← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
TCLBANKER: Brazilian Banking Trojan Spreading via WhatsApp and Outlook
A sophisticated Brazilian banking trojan named TCLBANKER has been identified, representing a significant evolution of the MAVERICK/SORVEPOTEL malware family. The campaign employs a trojanized Logitech installer that deploys two .NET Reactor-protected modules through DLL side-loading. The banking trojan monitors 59 Brazilian financial institutions using UI Automation and features a WPF-based full-screen overlay framework for operator-driven social engineering attacks, including credential harvesting and fake system screens. A secondary worm module enables self-propagation through WhatsApp session hijacking and Outlook COM automation, sending phishing messages from victims' own accounts. The malware implements robust anti-analysis capabilities including environment-gated payload decryption, comprehensive watchdog systems, and ETW patching. Infrastructure is hosted on Cloudflare Workers, with evidence suggesting the campaign was detected in early operational stages.
MITRE ATT&CK & Malware Families
MALWARE FAMILIES
TCLBANKER
MAVERICK
SORVEPOTEL
Indicators of Compromise (15)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-MD5 | e0d1eedaa0c1f98f50726df729594edc | — | 2026-05-06 | |
| FileHash-SHA1 | 91fafaa1240676afe5c55d931261e3798797c408 | — | 2026-05-06 | |
| FileHash-SHA1 | 94f21c140afd18b43d5a0f274216545442b3f6cd | — | 2026-05-06 | |
| FileHash-SHA256 | 63beb7372098c03baab77e0dfc8e5dca5e0a7420f382708a4df79bed2d900394 | — | 2026-05-06 | |
| FileHash-SHA256 | 668f932433a24bbae89d60b24eee4a24808fc741f62c5a3043bb7c9152342f40 | — | 2026-05-06 | |
| FileHash-SHA256 | 701d51b7be8b034c860bf97847bd59a87dca8481c4625328813746964995b626 | — | 2026-05-06 | |
| FileHash-SHA256 | 8a174aa70a4396547045aef6c69eb0259bae1706880f4375af71085eeb537059 | — | 2026-05-06 | |
| domain | afonsoferragista.com | — | 2026-05-06 | |
| domain | arquivos-omie.com | — | 2026-05-06 | |
| domain | doccompartilhe.com | — | 2026-05-06 | |
| domain | documentos-online.com | — | 2026-05-06 | |
| domain | mxtestacionamentos.com | — | 2026-05-06 | |
| domain | recebamais.com | — | 2026-05-06 | |
| domain | saogeraldoshiping.com | — | 2026-05-06 | |
| hostname | window.navigator.chrome | — | 2026-05-06 |