BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Brazilian Banking Trojan Targets Crypto Platforms

Brazilian TCLBANKER banking trojan targets 59 platforms, steals via overlays, spreads via WhatsApp and Outlook.

  • Cybersecurity researchers have uncovered a new Brazilian banking trojan named TCLBANKER, which targets 59 banking, fintech, and cryptocurrency platforms.
  • The malware spreads via malicious MSI installers and employs sophisticated anti-analysis checks, including generating a unique environment hash to decrypt its payload.
  • It features real-time social engineering and credential theft via overlays, and hijacks victims’ WhatsApp Web sessions and Microsoft Outlook accounts for further propagation.

Threat hunters have identified a previously undocumented Brazilian banking trojan, dubbed TCLBANKER, which is capable of targeting 59 banking, fintech, and cryptocurrency platforms. The activity is being tracked by Elastic Security Labs under the moniker REF3076.

- Advertisement -

At the infection chain’s core is a malicious MSI installer bundled inside a ZIP file, which abuses a signed Logitech program. This installer deploys a loader with a comprehensive watchdog subsystem to evade analysis tools, as explained by security researchers.

The loader performs rigorous anti-debugging and system checks to create an environment hash for payload decryption. Consequently, the trojan only executes if it confirms the system’s default language is Brazilian Portuguese.

Once active, the banking trojan establishes persistence and beacons to an external server. It also monitors URLs from major browsers and matches them against a hard-coded list of targeted financial institutions.

Upon a match, it establishes a WebSocket connection, enabling remote operators to run commands. These capabilities include capturing screenshots, starting a keylogger, and serving fake credential-stealing overlays.

- Advertisement -

For data theft, TCLBANKER uses a WPF-based overlay framework to display convincing social engineering prompts. Meanwhile, its worming module propagates the trojan via hijacked WhatsApp Web sessions and a Microsoft Outlook email spambot.

The WhatsApp worm uses templates from a server and leverages the UI Automation project to automate messages. Conversely, the Outlook agent sends phishing emails from the victim’s own account to bypass spam filters.

Elastic concluded that “TCLBANKER reflects a broader maturation happening across the Brazilian banking trojan ecosystem.” This distribution model hijacks the trust of legitimate communications, making it difficult for traditional defenses to catch.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Audit Gap Exposed As AI Finds Major Four-Year Crypto Bug

A critical four-year-old bug in ZCash's shielded pool, discovered in June 2026, wiped out...

Z.ai’s GLM-5.2 Nears Claude Opus, Beats GPT-5.5, MIT Licensed

Z.ai released the GLM-5.2 AI model, which performs within 1% of Claude Opus 4.8...

Strategy loses 40 years of dividend coverage in 7 months

Strategy lost 40 years of forecasted dividend coverage in just seven months.The coverage decline...

HIVE to deploy GPUs for Cohere in $220M AI cloud deal

HIVE Digital Technologies has signed a major three-year GPU cloud contract with Bell AI...

Apple warns of price hikes due to soaring AI chip costs

Apple CEO Tim Cook confirmed unavoidable price increases for most products due to soaring...

Must Read

Best Crypto Audiobooks of 2026: The Ultimate Listen & Learn Guide

You can't read Bitcoin charts while driving 70 mph on the highway. You can't study Ethereum whitepapers during your morning run. But you can...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading