New TCLBanker malware self-spreads over WhatsApp and Outlook
AI-summarised brief · reviewed before publication
A new trojan named TCLBanker targets 59 banking, fintech, and cryptocurrency platforms, using a trojanized MSI installer to infect systems and self-spreading worm modules for WhatsApp and Outlook. Discovered by Elastic Security Labs, it's believed to be a major evolution of the Maverick/Sorvepotel malware family, currently focused in Brazil, but with potential to expand. The malware is well-protected against analysis and features environment-dependent payload decryption routines.
💡 Why It Matters
- · TCLBanker's ability to autonomously propagate to contacts linked to the primary victim poses a significant threat to individual users and organizations.
- · Its use of social engineering tactics, such as fake credential prompts and overlays, can lead to significant financial losses.