TCLBANKER Banking Trojan Targets Financial Platforms via WhatsApp and Outlook Worms
By DAPSSA AI Desk | 2026-05-09T05:34:57.764Z

Overview
Threat hunters have flagged a previously undocumented Brazilian banking trojan dubbed TCLBANKER that's capable of targeting 59 banking, fintech, and cryptocurrency platforms. The activity is being tracked by Elastic Security Labs under the moniker REF3076. The malware family is assessed to be a major update of the Maverick, which is known to leverage a worm called SORVEPOTEL to spread via
Key Developments
This reflects an evolving cybersecurity situation.
Technical Details
Attackers may use automation and vulnerabilities.
Impact & Risks
Potential disruption and data exposure.
Conclusion
Organizations must stay vigilant.
Read more: https://thehackernews.com/2026/05/tclbanker-banking-trojan-targets.html