{"id":3885,"date":"2026-05-08T18:12:00","date_gmt":"2026-05-08T18:12:00","guid":{"rendered":"http:\/\/infosec-daily.com\/?page_id=3885"},"modified":"2026-05-08T18:12:00","modified_gmt":"2026-05-08T18:12:00","slug":"tclbanker-banking-trojan-targets-financial-platforms-via-whatsapp-and-outlook-worms","status":"publish","type":"page","link":"https:\/\/infosec-daily.com\/?page_id=3885","title":{"rendered":"TCLBANKER Banking Trojan Targets Financial Platforms via WhatsApp and Outlook Worms"},"content":{"rendered":"<p>Threat hunters have flagged a previously undocumented Brazilian banking trojan dubbed TCLBANKER that&#8217;s capable of targeting 59 banking, fintech, and cryptocurrency platforms.<br \/>\nThe activity is being tracked by Elastic Security Labs under the moniker REF3076. The malware family is assessed to be a major update of the Maverick, which is known to leverage a worm called SORVEPOTEL to spread via<\/p>","protected":false},"excerpt":{"rendered":"<p>Threat hunters have flagged a previously undocumented Brazilian banking trojan dubbed TCLBANKER that&#8217;s capable of targeting 59 banking, fintech, and cryptocurrency platforms. The activity is being tracked by Elastic Security&hellip;<\/p>\n","protected":false},"author":1,"featured_media":3886,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"saved_in_kubio":false,"footnotes":""},"class_list":["post-3885","page","type-page","status-publish","has-post-thumbnail","hentry"],"kubio_ai_page_context":{"short_desc":"","purpose":"general"},"_links":{"self":[{"href":"https:\/\/infosec-daily.com\/index.php?rest_route=\/wp\/v2\/pages\/3885","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/infosec-daily.com\/index.php?rest_route=\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/infosec-daily.com\/index.php?rest_route=\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/infosec-daily.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/infosec-daily.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3885"}],"version-history":[{"count":0,"href":"https:\/\/infosec-daily.com\/index.php?rest_route=\/wp\/v2\/pages\/3885\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/infosec-daily.com\/index.php?rest_route=\/wp\/v2\/media\/3886"}],"wp:attachment":[{"href":"https:\/\/infosec-daily.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3885"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}