TCLBanker Trojan Self-Spreads WhatsApp Outlook Banking Theft | MSSP Advisory

Critical
DateMay 7, 2026
📋Executive Summary
TCLBanker trojan spreads through compromised MSI installers disguised as legitimate Logitech AI Prompt Builder software, then self-propagates via WhatsApp and Outlook contacts. The malware targets 59 banking, fintech, and cryptocurrency platforms with credential theft and transaction manipulation capabilities. Distribution occurs through both direct email campaigns and automated spreading through infected user contact lists.
⚠️Why It Matters for MSSPs
Your RMM and PSA platforms become infection vectors if TCLBanker compromises admin workstations, giving attackers automated access to spread through your entire client base via your communication channels. Clients running banking software or cryptocurrency platforms face direct financial theft, and if they get hit after using your network or receiving infected files from your systems, you own that incident.
📬

Get notified when client-ready advisories like this are published each week.

Join the MSSP Watchlist →
🏷️Threat Category
Supply Chain

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.