New TCLBanker malware self-spreads over WhatsApp and Outlook
bleepingcomputer.com May 8, 2026

New TCLBanker malware self-spreads over WhatsApp and Outlook

AI-summarised brief · reviewed before publication

A new trojan named TCLBanker targets 59 banking, fintech, and cryptocurrency platforms, using a trojanized MSI installer to infect systems and self-spreading worm modules for WhatsApp and Outlook. Discovered by Elastic Security Labs, it's believed to be a major evolution of the Maverick/Sorvepotel malware family, currently focused in Brazil, but with potential to expand. The malware is well-protected against analysis and features environment-dependent payload decryption routines.

💡 Why It Matters

  • · TCLBanker's ability to autonomously propagate to contacts linked to the primary victim poses a significant threat to individual users and organizations.
  • · Its use of social engineering tactics, such as fake credential prompts and overlays, can lead to significant financial losses.