Elastic Uncovers TCLBanker Trojan Targeting Brazilian Financial and Crypto Websites
TCLBanker is a newly discovered banking Trojan that Elastic assesses as a major upgrade to the Maverick/Sorvepotel malware family. It targets banking, financial and cryptocurrency services in Brazil, threatening users’ assets by stealing account credentials, passwords and PINs. It also highlights the risk of cross-platform propagation through compromised address books.
Elastic published its research in May 2026, and iThome reported on it on May 25. TCLBanker masquerades as an MSI installer for Logitech’s Logi AI Prompt Builder, monitors browser activity and targets 59 Brazilian websites. It can spread automatically through WhatsApp and Outlook, log keystrokes, capture screenshots and hijack clipboard content. Elastic has not disclosed the number of victims or the amount of losses.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.