{"id":12737,"date":"2026-05-09T10:03:48","date_gmt":"2026-05-09T10:03:48","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/05\/09\/tclbanker-malware-targets-users-through-self-propagating-whatsapp-and-outlook-worm-modules\/"},"modified":"2026-05-09T10:03:48","modified_gmt":"2026-05-09T10:03:48","slug":"tclbanker-malware-targets-users-through-self-propagating-whatsapp-and-outlook-worm-modules","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/05\/09\/tclbanker-malware-targets-users-through-self-propagating-whatsapp-and-outlook-worm-modules\/","title":{"rendered":"TCLBANKER Malware Targets Users Through Self-Propagating WhatsApp and Outlook Worm Modules"},"content":{"rendered":"<p>    TCLBANKER Malware Targets Users Through Self-Propagating WhatsApp and Outlook Worm Modules<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A highly sophisticated Brazilian banking trojan named <a href=\"https:\/\/cybersecuritynews.com\/hackers-abuse-signed-logitech-installer-tclbanker\/\" target=\"_blank\" rel=\"noreferrer noopener\">TCLBANKER, tracked under the campaign REF3076<\/a>, this malware represents a major update to the older Maverick and SORVEPOTEL families. <\/p>\n<p>It stands out because it uses a fake, signed Logitech installer to infect systems and spreads automatically via WhatsApp and Microsoft Outlook.<\/p>\n<p>The attack begins when a user downloads a malicious ZIP file. Inside this archive is an installer that abuses a real, digitally signed Logitech program called Logi AI Prompt Builder.<\/p>\n<figure class=\"wp-block-image size-full\"><img data-recalc-dims=\"1\" fetchpriority=\"high\" decoding=\"async\" width=\"843\" height=\"389\" src=\"https:\/\/i0.wp.com\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-24.png?resize=843%2C389&#038;ssl=1\" alt=\"File directory contents showing a malicious DLL (Source: Elastic)\" class=\"wp-image-149559\" srcset=\"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-24.png 843w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-24-300x138.png 300w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-24-768x354.png 768w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-24-150x69.png 150w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-24-696x321.png 696w\" sizes=\"(max-width: 843px) 100vw, 843px\"><figcaption class=\"wp-element-caption\"><em>File directory contents showing a malicious DLL<\/em> (Source: Elastic)<\/figcaption><\/figure>\n<p> By using a technique known as DLL side-loading, the hackers trick the legitimate Logitech application into loading a malicious file instead of its normal system components. Once activated, this hidden loader takes control of the system to prepare the next stages of the attack.<\/p>\n<figure class=\"wp-block-image size-full\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"778\" height=\"460\" src=\"https:\/\/i0.wp.com\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-23.png?resize=778%2C460&#038;ssl=1\" alt=\"Targeted process names decrypted by TCLBANKER (Source: ELastic)\" class=\"wp-image-149558\" srcset=\"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-23.png 778w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-23-300x177.png 300w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-23-768x454.png 768w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-23-710x420.png 710w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-23-150x89.png 150w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-23-696x412.png 696w\" sizes=\"(max-width: 778px) 100vw, 778px\"><figcaption class=\"wp-element-caption\"><em>Targeted process names decrypted by TCLBANKER<\/em> (Source: ELastic)<\/figcaption><\/figure>\n<p>TCLBANKER is carefully built to hide from security researchers. Before it fully unpacks, it checks whether the computer is running in a security sandbox. It looks for <a href=\"https:\/\/cybersecuritynews.com\/code-security-tools\/\" type=\"post\" id=\"18874\" target=\"_blank\" rel=\"noreferrer noopener\">debugging tools<\/a>, virtual machines, and specific antivirus software. <\/p>\n<p>It also checks the system language and time zone to ensure the victim is actually located in Brazil. If the environment does not match a real Brazilian user, the payload refuses to decrypt, keeping the malware completely hidden from automated security scanners.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"303\" src=\"https:\/\/i0.wp.com\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-22-1024x303.png?resize=1024%2C303&#038;ssl=1\" alt=\"\nEncrypted bank\/fintech\/crypto domains(Source: Elastic)\" class=\"wp-image-149557\" srcset=\"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-22-1024x303.png 1024w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-22-300x89.png 300w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-22-768x228.png 768w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-22-150x44.png 150w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-22-696x206.png 696w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-22-1068x317.png 1068w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-22.png 1370w\" sizes=\"(max-width: 1024px) 100vw, 1024px\"><figcaption class=\"wp-element-caption\">Encrypted bank\/fintech\/crypto domains(Source: Elastic)<\/figcaption><\/figure>\n<h2 class=\"wp-block-heading\" id=\"h-tclbanker-malware-targets-users\"><strong>TCLBANKER Malware Targets Users<\/strong><\/h2>\n<p>Once the malware confirms it is on a real victim\u2019s machine, it launches the main banking trojan. <\/p>\n<p>This tool continuously monitors the user\u2019s web browser to detect whether the user visits one of 59 targeted banks, financial technology platforms, or cryptocurrency websites. When a match is found, the malware connects to a remote server.