www.elastic.co
TCLBANKER Trojan Targets Brazilian Financial Sector via Logitech Installer
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A new banking trojan named TCLBANKER has emerged, targeting 59 Brazilian banking, fintech, and cryptocurrency platforms. Discovered by Elastic Security Labs, the malware utilizes a trojanized MSI installer of Logitech's AI Prompt Builder to infect systems stealthily. It features self-propagating worm modules that spread through WhatsApp and Outlook, hijacking authenticated sessions to message contacts and send phishing emails. The malware is designed to evade detection with robust anti-analysis techniques, including environment-dependent payloads and a persistent watchdog to eliminate debugging tools. Currently, the threat is primarily focused on Brazilian users, but there is potential for it to expand its targeting scope. The campaign is tracked as REF3076, and the malware's capabilities include monitoring browser activity and deploying fraudulent overlays to steal sensitive information.
Key Points: • TCLBANKER targets 59 Brazilian financial platforms using a trojanized Logitech installer. • The malware includes self-propagating worm modules for WhatsApp and Outlook. • It employs advanced anti-analysis techniques to evade detection and protect its operations.