The Containment Era is here. →Explore

Industry Category

Banking/Mortgage

Breach intelligence, attack campaigns, and threat reports targeting the Banking/Mortgage sector.

447 threat reports
Page 26 of 38

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Banking/Mortgage Threat Reports

Showing 301312 / 447 reports
North Korea’s $2 Billion Crypto Heist: 2025’s Largest Nation-State Cyber Attack
Impact· high

North Korea’s $2 Billion Crypto Heist: 2025’s Largest Nation-State Cyber Attack

In 2025, threat actors closely tied to North Korea orchestrated a record-breaking $2.02 billion in cryptocurrency thefts, representing over half of the global digital asset losses for the year. These attackers leveraged sophisticated intrusion techniques, advanced persistent threat (APT) operations, and exploited vulnerabilities in decentralized finance (DeFi) platforms and exchanges from January through early December. High-value thefts were often facilitated by exploiting weak internal controls, compromised credentials, and security gaps in cross-chain bridges, resulting in severe financial losses for both exchanges and their clients. This incident marks a significant escalation in nation-state cybercrime and highlights evolving attacker sophistication in targeting cryptocurrency infrastructure. It underscores escalating regulatory scrutiny and the necessity for organizations to bolster east-west traffic controls, threat detection, and zero trust architectures in response to persistent, financially-motivated adversaries.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Cellik RAT’s Google Play Store Infiltration Exposes Mobile Security Gaps
Impact· high

Cellik RAT’s Google Play Store Infiltration Exposes Mobile Security Gaps

In June 2024, cybersecurity researchers uncovered that the Cellik Android Remote Access Trojan (RAT) was being distributed through malicious applications on the official Google Play Store. The Cellik RAT allows attackers to remotely control infected Android devices, harvest sensitive credentials, and exfiltrate private data without the user’s knowledge. Threat actors used advanced evasion tactics, including app generation within Play Store guidelines and encrypted communications, to bypass traditional defenses. The incident highlights weaknesses in mobile app review processes and demonstrates the continued use of popular app stores as distribution vectors for sophisticated malware campaigns. This breach is especially notable as attackers continue to exploit trusted platforms like the Google Play Store, elevating risk for both individuals and enterprises. The emergence of Cellik marks an uptick in mobile RAT sophistication and underscores the urgent need for stronger app vetting and threat detection on mainstream digital ecosystems.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
DOJ Takes Down E-Note: Ransomware Laundering Hub Disrupted in 2024 Crackdown
Impact· medium

DOJ Takes Down E-Note: Ransomware Laundering Hub Disrupted in 2024 Crackdown

In early 2024, the US Department of Justice, in partnership with international law enforcement, dismantled the E-Note cryptocurrency exchange—a major online infrastructure used for laundering illicit proceeds from ransomware and cybercrime. Authorities indicted Mykhalio Petrovich Chudnovets, a Russian national alleged to have operated E-Note since 2010, with facilitating the transfer of over $70 million in stolen or extorted funds from attacks targeting sectors like healthcare and critical infrastructure. Federal and state agencies seized E-Note servers, websites, and mobile apps, obtaining customer and transaction data to further map criminal networks. This takedown highlights cybercriminals’ growing use of specialized laundering platforms to enable ransomware and account takeover monetization at scale. As regulatory scrutiny intensifies and attacker infrastructure becomes more modular and resilient, law enforcement action against these enablers is an increasing priority.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Cellik Android Malware: The New Frontier for Trojanized Google Play Apps
Impact· medium

Cellik Android Malware: The New Frontier for Trojanized Google Play Apps

In December 2025, cybersecurity researchers identified a new Android malware-as-a-service (MaaS) dubbed Cellik that enables cybercriminals to create malicious variants of popular Google Play Store apps. Distributed via underground forums, Cellik’s service allows threat actors to select legitimate apps, inject sophisticated malware, and maintain original app functionality, thereby bypassing typical user suspicion and potentially evading Google Play Protect. Cellik's features include real-time screen streaming, notification interception, filesystem browsing, data exfiltration, device wiping, and encrypted command-and-control communications. Attackers can also overlay fake login screens, inject malicious payloads into trusted apps, and exploit a hidden browser to steal credentials using stored cookies from infected devices. The emergence of Cellik signals an evolution in Android threat tooling, where MaaS kits empower less skilled actors to launch advanced attacks. This development heightens risks for organizations subject to mobile threats as attackers embrace more modular and evasive tactics, underlining the urgent need for advanced mobile security controls and proactive user education.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Turkey Hit by Advancing Android Banking Trojan: Inside the Frogblight Campaign
Impact· medium