<\/p>\n<p>To steal passwords, the trojan uses full-screen overlays built with Microsoft\u2019s Windows Presentation Foundation. These overlays cover the entire screen and look exactly like real banking prompts or official Windows Update screens. <\/p>\n<figure class=\"wp-block-image size-full\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"950\" height=\"199\" src=\"https:\/\/i0.wp.com\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-21.png?resize=950%2C199&#038;ssl=1\" alt=\"Zip file containing TCLBANKER grabbed from the file server (Source: Elastic)\" class=\"wp-image-149556\" srcset=\"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-21.png 950w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-21-300x63.png 300w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-21-768x161.png 768w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-21-150x31.png 150w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-21-696x146.png 696w\" sizes=\"auto, (max-width: 950px) 100vw, 950px\"><figcaption class=\"wp-element-caption\">Zip file containing TCLBANKER grabbed from the file server (Source: Elastic)<\/figcaption><\/figure>\n<p>They freeze the desktop, block keyboard shortcuts such as the Windows key or Escape, and turn off screen-capture tools so the victim cannot record the fraud. The user is forced to enter their security codes or personal identification numbers directly into the hacker\u2019s fake screen.<\/p>\n<p>What makes TCLBANKER incredibly dangerous is its ability to spread automatically. The first worm <a href=\"https:\/\/cybersecuritynews.com\/whatsapp-web-code-hacked\/\" target=\"_blank\" rel=\"noreferrer noopener\">module targets WhatsApp Web<\/a>. The malware scans the computer for web browsers such as Chrome or Edge and looks for active WhatsApp accounts. <\/p>\n<figure class=\"wp-block-image size-full\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"845\" height=\"912\" src=\"https:\/\/i0.wp.com\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-20.png?resize=845%2C912&#038;ssl=1\" alt=\"WhatsApp Web profile cloning and session hijacking (Source: Eastic)\" class=\"wp-image-149555\" srcset=\"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-20.png 845w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-20-278x300.png 278w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-20-768x829.png 768w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-20-389x420.png 389w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-20-150x162.png 150w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-20-696x751.png 696w\" sizes=\"auto, (max-width: 845px) 100vw, 845px\"><figcaption class=\"wp-element-caption\">WhatsApp Web profile cloning and session hijacking (Source: Eastic)<\/figcaption><\/figure>\n<p>Instead of asking the user to scan a new QR code, the malware secretly clones the saved session data. It then opens a hidden browser window, bypasses bot detection, and sends phishing messages and the malware file directly to the victim\u2019s contacts. Because the messages come from a trusted friend, new victims are highly likely to download the file.<\/p>\n<p><a href=\"https:\/\/www.elastic.co\/security-labs\/tclbanker-brazilian-banking-trojan\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Elastic Security Labs has uncovered <\/a>that the second worm module focuses on email. It silently opens Microsoft Outlook in the background and uses Windows COM automation to take complete control of the victim\u2019s email account. <\/p>\n<p>The bot searches the address book and inbox to harvest contacts. It then drafts completely new phishing emails and sends them from the infected user\u2019s actual email address. This technique easily bypasses standard email security filters because the emails originate from a legitimate, trusted source.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"616\" src=\"https:\/\/i0.wp.com\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-19-1024x616.png?resize=1024%2C616&#038;ssl=1\" alt=\"Code related to filtering potential spam victim emails (Source: Elastic)\" class=\"wp-image-149554\" srcset=\"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-19-1024x616.png 1024w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-19-300x181.png 300w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-19-768x462.png 768w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-19-698x420.png 698w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-19-150x90.png 150w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-19-696x419.png 696w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-19-1068x643.png 1068w, https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2026\/05\/image-19.png 1494w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\"><figcaption class=\"wp-element-caption\"><em>Code related to filtering potential spam victim emails<\/em> (Source: Elastic)<\/figcaption><\/figure>\n<p>All of this malicious activity is managed using serverless cloud tools such as Cloudflare Workers. By using legitimate cloud services, the attackers can quickly change their servers and avoid being blocked by simple network defenses. <\/p>\n<p>The hackers also host their malicious files on Cloudflare, making the download links look safe to the average user. Researchers note that this campaign is still in its early stages, suggesting that the threat actors are likely preparing to expand their targets.<\/p>\n<p>To protect against TCLBANKER, organizations should look for unusual background processes spawned by Logitech applications. <\/p>\n<p>Security teams must monitor for unauthorized browser profile cloning and watch for unusual spikes in outbound emails from Microsoft Outlook. Using advanced endpoint protection that detects unauthorized full-screen overlays is also essential to keeping systems safe from this evolving threat.