, and Vivaldi.

The extracted URL is matched against a hard-coded list of targeted financial institutions. If there is a match, it establishes a WebSocket connection to a remote server and enters into a command dispatch loop, enabling the operator to perform a broad range of tasks –

  • Run shell commands
  • Capture screenshots
  • Start/stop screen streaming
  • Manipulate clipboard
  • Launch a keylogger
  • Remotely control mouse/keyboard
  • Manage files and processes
  • Enumerate running processes
  • List visible windows
  • Serve fake credential-stealing overlays

To conduct data theft, TCLBANKER relies on a Windows Presentation Foundation (WPF)-based full-screen overlay framework to conduct social engineering using credential harvesting prompts, vishing wait screens, bogus progress bars, and fake Windows Updates, all while hiding overlays from screen capture tools.

In tandem, the loader invokes the worming module to propagate the trojan via spam and phishing messages at scale. It employs a two-pronged approach that involves a WhatsApp Web worm that hijacks authenticated browser sessions and an Outlook email bot that abuses Microsoft Outlook to send fake emails to the victim’s contacts.

Like in the case of SORVEPOTEL, the WhatsApp worm retrieves a messaging template from the server and leverages the open-source project WPPConnect to automate the sending of messages to other users, while filtering out groups, broadcasts, and non-Brazilian numbers.

The Outlook agent, on the other hand, is an email spambot that abuses the victim’s installed Microsoft Outlook application to send phishing emails from the victim’s email address, thereby bypassing spam filters and giving the messages an illusion of trust.

“TCLBANKER reflects a broader maturation happening across the Brazilian banking trojan ecosystem,” Elastic concluded. “Techniques that were once the hallmark of more sophisticated threat actors: environment-gated payload decryption, direct syscall generation, real-time social engineering orchestration over WebSocket, are now being packaged into commodity crimeware.”

“The campaign inherits the trust and deliverability of legitimate communications by hijacking victims’ WhatsApp sessions and Outlook accounts. This is a distribution model that traditional email gateways and reputation-based defenses are ill-equipped to catch.”



Source link

Related Posts

Hostage situation unfolds at German bank

May 8, 2026

Kyndryl: The agentic AI shortcut to faster, cheaper and safer bank IT overhauls

May 8, 2026

Citi’s Investment Banking Boss: ‘We Can Get Whoever We Want’

May 7, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Abandoned malls, whispers of nuclear war and young foreigners detained. This is what’s REALLY going on in Dubai… and the chilling warning one taxi driver gave to the Mail’s IAN BIRRELL

April 11, 2026

Dubai food conglomerate IFFCO set to go into provisional liquidation – Financial Times

May 3, 2026

Asian Angle | Why Japan-China ties can benefit from promoting people-to-people exchanges

May 3, 2026
Don't Miss

Jackie Chan’s martial arts flair in Turandot

By IslaMay 8, 2026

A scene from Turandot at the Guangzhou Opera House on May 8, 2026. The production,…

Mount Dukono: Massive volcano kills hikers in Indonesia sparking emergency rescue mission

May 8, 2026

DVIDS – Video – DOW-UAP-PR27, Unresolved UAP Report, United Arab Emirates, October 2023

May 8, 2026

U.S. Steel Shipments Up 4.4% in Q1 2026; Imports Fall 35% YoY | AISI Data – News and Statistics

May 8, 2026
SUBSCRIBE TO OUR NEWSLETTER

Get our latest downloads and information first. Complete the form below to subscribe to our weekly newsletter.


I consent to being contacted via telephone and/or email and I consent to my data being stored in accordance with European GDPR regulations and agree to the terms of use and privacy policy.

Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Top Trending

China payments firm chases LatAm trade boom – BNamericas

By IslaMay 8, 2026

The Proposed European Biotech Act, 100 Days On | Jones Day

By IslaMay 8, 2026

My Dubai Salary: ‘I earn Dh20,000 a month sailing Dubai’s waters’

By IslaMay 8, 2026
Most Popular

Discovery renews confirmation that Mars had the “chemistry for life”

April 30, 2026

Goodwill Entertainment Expands to Malaysia with Flagship Multi-Entertainment Outlet in Kuala Lumpur – Minichart

April 18, 2026

It’s big enough to swallow cities, deep enough to hide skyscrapers and inside lies an ancient, thriving ‘lost world’ cut off from everything above

April 26, 2026
Our Picks

REVEALED: UAE Etihad Rail full station list ahead of 2026 launch

April 20, 2026

UAE schools, universities to switch to distance learning – ARN News Centre

May 5, 2026

China’s Toughest Regulations on Fireworks to Take Effect

April 24, 2026
SUBSCRIBE TO OUR NEWSLETTER

Get our latest downloads and information first. Complete the form below to subscribe to our weekly newsletter.


I consent to being contacted via telephone and/or email and I consent to my data being stored in accordance with European GDPR regulations and agree to the terms of use and privacy policy.

© 2026 Simply Invest Asia.
  • Get In Touch
  • Cookie Policy
  • Privacy policy
  • Terms & Conditions

Type above and press Enter to search. Press Esc to cancel.

SUBSCRIBE TO OUR NEWSLETTER

Get our latest downloads and information first.

Complete the form below to subscribe to our weekly newsletter.


I consent to being contacted via telephone and/or email and I consent to my data being stored in accordance with European GDPR regulations and agree to the terms of use and privacy policy.