www.elastic.co TCLBANKER Trojan Targets Brazilian Financial Sector via Logitech Installer
Article Content
- •TCLBANKER targets 59 Brazilian financial platforms using a trojanized Logitech installer.
- •The malware includes self-propagating worm modules for WhatsApp and Outlook.
- •It employs advanced anti-analysis techniques to evade detection and protect its operations.
A new banking trojan named TCLBANKER has emerged, targeting 59 Brazilian banking, fintech, and cryptocurrency platforms. Discovered by Elastic Security Labs, the malware utilizes a trojanized MSI installer of Logitech's AI Prompt Builder to infect systems stealthily. It features self-propagating worm modules that spread through WhatsApp and Outlook, hijacking authenticated sessions to message contacts and send phishing emails. The malware is designed to evade detection with robust anti-analysis techniques, including environment-dependent payloads and a persistent watchdog to eliminate debugging tools. Currently, the threat is primarily focused on Brazilian users, but there is potential for it to expand its targeting scope. The campaign is tracked as REF3076, and the malware's capabilities include monitoring browser activity and deploying fraudulent overlays to steal sensitive information.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (8)
Following this threat?
Track Maverick and Logitech in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
BlueMoon Exploit Kit Targeting Chrome and Windows by Multiple State Actors A new exploit kit named BlueMoon has been rapidly adopted by at least four espionage groups, primarily linked to China, exploiting vulnerabilities in Google Chrome and Microsoft Windows. The first observed use of BlueMoon was on August 28, 2026, by the China-aligned threat actor TA412, with subsequent adoption by…