<\/p>\n<p><strong>IoC<\/strong><\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th class=\"has-text-align-left\" data-align=\"left\">Observable<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Type<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Name<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Reference<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">701d51b7be8b034c860bf97847bd59a87dca8481c4625328813746964995b626<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">SHA-256<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">screen_retriever_plugin.dll<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">TCLBanker loader component<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">8a174aa70a4396547045aef6c69eb0259bae1706880f4375af71085eeb537059<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">SHA-256<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">screen_retriever_plugin.dll<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">TCLBanker loader component<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">668f932433a24bbae89d60b24eee4a24808fc741f62c5a3043bb7c9152342f40<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">SHA-256<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">screen_retriever_plugin.dll<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">TCLBanker loader component<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">63beb7372098c03baab77e0dfc8e5dca5e0a7420f382708a4df79bed2d900394<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">SHA-256<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">XXL_21042026-181516.zip<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">TCLBanker initial ZIP file<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">campanha1-api.ef971a42[.]workers.dev<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">domain-name<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\"><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">TCLBanker C2<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">mxtestacionamentos[.]com<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">domain-name<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\"><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">TCLBanker C2<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">documents.ef971a42.workers[.]dev<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">domain-name<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\"><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">TCLBanker file server<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">arquivos-omie[.]com<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">domain-name<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\"><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">TCLBanker phishing page (under development)<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">documentos-online[.]com<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">domain-name<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\"><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">TCLBanker phishing page (under development)<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">afonsoferragista[.]com<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">domain-name<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\"><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">TCLBanker phishing page (under development)<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">doccompartilhe[.]com<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">domain-name<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\"><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">TCLBanker phishing page (under development)<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">recebamais[.]com<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">domain-name<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\"><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">TCLBanker phishing page (under development)<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p><strong>Note:<\/strong> <em>IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.<\/em><\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\"><strong>Cybercriminals now enter through your suppliers instead of your front door \u2013 <a href=\"https:\/\/www.manageengine.com\/products\/desktop-central\/webinars\/uk-cybersecurity-essentials-2026.html?utm_source=CSN&amp;utm_medium=TPS-mailer&amp;utm_campaign=UKCSW\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Free Webinar<\/a><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/tclbanker-malware-targets-users-whatsapp-outlook-worm-modules\/\">TCLBANKER Malware Targets Users Through Self-Propagating WhatsApp and Outlook Worm Modules<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Dhivya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/tclbanker-malware-targets-users-whatsapp-outlook-worm-modules\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>TCLBANKER Malware Targets Users Through Self-Propagating WhatsApp and Outlook Worm Modules A highly sophisticated Brazilian banking trojan named TCLBANKER, tracked under the campaign REF3076, this malware represents a major update to the older Maverick and SORVEPOTEL families. It stands out because it uses a fake, signed Logitech installer to infect systems and spreads automatically via [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,258,460],"tags":[130],"class_list":["post-12737","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-malware","category-whatsapp","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12737"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=12737"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12737\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=12737"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=12737"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=12737"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}