TCLBANKER Trojan Targets Brazilian Financial Sector via Logitech Installer

TCLBANKER Trojan Targets Brazilian Financial Sector via Logitech Installer

First seen 7 May 2026, 22:42 UTC Bleepingcomputerwww.elastic.coGbhackersCybersecuritynewsMexc+1 85% similarity 70.2

Article Content

Browse articles
ThreatCluster

A new banking trojan named TCLBANKER has emerged, targeting 59 Brazilian banking, fintech, and cryptocurrency platforms. Discovered by Elastic Security Labs, the malware utilizes a trojanized MSI installer of Logitech's AI Prompt Builder to infect systems stealthily. It features self-propagating worm modules that spread through WhatsApp and Outlook, hijacking authenticated sessions to message contacts and send phishing emails. The malware is designed to evade detection with robust anti-analysis techniques, including environment-dependent payloads and a persistent watchdog to eliminate debugging tools. Currently, the threat is primarily focused on Brazilian users, but there is potential for it to expand its targeting scope. The campaign is tracked as REF3076, and the malware's capabilities include monitoring browser activity and deploying fraudulent overlays to steal sensitive information.

Key Points: • TCLBANKER targets 59 Brazilian financial platforms using a trojanized Logitech installer. • The malware includes self-propagating worm modules for WhatsApp and Outlook. • It employs advanced anti-analysis techniques to evade detection and protect its operations.

ThreatCluster AI

Timeline

2026-05-07
TCLBANKER discovered by Elastic Security Labs
Researchers identified TCLBANKER as a significant evolution of the Maverick/Sorvepotel malware family targeting Brazilian users.
Elastic.co
2026-05-07
TCLBANKER's delivery method revealed
The malware is delivered via a trojanized MSI installer of Logitech's AI Prompt Builder, enabling stealthy infections.
BleepingComputer
2026-05-08
TCLBANKER's features detailed
The malware includes self-propagation modules and sophisticated UI overlays for data theft, targeting Brazilian banking sites.
Gbhackers
2026-05-08
TCLBANKER campaign tracked as REF3076
The ongoing campaign is noted for its clever use of a signed installer to bypass security measures.
Cybersecuritynews

Community

Browse all →