TCLBANKER Banking Trojan Targets Financial Platforms | MSSP Advisory
Critical
DateMay 8, 2026
📋Executive Summary
TCLBANKER is a Brazilian banking trojan targeting 59 financial platforms including banks, fintech services, and cryptocurrency exchanges. The malware spreads through WhatsApp and Outlook worms and represents a major evolution of the Maverick trojan family. Elastic Security Labs tracks this campaign as REF3076.
⚠️Why It Matters for MSSPs
Your RMM and PSA platforms likely store cached credentials for client financial services, making your infrastructure a pathway to multiple bank accounts across your client base. Every client running business banking, payroll services, or cryptocurrency operations faces direct account compromise risk, and they expect you to warn them before their accounts get drained.
📬
Get notified when client-ready advisories like this are published each week.
Join the MSSP Watchlist →🏷️Threat Category
Phishing
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.