CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

Brazilian TCLBANKER malware evolves Maverick lineage with dual-worm propagation and advanced evasion

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

A new Brazilian banking trojan named TCLBANKER has been identified targeting 59 financial platforms via a loader that deploys both a banking trojan and a worm module propagating through WhatsApp Web and Microsoft Outlook. The malware leverages DLL side-loading against a signed Logitech application to bypass detection and employs environment-gated payload decryption using anti-debugging, anti-virtualization, and language checks. Once deployed, TCLBANKER establishes persistence, exfiltrates data via a WebSocket command loop, and uses fake credential-stealing overlays while hiding from screen capture tools. The worm component hijacks authenticated WhatsApp sessions and abuses Outlook to send phishing emails from compromised accounts, bypassing spam filters.

Timeline

  1. 08.05.2026 21:12 1 articles · 7h ago

    TCLBANKER banking trojan campaign expands Maverick lineage with dual-worm propagation and advanced evasion

    A new banking trojan, TCLBANKER, has been observed targeting 59 financial platforms using a loader that deploys both a banking trojan and a worm module. The malware abuses DLL side-loading against a signed Logitech application to bypass security controls and uses environment-gated payload decryption based on anti-debugging, anti-virtualization, and language checks. The banking trojan establishes persistence, exfiltrates system information, and communicates via WebSocket for command and control, enabling a range of malicious activities including credential harvesting via fake overlays. Concurrently, the worm component propagates through hijacked WhatsApp Web sessions and compromised Outlook accounts, bypassing spam filters and enhancing delivery efficacy.

    Show sources

Information Snippets