Turkey Hit by Advancing Android Banking Trojan: Inside the Frogblight Campaign

In August 2025, researchers identified a sophisticated Android banking Trojan dubbed "Frogblight" targeting users in Turkey. Distributed primarily through smishing campaigns and phishing sites masquerading as official government portals, Frogblight lured victims by posing as legitimate court case or Chrome browser apps. Once installed, it harvested banking credentials, SMS, contact lists, call logs, and device data, while providing remote device control and persistence mechanisms for operators. The malware communicated via REST API and later WebSockets to exfiltrate stolen data to attacker-controlled C2 servers and was frequently updated with new spyware features, indicating ongoing development and potential adoption as Malware-as-a-Service (MaaS). Frogblight exemplifies the rapid evolution and increasing capabilities of mobile banking malware. The campaign underscores the rising threat to mobile users—particularly in markets where banks and government digital services are trusted attack vectors—and reflects a broader trend toward commoditized MaaS offerings and advanced evasion techniques. Effective mobile security controls and user awareness remain critical as adversaries refine their payloads.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Parked Domains Weaponized: Inside the 2025 Typosquatting Malvertising Surge
Impact· medium

Parked Domains Weaponized: Inside the 2025 Typosquatting Malvertising Surge

In late 2025, security researchers uncovered that over 90% of parked domains—unused, expired, or misspelled web addresses—were actively redirecting visitors to malicious destinations, including scams, malware, and deceptive subscription offers. Utilizing techniques like device fingerprinting, IP geolocation, and chained redirects, threat actors profited by manipulating the domain parking ecosystem, turning innocuous navigation mistakes into vectors for malware delivery and fraud. The campaign targeted high-profile brands and government offices, often bypassing detection by profiling user access (e.g., residential IPs or VPN use), with some domains weaponized for business email compromise. This incident highlights an alarming shift: parked and typo domains are now a primary malvertising risk, not a minor threat. As domain registration and ad platform policies evolve, attackers rapidly adapt, exploiting weaknesses in digital trust and endpoint security. Organizations must broaden threat detection and policy enforcement to address direct navigation attacks and affiliate-driven malvertising.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
700Credit 2024 Breach: 5.8 Million Dealership Customers' Data Exposed
Impact· high

700Credit 2024 Breach: 5.8 Million Dealership Customers' Data Exposed

In early 2024, 700Credit, a US-based fintech firm specializing in credit and compliance solutions for auto dealerships, disclosed a major data breach affecting over 5.8 million individuals. The breach was traced to a vulnerability in a third-party web application platform, resulting in unauthorized access to sensitive customer data submitted to vehicle dealerships across North America. Exposed data included names, addresses, Social Security Numbers, dates of birth, and driver’s license numbers. The breach forced 700Credit to rapidly contain the issue, engage forensic experts, and notify customers, while drawing regulatory scrutiny due to the significant privacy impact. This incident is especially important as it highlights the persistent risks presented by web application vulnerabilities and supply chain exposure across critical business platforms. Increased attacker focus on third-party dependencies and data-rich payment ecosystems continues to drive urgency around zero trust architectures and more proactive monitoring and response.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(high)
Read Report
SantaStealer: The 2024 Memory-Based Infostealer Malware Targeting Credentials and Crypto Wallets
Impact· high

SantaStealer: The 2024 Memory-Based Infostealer Malware Targeting Credentials and Crypto Wallets

In early 2024, a new information-stealing malware known as SantaStealer emerged on cybercriminal Telegram channels and hacker forums, operating as a malware-as-a-service (MaaS). Designed to run primarily in memory, SantaStealer avoids traditional file-based detection and targets sensitive data in browsers, cryptocurrency wallets, and installed application credentials. Attackers typically distribute the malware through phishing campaigns and malicious attachments. Once executed, SantaStealer exfiltrates stolen data to command-and-control servers, enabling threat actors to harvest victims' digital assets and credentials for further exploitation or sale on underground markets. The incident underlines a growing trend of evasive, memory-resident stealer malware leveraging MaaS models. Cybercriminals are accelerating adoption of these techniques, raising the stakes for organizations and individuals who store credentials and assets on personal and enterprise endpoints.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Phantom Stealer Phishing: 2025 Attack Hits Russian Finance via ISO Emails
Impact· medium

