TCLBANKER Banking Trojan Targets Financial Platforms via WhatsApp and Outlook Worms

2026-05-09T07:24:07Z055d34d43d892cbf163eb2de9b82e3f52a16cba8e297144097ef37cca9d050c1
Apache-HTTP2CloudZDAEMON-ToolsDirty-FragIvanti-EPMMMiraiMuddyWaterOutlookPAM-backdoorPAN-OSPCPJackPamDOORaPyPI-malwareQuasar-Linux-RATTCLBANKERUAT-8302WhatsAppZiChatBotactive-exploitationbanking-trojancredential-theftsupply-chain-attackvm2-sandbox-escapewormxlabs_v1

What happened

A large set of high-impact security stories: new and evolving malware (TCLBANKER banking trojan with WhatsApp/Outlook worm capabilities, Quasar Linux RAT targeting developers, CloudZ RAT/Pheno plugin, PamDOORa PAM-based backdoor, ZiChatBot delivered via PyPI, Mirai-derived xlabs_v1 botnet, PCPJack credential-stealer) and multiple active/critical vulnerabilities and supply-chain incidents. Notable vulnerabilities under active exploitation or disclosure include PAN-OS CVE-2026-0300 (critical RCE), Apache HTTP/2 CVE-2026-23918 (double-free, possible RCE), Ivanti EPMM CVE-2026-6973 (RCE), and the新

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
055d34d43d892cbf163eb2de9b82e3f52a16cba8e297144097ef37cca9d050c1
Enrichment time
2026-05-09T07:24:07Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.