TCLBANKER: Brazilian Banking Trojan Spreading via WhatsApp and Outlook
CYBERSECURITY FEATURED ANALYSIS

TCLBANKER: Brazilian Banking Trojan Spreading via WhatsApp and Outlook

SOURCE

Elastic Security Labs

DATE

READ

1 min read

REF3076 uses a trojanized Logitech installer to deploy TCLBANKER, a Brazilian banking trojan with environment-gated payloads, WPF fraud overlays, and self-propagating WhatsApp and Outlook worm modules.

REF3076 uses a trojanized Logitech installer to deploy TCLBANKER, a Brazilian banking trojan with environment-gated payloads, WPF fraud overlays, and self-propagating WhatsApp and Outlook worm modules.