# TCLBanker Malware Targets Fintech via WhatsApp and Outlook

> TCLBanker malware uses trojanized Logitech AI installers to target 59 banking apps and spreads automatically via WhatsApp and Outlook messages.

- Published: 2026-05-08T05:05:17.000Z
- Severity: high
- Category: Malware
- Tags: TCLBANKER, Logitech AI Prompt Builder, Banking Trojan, WhatsApp Malware, Outlook Propagation
- Author: Runtime Rebel Intel
- Primary source: https://www.bleepingcomputer.com/news/security/new-tclbanker-malware-self-spreads-over-whatsapp-and-outlook/
- Canonical: https://runtimerebel.com/blog/tclbanker-malware-targets-fintech-via-whatsapp-and-outlook

## Key points

- TCLBanker targets 59 financial and cryptocurrency platforms through data exfiltration and overlay attacks, posing a high risk of credential and asset theft.
- Systems are compromised via a trojanized Logitech AI Prompt Builder installer which facilitates self-propagation across WhatsApp and Outlook desktop clients.
- Organizations must block execution of unauthorized MSI installers and monitor for unusual automated messaging activity within corporate communication platforms.

## Overview of the TCLBanker Campaign

A sophisticated new banking trojan dubbed TCLBanker has been identified targeting dozens of financial and cryptocurrency platforms. According to [Bleeping Computer](https://www.bleepingcomputer.com/news/security/new-tclbanker-malware-self-spreads-over-whatsapp-and-outlook/), the malware is currently being distributed through a trojanized MSI installer for 'Logitech AI Prompt Builder,' a legitimate productivity tool. Once installed, TCLBanker employs worm-like capabilities to spread itself to other systems via WhatsApp and Microsoft Outlook, making it a significant threat to corporate environments where these communication tools are ubiquitous.

While this campaign appears to focus heavily on South American users, the infrastructure and [TTP](/glossary#ttp) employed by the attackers suggest a global potential for impact. By mimicking legitimate software, the attackers bypass traditional user skepticism, relying on the brand recognition of companies like Logitech to facilitate the initial compromise. This threat does not rely on a known [CVE](/glossary#cve) for initial entry, instead utilizing social engineering and [Phishing](/glossary#phishing) to trick users into executing a malicious installer.

## Analysis of the Trojanized Logitech AI Prompt Builder Installer

The infection chain begins when a victim downloads a malicious MSI file advertised as the Logitech AI Prompt Builder. Unlike standard malware delivery mechanisms that might use macro-enabled documents, this **trojanized Logitech AI Prompt Builder installer** provides a veneer of legitimacy. Technical analysis reveals that the installer is written in AutoIt, a scripting language frequently used by malware authors to automate tasks and evade basic signature-based detection.

Upon execution, the malware establishes persistence and connects to its [C2](/glossary#c2) server to receive instructions. Its primary objective is the theft of financial credentials. It specifically monitors for activity related to 59 different banking, fintech, and cryptocurrency platforms. When a user navigates to a targeted site, the malware initiates overlay attacks—transparent windows that mimic the legitimate login interface of the bank—to capture usernames, passwords, and two-factor authentication (2FA) codes in real-time.

## Mechanism of Self-Propagation and Data Exfiltration

What distinguishes TCLBanker from standard banking trojans is its automated propagation module. Once a system is infected, the malware scans for the presence of the WhatsApp and Outlook desktop applications. It then uses the victim's own account to send malicious links or files to their contact list. This lateral spread within an organization or among trusted contacts significantly increases the success rate of the campaign, as recipients are more likely to trust a file sent by a known colleague or friend.

### Detecting and Preventing WhatsApp and Outlook Malware Propagation

Security teams must focus on identifying the specific behaviors associated with this threat. To understand **how to detect TCLBanker malware infection**, [SOC](/glossary#soc) analysts should look for unauthorized AutoIt scripts executing from temporary directories or the presence of suspicious MSI installers that do not match known organizational hash baselines. Furthermore, [SIEM](/glossary#siem) alerts should be configured to flag unusual spikes in outbound messaging activity from desktop messaging clients, which may indicate an active worm-like propagation event.

In addition to propagation, TCLBanker exfiltrates comprehensive system metadata, including IP addresses, OS versions, and list of installed security software. This allows the attackers to tailor further stages of the attack or sell the access to other [APT](/glossary#apt) groups or [ransomware](/glossary#ransomware) operators.

## Mitigation and Defense Strategies

Defenders should prioritize a multi-layered approach to **preventing WhatsApp and Outlook malware propagation** and neutralizing the TCLBanker threat. Because the malware relies on local execution of an MSI file, application whitelisting and strict software execution policies are the most effective barriers.

*   **Software Verification:** Only allow the installation of software from verified, internal repositories. Implement hashes-based blocking for the known malicious Logitech AI installers.
*   **Endpoint Protection:** Deploy [EDR](/glossary#edr) solutions capable of behavioral monitoring. TCLBanker’s use of AutoIt and its overlay injection techniques often trigger heuristic alerts based on the [MITRE ATT&CK](/glossary#mitre-att-ck) framework.
*   **Communication Security:** Educate employees to remain vigilant even when receiving files from trusted contacts via WhatsApp or Outlook. Any unexpected file, especially an installer or executable, should be verified via a secondary channel.
*   **Network Segmentation:** Limit the ability of infected endpoints to communicate with known malicious C2 infrastructures by utilizing threat intelligence feeds that track TCLBanker's evolving domain list.

**Related:** [Casbaneiro Banking Trojan: Evasion and Lateral Movement in Latin America](/blog/casbaneiro-banking-trojan-evasion-and-lateral-movement-in-latin-america), [VENON Malware: Rust-Based Banking Trojan Targets Brazilian Banks](/blog/venon-malware-rust-based-banking-trojan-targets-brazilian-banks)

---

AI-generated analysis from the primary source above; not human-reviewed before publication — verify anything operational against the original (https://runtimerebel.com/editorial). Quote with attribution and a link to the canonical URL: https://runtimerebel.com/blog/tclbanker-malware-targets-fintech-via-whatsapp-and-outlook
