{"id":214797,"date":"2026-05-17T03:45:08","date_gmt":"2026-05-17T07:45:08","guid":{"rendered":"https:\/\/testing.news-you-need.com\/index.php\/2026\/05\/17\/tclbanker-banking-trojan-targets-financial-platforms-via-whatsapp-and-outlook-worms\/"},"modified":"2026-05-17T03:45:10","modified_gmt":"2026-05-17T07:45:10","slug":"tclbanker-banking-trojan-targets-financial-platforms-via-whatsapp-and-outlook-worms","status":"publish","type":"post","link":"https:\/\/testing.news-you-need.com\/index.php\/2026\/05\/17\/tclbanker-banking-trojan-targets-financial-platforms-via-whatsapp-and-outlook-worms\/","title":{"rendered":"TCLBANKER Banking Trojan Targets Financial Platforms via WhatsApp and Outlook Worms"},"content":{"rendered":"<p><a href=\"https:\/\/thehackernews.com\/2026\/05\/tclbanker-banking-trojan-targets.html\">TCLBANKER Banking Trojan Targets Financial Platforms via WhatsApp and Outlook Worms<\/a><\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/05\/tclbanker-banking-trojan-targets.html\">https:\/\/thehackernews.com\/2026\/05\/tclbanker-banking-trojan-targets.html<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-05-08 14:12:00<\/a><\/p>\n<p>Source Domain: <a href=\"thehackernews.com\">thehackernews.com<\/a><\/p>\n<p><strong>Summary:<\/strong><br \/>\nSecurity experts from Elastic Security Labs have identified TCLBANKER, a new banking trojan initially undocumented that targets 59 Brazilian financial institutions, fintech services, and cryptocurrency platforms. This malware, named REF3076, is a major evolution of the well-known Maverick family, with the threat activity attributed to the Water Saci cluster. Its attack chain involves a robust loader with embedded modules for both a trojan and a worm that propagates via WhatsApp and Microsoft Outlook messages. The trojan employs multiple anti-analysis methods to evade detection and leverages DLL side-loading using a signed Logitech program, and also hijacks the victim\u2019s WhatsApp and Outlook sessions to widely distribute itself. The malware contains comprehensive features for credential theft, remote control, and persistence mechanisms and appears to be still developing as suggested by debug paths in its code.<\/p>\n<p><strong>Key Points:<\/strong><\/p>\n<ul>\n<li>\n<p><strong>TCLBANKER is an Update:<\/strong> TCLBANKER is a refined version of the Maverick family, targeting 59 financial institutions including banks, fintech, and crypto platforms in Brazil.<\/p>\n<\/li>\n<li>\n<p><strong>Advanced Distribution and Evasion:<\/strong> The malware uses a loader with anti-analysis features, alongside a worm component that spreads via WhatsApp Web and Microsoft Outlook.<\/p>\n<\/li>\n<li>\n<p>**Integration with Legitimate &#8211; The generated text has been blocked by our content filters.<\/p>\n<\/li>\n<\/ul>\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>TCLBANKER Banking Trojan Targets Financial Platforms via WhatsApp and Outlook Worms https:\/\/thehackernews.com\/2026\/05\/tclbanker-banking-trojan-targets.html Publish Date: 2026-05-08&#8230;<\/p>\n","protected":false},"author":1,"featured_media":214799,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiWchpptUYeW4vXSUXfGq-uMzB1mr_dzsvX8XIWssIKzaWa4_eYbaLwec5Zos3xCoD0s8-LDcGI7Vj8DjFq6RtUY68HP21YudHYdsFS2xdyzQE7OPyuTlqyO2X9uwlSCRuVl9tAUwq0mvGuXlYkxjdmC7ynyAcIDpbejkR45ucf_L3VCDupSZMteOby7BUp\/s1700-e365\/banking.jpg","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[32],"class_list":["post-214797","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-malware"],"_links":{"self":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/214797"}],"collection":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=214797"}],"version-history":[{"count":1,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/214797\/revisions"}],"predecessor-version":[{"id":214801,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/214797\/revisions\/214801"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/214799"}],"wp:attachment":[{"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=214797"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=214797"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/testing.news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=214797"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}