BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Brazilian Banking Trojan Targets Crypto Platforms

Brazilian TCLBANKER banking trojan targets 59 platforms, steals via overlays, spreads via WhatsApp and Outlook.

  • Cybersecurity researchers have uncovered a new Brazilian banking trojan named TCLBANKER, which targets 59 banking, fintech, and cryptocurrency platforms.
  • The malware spreads via malicious MSI installers and employs sophisticated anti-analysis checks, including generating a unique environment hash to decrypt its payload.
  • It features real-time social engineering and credential theft via overlays, and hijacks victims’ WhatsApp Web sessions and Microsoft Outlook accounts for further propagation.

Threat hunters have identified a previously undocumented Brazilian banking trojan, dubbed TCLBANKER, which is capable of targeting 59 banking, fintech, and cryptocurrency platforms. The activity is being tracked by Elastic Security Labs under the moniker REF3076.

- Advertisement -

At the infection chain’s core is a malicious MSI installer bundled inside a ZIP file, which abuses a signed Logitech program. This installer deploys a loader with a comprehensive watchdog subsystem to evade analysis tools, as explained by security researchers.

The loader performs rigorous anti-debugging and system checks to create an environment hash for payload decryption. Consequently, the trojan only executes if it confirms the system’s default language is Brazilian Portuguese.

Once active, the banking trojan establishes persistence and beacons to an external server. It also monitors URLs from major browsers and matches them against a hard-coded list of targeted financial institutions.

Upon a match, it establishes a WebSocket connection, enabling remote operators to run commands. These capabilities include capturing screenshots, starting a keylogger, and serving fake credential-stealing overlays.

- Advertisement -

For data theft, TCLBANKER uses a WPF-based overlay framework to display convincing social engineering prompts. Meanwhile, its worming module propagates the trojan via hijacked WhatsApp Web sessions and a Microsoft Outlook email spambot.

The WhatsApp worm uses templates from a server and leverages the UI Automation project to automate messages. Conversely, the Outlook agent sends phishing emails from the victim’s own account to bypass spam filters.

Elastic concluded that “TCLBANKER reflects a broader maturation happening across the Brazilian banking trojan ecosystem.” This distribution model hijacks the trust of legitimate communications, making it difficult for traditional defenses to catch.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

U.S. Approves First Bitcoin Perpetual Futures

The U.S. Commodity Futures Trading Commission (CFTC) approved the nation's first regulated Bitcoin perpetual...

Arabic NLP Research Gains EdgeCloud GPU Support

Researchers at Cairo University leveraged distributed GPU compute via Theta EdgeCloud to overcome infrastructure...

Bitcoin Buy Orders Stack $500M Near Key $70K Zone

More than $500 million in buy orders is clustered between $72,000 and $70,000, creating...

Robinhood Stock Rallies on New AI Trading Agents

Robinhood shares surged 17% in 30 days, breaking from their tight correlation with declining...

Celsius Founder Seeks to Overturn 12-Year Prison Term

Alex Mashinsky filed a motion to vacate his 12-year prison sentence for fraud.His motion...

Must Read

7 Best NFT Marketplaces for Every Need

Open Sea | Pianity | Foundation | Magic Eden | SuperRare | Rarible | Theta Drop | Other Platforms | About NFTs | FAQ...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading