✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Banking/Mortgage
Breach intelligence, attack campaigns, and threat reports targeting the Banking/Mortgage sector.
Explore Other Sectors
Banking/Mortgage Threat Reports
Sturnus: New Android Trojan Hijacks Devices & Captures Encrypted Chats
In late 2025, cybersecurity researchers discovered a sophisticated Android banking trojan dubbed Sturnus, which enables credential theft and full device takeover for financial fraud. Sturnus stands out by bypassing encrypted messaging protections, capturing decrypted content directly from the device screen to monitor sensitive apps and intercept confidential chats. Threat actors leveraged phishing campaigns and malicious app distribution to compromise victims, ultimately gaining unauthorized access to financial information and conducting unauthorized transactions. The attack demonstrates the growing ingenuity of malware targeting mobile banking and highlights the challenges of relying solely on network-level encryption. This incident is especially timely due to the rapid evolution of mobile banking threats and attackers' increasing focus on defeating application-layer defenses. Sturnus's capability to monitor encrypted communications at the device level sets a worrying new precedent in malware TTPs, urging organizations to reassess endpoint and messaging security controls.
6 months ago
Kill Chain
Matrix Push: How Browser Notifications Became a C2 Weapon in 2024
In early 2024, cybersecurity researchers reported that a threat actor group leveraged a new Command and Control tool—dubbed 'Matrix Push'—to hijack web browser notifications as an innovative phishing and persistence mechanism. Attackers delivered malicious payloads through deceptive websites, tricking users into allowing browser notifications. These notifications were abused to send phishing lures and exfiltrate user information, evading traditional network monitoring tools by using trusted browser channels. The campaign allowed remote control and persistent access to compromised endpoints, highlighting a shift toward social engineering at the browser level. Organizations targeted included enterprises in technology, finance, and professional services sectors, resulting in elevated risks of credential theft and lateral movement. This incident is especially notable for exploiting a trusted browser feature in new ways, bypassing established email and endpoint filtering controls. As browser notification-based attacks surge, security teams face increased pressure to adapt controls. The tactics highlight the urgent need for enhanced user awareness and modern segmentation/visibility solutions that can identify and mitigate covert browser-based C2 channels.
6 months ago
Kill Chain
WhatsApp 'Eternidade' Trojan Self-Propagates Across Brazil
In early 2024, a sophisticated infostealer campaign dubbed 'Eternidade' began targeting Brazilian Portuguese–speaking WhatsApp users. The attackers distributed a trojan combining phishing, credential theft, and worm-like self-propagation via compromised WhatsApp messages. Victims were lured with messages containing malicious links; once infected, devices exposed sensitive banking credentials and personal data to attackers. The malware leveraged localized tactics and social engineering to increase infection rates and circumvent traditional perimeter defenses, leading to widespread compromise across individual users and organizations reliant on WhatsApp for communication. The rapid spread, data loss, and potential for further extortion amplified business and consumer risks. This breach signals the growing sophistication of infostealer operations, especially their ability to exploit trusted communication apps in regionally tailored attacks. The incident raises alarm over encrypted-messaging-based malware and highlights gaps in endpoint and messaging security as threat actors increasingly weaponize social communication platforms.
6 months ago
Kill Chain
California Crypto Laundering: $230M Theft and Tracing the Mixers – 2024 Incident
In 2024, a California resident pleaded guilty to laundering over $25 million in cryptocurrency, part of a broader $230 million theft stemming from a major cyber heist targeting a cryptocurrency platform. The attacker leveraged sophisticated tactics to siphon digital assets and enlisted money-laundering services to funnel proceeds through a series of mixers, obscuring the criminal origins. Investigators traced the flows across multiple wallets and exchanges over several months—ultimately apprehending the facilitator in the U.S. This multi-jurisdictional operation illustrated both the scale of modern crypto theft and challenges in asset recovery for victims and exchanges. The case underscores the mounting trend of advanced laundering techniques following crypto thefts, as decentralized financial ecosystems and global regulatory gaps give threat actors new cover. Organizations handling digital assets face heightened pressure for compliance, zero trust, and full-spectrum monitoring.
6 months ago
Kill Chain
Phishing-as-a-Service Evolves: Sneaky2FA Adds Browser-in-the-Browser Attacks in 2024
In early June 2024, cybersecurity researchers reported that the Sneaky2FA phishing-as-a-service (PhaaS) kit has adopted the Browser-in-the-Browser (BitB) attack tactic, previously used by red teamers, to improve the effectiveness of credential phishing campaigns. This new feature enables threat actors using the Sneaky2FA service to launch highly convincing fake login pop-ups, closely mimicking legitimate authentication flows, including prompts for multifactor authentication (MFA). The update broadens the risks for both organizations and individuals, as traditional indicators of phishing are increasingly hard to spot. The deployment of BitB tactics by a turnkey phishing kit marks a concerning development in the automation and commercial accessibility of advanced cybercrime techniques. This incident underscores the escalating sophistication of phishing attacks driven by the commoditization of offensive security techniques. Organizations face renewed urgency to revisit their authentication controls, user awareness training, and phishing-resistant MFA, as adversary innovation quickly outpaces conventional defense measures.
6 months ago
Kill Chain
Mobile Malware Soars in Q3 2025: Key Insights from Kaspersky's Global Report
In Q3 2025, Kaspersky reported a significant surge in mobile malware activity, with 47 million attacks prevented globally targeting Android devices with Trojans, adware, banking malware, and ransomware. Threat actors exploited new variants—including BADBOX and sophisticated Trojans like Triada and Fakemoney—utilizing methods such as pre-installed backdoors and malicious app mods. Mobile banking Trojans (especially Mamont and Coper) and region-targeted malware attacks in Turkey, India, Iran, and Germany impacted financial data security and user privacy, highlighting expanding attacker sophistication and supply chain compromise. This incident is critical as it illustrates the rising prevalence and complexity of mobile threats, coinciding with increased ransomware attacks and evolving delivery channels. The continued targeting of financial apps and global user bases signals an urgent need for organizations to strengthen mobile security, visibility, and compliance with privacy mandates.
6 months ago
Kill Chain
WhatsApp Hijack: Eternidade Stealer Campaign Hits Brazilian Users via Python Worm
In November 2025, cybersecurity researchers identified a sophisticated campaign targeting Brazilian users via WhatsApp, where attackers leveraged a Python-based worm combined with social engineering tactics. Victims were tricked into installing a worm that hijacked WhatsApp sessions and propagated itself to contacts, while delivering a Delphi-based banking trojan known as Eternidade Stealer. The campaign exploited IMAP to dynamically resolve command-and-control infrastructure, enabling threat actors to orchestrate info-stealing and credential harvesting at scale and with resilience to takedown attempts. The incident had significant implications for financial fraud and impacted numerous personal and business WhatsApp accounts across Brazil. This campaign is emblematic of a wider surge in malware leveraging messaging platforms for lateral movement and rapid propagation. The popularity of WhatsApp, combined with increasingly modular infostealers and TTP reuse by criminal groups, highlights the urgent need for proactive controls and visibility across both east-west and outbound communication paths.
6 months ago
Kill Chain
Tycoon 2FA: How Phishing-as-a-Service Broke Legacy MFA at Scale in 2024
In 2024, cybercriminals leveraged the Tycoon Phishing-as-a-Service (PaaS) platform to orchestrate over 64,000 successful real-time attacks bypassing legacy multi-factor authentication (MFA) with relay-based phishing toolkits. Tycoon allowed even low-skilled attackers to automate the interception and relay of users’ MFA tokens, defeating common one-time passcodes and push-based authentication. This Phishing-as-a-Service campaign targeted a wide array of industries and organizations, exposing user credentials and compromising sensitive systems at scale. The incident underscores the urgent collapse of legacy MFA methods under modern, scalable phishing threats. The widespread exposure from Tycoon demonstrates how phishing-resistant authentication (such as FIDO2 hardware tokens and biometrics) are now critical. Regulatory agencies and security experts have since elevated calls for organizations to rapidly phase out vulnerable MFA in favor of hardware-backed solutions, as attackers weaponize automated, scalable PaaS infrastructure.