Phantom Stealer Phishing: 2025 Attack Hits Russian Finance via ISO Emails

In late 2025, an active phishing campaign dubbed "Operation MoneyMount-ISO" began targeting the Russian financial sector and related industries, with threat actors distributing phishing emails containing malicious ISO disk image attachments. Once opened, these ISO files delivered the Phantom Stealer malware, enabling attackers to exfiltrate sensitive data from finance, accounting, procurement, legal, and payroll departments. The malware operated covertly, seeking credentials and financial information, leading to notable data exposure risks and potential regulatory disruptions for victim organizations. This campaign highlights the increasing sophistication of phishing operations leveraging disk image formats for initial access and the persistent targeting of high-value sectors with advanced infostealer malware. Financial and critical infrastructure organizations face heightened pressure to improve detection and segmentation as threat actors continually refine their social engineering tactics.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Apple 2025 WebKit Zero-Day Breach: What Security Teams Must Know
Impact· low

Apple 2025 WebKit Zero-Day Breach: What Security Teams Must Know

In June 2025, Apple issued urgent security updates across iOS, iPadOS, macOS, tvOS, watchOS, visionOS, and Safari in response to two actively exploited zero-day vulnerabilities in the WebKit browser engine. One notable vulnerability, CVE-2025-43529, was a use-after-free flaw that could allow maliciously crafted web content to execute arbitrary code on affected devices. The flaws were discovered being exploited in the wild, with attackers leveraging compromised web traffic to bypass built-in device protections, raising concerns for the billions of global Apple device users. This event underscores the growing prevalence and severity of zero-day exploits against popular consumer platforms, highlighting attacker agility and cross-app targeting. With the rapid pace of vulnerability discovery and exploitation, it accentuates the pressing need for real-time patching, proactive threat detection, and segmentation strategy for organizations leveraging Apple devices.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(low)
Read Report
2025 Advanced Phishing Kits Exploit AI and MFA Bypass to Steal Credentials at Scale
Impact· low

2025 Advanced Phishing Kits Exploit AI and MFA Bypass to Steal Credentials at Scale

In August 2025, cybersecurity firms identified four sophisticated phishing kits—BlackForce, GhostFrame, InboxPrime AI, and Spiderman—leveraging advanced AI and multi-factor authentication (MFA) bypass tactics to automate credential theft at massive scale. These kits use capabilities like Man-in-the-Browser (MitB) attacks to capture one-time passwords, impersonate legitimate brands, evade detection, and target both enterprise and individual platforms. Attackers deploy these toolkits to orchestrate widespread phishing campaigns, resulting in unauthorized account access, data loss, and potential downstream breaches for affected organizations. This incident illustrates a significant escalation in the complexity of phishing operations, combining AI-powered evasion with real-time MFA bypass. The rise of such modular, scalable phishing kits demonstrates the evolving challenge for organizations to safeguard user credentials and the urgent need for adaptive defenses.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
AI-Powered Attacks Break Smart Contracts: A 2025 Blockchain Breach Analysis
Impact· high

AI-Powered Attacks Break Smart Contracts: A 2025 Blockchain Breach Analysis

In late 2025, advanced AI models including Anthropic's Claude Opus 4.5, Claude Sonnet 4.5, and OpenAI's GPT-5 autonomously exploited vulnerabilities across a new smart contract benchmark (SCONE-bench) comprising 405 blockchain contracts. These AIs collectively discovered and weaponized vulnerabilities leading to $4.6 million in simulated or actual economic loss, proving AI-driven cyber capabilities have reached critical new thresholds. Further, simulations against nearly 2,850 newly deployed smart contracts with no previously known vulnerabilities resulted in successful zero-day discoveries and profitable exploits, despite only modest operational costs for the threat actors. This fundamentally changed the risk calculus for decentralized finance and blockchain-based businesses. These findings underscore a turning point, where the integration of conversational and agentic AI with offensive security tools directly translates to scalable, profitable cyberattacks. The incident highlights an urgent risk landscape: AI-driven exploitation is no longer theoretical, driving increased pressure for automated AI defensive strategies and regulatory focus in sectors reliant on smart contracts.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports