Banking trojan
TCLBANKER
According to Elastic Security Labs, TCLBANKER is a Brazilian banking trojan comprised of a native code loader and .NET-based payloads that targets financial institutions in Brazil.
TCLBANKER is a Windows banking trojan.
Background
Elastic Security Labs describes TCLBANKER as a Brazilian banking trojan made up of a native code loader and .NET-based payloads, aimed at financial institutions in Brazil. Its main features include watching browser addresses through UI Automation so it can pop WPF full-screen overlays for credential theft and operator-led social engineering, plus self-spreading worm modules that take over WhatsApp Web sessions and abuse Outlook via COM automation to push phishing messages. For evasion, it uses environment-gated payload decryption that quietly fails inside sandboxes or wrong environments, along with a thorough watchdog subsystem that continually checks for debuggers, analysis tools, and instrumentation frameworks while it runs.
Source: Malpedia (Fraunhofer FKIE).