6 months ago
Kill Chain
Google Chrome’s 2025 V8 Zero-Day: What Organizations Must Do After the Latest Exploit
In June 2025, Google disclosed an actively exploited zero-day vulnerability (CVE-2025-13223) in the V8 JavaScript and WebAssembly engine powering Chrome. Attackers leveraged this type confusion flaw to execute arbitrary code or trigger program crashes, enabling them to compromise vulnerable browsers. Google promptly released patches to address the flaw after receiving reports of in-the-wild exploitation. At-risk users included anyone running unpatched Chrome versions across platforms, with attackers potentially able to hijack sessions, install malware, or steal sensitive data simply by enticing users to visit a malicious web page. This incident highlights the persistent risks posed by emerging browser vulnerabilities, as both sophisticated threat actors and opportunistic cybercriminals increasingly exploit zero-day flaws for rapid compromise. Security teams face mounting urgency to prioritize browser patching cycles to counter fast-moving, exploitation-ready threats.
6 months ago
Kill Chain
Sneaky 2FA Kit Innovates with BitB Pop-up Phishing: MFA Bypass at Scale
In November 2025, security researchers reported on the evolving Sneaky 2FA Phishing-as-a-Service (PhaaS) kit, which now features sophisticated Browser-in-the-Browser (BitB) pop-ups that convincingly mimic legitimate browser address bars. These enhancements enable threat actors, including low-skilled attackers, to deploy highly realistic phishing attacks at scale and bypass multi-factor authentication (MFA) protections. Victims, typically employees of enterprises and large organizations, are tricked into entering credentials and 2FA codes into deceptive portals, facilitating account compromise and potential unauthorized access to sensitive business assets. This incident highlights a troubling trend of phishing toolkits increasing in sophistication, making advanced attacks accessible to broader criminal audiences. Organizations are now facing growing regulatory and operational pressure to update authentication, identity protection, and detection controls amid a wave of phishing leveraging MFA bypass and deceptive visual TTPs.
6 months ago
Kill Chain
North Korean Identity Laundering & IT Worker Scheme Disrupts 136 US Companies – 2024
Between 2019 and 2024, a coordinated North Korean scheme enabled state-backed operatives to access U.S. company systems and launder stolen funds. Facilitated by both domestic and foreign conspirators, including Oleksandr Didenko, Audricus Phagnasay, Jason Salazar, Alexander Paul Travis, and Erick Ntekereze Prince, the operation leveraged stolen and forged American identities to secure remote IT jobs, deploying laptop farms and remote access software to evade detection. The group collectively compromised over 136 U.S. companies, funneled more than $2.2 million to North Korea's regime, and participated in cryptocurrency heists attributed to APT38. The case signals a pronounced jump in sophisticated, identity-driven attacks by nation-state threat actors targeting both the technology sector and U.S. critical infrastructure. As similar TTPs proliferate, the incident underscores the urgent need for robust identity verification, zero trust segmentation, and ongoing monitoring to counter evolving supply chain threats.
6 months ago
Kill Chain
Police Disrupts Global Rhadamanthys, VenomRAT & Elysium Malware Servers in Landmark 2024 Operation
In May 2024, a coordinated international operation involving law enforcement agencies from nine countries dismantled 1,025 servers associated with the Rhadamanthys infostealer, VenomRAT, and Elysium botnet malware operations. The infrastructure takedown was part of Operation Endgame, which targeted malware botnets used to steal data, deliver ransomware, and facilitate cyberattacks globally. By disrupting these networks, authorities severely impaired the threat actors' ability to conduct ongoing credential, financial, and personal data theft campaigns against businesses and individuals across multiple regions. This incident highlights the escalating efforts among global law enforcement to target and disable cybercriminal infrastructure at scale. The takedown reflects a trend towards greater intelligence-sharing and direct action, signaling that even complex, distributed botnet operations can be disrupted through multinational cooperation.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports