Return to Global Matrix
CLASSIFIED: EYES ONLY

TCLBANKER Banking Trojan Targets Financial Platforms via WhatsApp and Outlook Worms

TELEMETRY SUMMARY DECRYPTION

SITREP: A new Brazilian banking trojan named TCLBANKER has been identified, capable of targeting 59 financial platforms including banks, fintechs, and cryptocurrency services. This malware is linked to a previously known variant, Maverick, and utilizes a worm called SORVEPOTEL for propagation through communication platforms like WhatsApp and Outlook. TACTICAL ASSESSMENT: The emergence of TCLBANKER indicates a significant evolution in cyber threats targeting financial institutions, particularly in Brazil. Its ability to spread through widely used communication tools suggests a strategic shift towards more sophisticated and accessible attack vectors. PROJECTED VECTORS: Future attacks may increase in frequency and sophistication as cybercriminals adopt similar tactics to exploit vulnerabilities in communication platforms.

SAT-COM 4LAT: 45.192LON: 34.021UTC: 2026-05-09

Event Telemetry

STATUS IDENTIFIERNORMAL TRAFFIC
ORIGIN DESKCYBER
ACQUISITION TIME05/0903:56 ZULU
AUTHORSYSTEM.AUTO[992]