CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

TCLBANKER: Brazilian Banking Trojan Spreading via WhatsApp and Outlook

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 621

As cited

Copy frozen at (site build).

threat intel

TCLBANKER: Brazilian Banking Trojan Spreading via WhatsApp and Outlook

Elastic Security Labs identified TCLBANKER, a Brazilian banking trojan that represents a significant evolution of the MAVERICK/SORVEPOTEL malware family. The malware uses a loader with extensive anti-analysis capabilities to deploy a banking trojan targeting 59 Brazilian financial institutions and a worm module that spreads via compromised WhatsApp and Outlook accounts. The infrastructure is hosted on Cloudflare Workers and shows signs of early-stage operations with debug artifacts and incomplete phishing pages.

Why it matters: Brazilian financial institution customers and organizations supporting them need to monitor for MSI installers bundled in ZIP files and educate users about WhatsApp and email messages from contacts, as the malware hijacks authenticated sessions to propagate to victims' contact lists.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

TCLBANKER: Brazilian Banking Trojan Spreading via WhatsApp and Outlook

Elastic Security Labs identified TCLBANKER, a Brazilian banking trojan that represents a significant evolution of the MAVERICK/SORVEPOTEL malware family. The malware uses a loader with extensive anti-analysis capabilities to deploy a banking trojan targeting 59 Brazilian financial institutions and a worm module that spreads via compromised WhatsApp and Outlook accounts. The infrastructure is hosted on Cloudflare Workers and shows signs of early-stage operations with debug artifacts and incomplete phishing pages.

Why it matters: Brazilian financial institution customers and organizations supporting them need to monitor for MSI installers bundled in ZIP files and educate users about WhatsApp and email messages from contacts, as the malware hijacks authenticated sessions to propagate to victims' contact lists.

VendorsMicrosoftCloudflare
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary