Return to Global Matrix
CLASSIFIED: EYES ONLY

New TCLBanker malware self-spreads over WhatsApp and Outlook

TELEMETRY SUMMARY DECRYPTION

SITREP: A new malware known as TCLBanker has been identified, capable of self-propagation via WhatsApp and Outlook. It specifically targets 59 banking, fintech, and cryptocurrency platforms using a compromised MSI installer for Logitech AI Prompt Builder. TACTICAL ASSESSMENT: The emergence of TCLBanker represents a significant escalation in cyber threats, particularly against financial institutions. Its ability to spread through widely used communication platforms indicates a potential for widespread impact and increased vulnerability in the financial sector. PROJECTED VECTORS: Future attacks may see an increase in phishing attempts and exploitation of other communication tools to further disseminate the malware.

SAT-COM 4LAT: 45.192LON: 34.021UTC: 2026-05-09

Event Telemetry

STATUS IDENTIFIERCRITICAL EVENT
ORIGIN DESKCYBER
ACQUISITION TIME05/0722:34 ZULU
AUTHORSYSTEM.AUTO[992]