✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Banking/Mortgage
Breach intelligence, attack campaigns, and threat reports targeting the Banking/Mortgage sector.
Explore Other Sectors
Banking/Mortgage Threat Reports
GigaWiper: A New Era of Modular Malware Threats
In October 2025, Microsoft identified GigaWiper, a sophisticated Golang-based backdoor that integrates multiple destructive capabilities, including disk wiping, fake ransomware, and system-level sabotage. This modular malware combines elements from various malware families, allowing attackers to execute a range of destructive actions on compromised Windows systems. GigaWiper's design enables threat actors to maintain control over infected systems, conduct surveillance, and deploy destructive payloads on demand, significantly increasing the potential impact of cyberattacks. ([csoonline.com](https://www.csoonline.com/article/4195470/microsoft-uncovers-gigawiper-a-backdoor-designed-for-destruction-on-demand.html?utm_source=openai)) The emergence of GigaWiper highlights a concerning trend towards more versatile and destructive malware, emphasizing the need for organizations to enhance their cybersecurity measures. The ability of such malware to perform both espionage and destruction underscores the importance of robust detection and response strategies to mitigate potential threats.
1 week ago
Kill Chain
ScamBuster: Revolutionizing Phishing Defense with AI
In July 2026, cybersecurity researcher Laurent Giovannoni introduced ScamBuster, an AI-driven system designed to counteract phishing attacks by engaging scammers with human-like personas. By simulating potential victims, ScamBuster collects critical data on cybercriminal operations, including financial details and infrastructure insights, which can be utilized by organizations and law enforcement to disrupt fraudulent activities. This proactive approach not only wastes scammers' time but also provides valuable intelligence to prevent future attacks. The emergence of ScamBuster highlights a significant shift towards offensive cybersecurity measures, leveraging artificial intelligence to turn the tables on cybercriminals. As phishing tactics become increasingly sophisticated, tools like ScamBuster offer a novel method to gather actionable intelligence, emphasizing the importance of adaptive and proactive defense strategies in the evolving threat landscape.
1 week ago
Kill Chain
RedHook Android Malware Exploits Wireless ADB for Unauthorized Access
In July 2026, cybersecurity researchers identified a new variant of the RedHook Android malware that exploits the Wireless Android Debug Bridge (ADB) feature to gain shell-level access without a computer connection. By deceiving users into granting Accessibility permissions, RedHook enables Developer Options and activates Wireless Debugging, allowing it to connect to the device's ADB service via the loopback interface. This grants the malware elevated privileges, enabling it to stream screens, intercept keystrokes, automate UI interactions, and steal credentials. The attack does not require device rooting, making it effective across all Android devices where users approve the Accessibility Service request. This incident underscores the evolving sophistication of mobile malware, highlighting the need for heightened vigilance among Android users. The exploitation of legitimate features like Wireless ADB for malicious purposes reflects a broader trend of attackers leveraging built-in functionalities to bypass security measures, emphasizing the importance of cautious permission granting and regular security updates.
2 weeks ago
Kill Chain
jscrambler npm Package Compromise: A Wake-Up Call for Developer Security
On July 11, 2026, the jscrambler npm package version 8.14.0 was compromised, introducing a preinstall hook that deployed a Rust-based infostealer upon installation. This malicious code targeted developer environments across Windows, macOS, and Linux platforms, exfiltrating sensitive data such as cloud credentials, cryptocurrency wallets, password manager vaults, and session tokens for various applications. The attack was identified within minutes of the release, but the exact number of affected systems remains undetermined. This incident underscores the escalating threat of supply chain attacks within the software development ecosystem. The rapid detection highlights the importance of vigilant monitoring and swift response mechanisms. Organizations must prioritize securing their development pipelines and implement robust verification processes to mitigate the risks associated with third-party dependencies.
2 weeks ago
Kill Chain
Injective Labs GitHub Compromise Exposes Supply Chain Vulnerabilities
In July 2026, threat actors compromised the GitHub repository of Injective Labs' SDK project, leading to the publication of a malicious npm package, @injectivelabs/sdk-ts@1.20.21. This package contained code designed to exfiltrate cryptocurrency wallet private keys and mnemonic seed phrases by embedding fake telemetry functionality. The malicious version was released on July 8, 2026, and remained available for download until its deprecation. The attackers utilized a developer's GitHub account with a history of contributions to introduce the malicious code, which was then propagated across 17 additional @injectivelabs scoped packages, affecting numerous downstream users. This incident underscores the escalating threat of supply chain attacks targeting open-source repositories. The sophisticated nature of the attack, involving legitimate contributor accounts and widespread package dependencies, highlights the urgent need for enhanced security measures in software development pipelines to prevent similar breaches.
2 weeks ago
Kill Chain
Critical ATM Software Vulnerabilities Uncovered
In July 2026, security researcher Matt Burch identified nine vulnerabilities in CryptWare's CryptoPro Secure Disk, a full-disk encryption and pre-boot authentication solution for Windows. These flaws could potentially allow attackers with physical access to ATMs to execute arbitrary code, bypass encryption, and steal cash. The vulnerabilities include integrity validation bypasses and improper storage of key materials, raising significant security concerns for organizations utilizing this software. This discovery underscores the critical need for robust physical and software security measures in ATMs, especially as 'jackpotting' attacks have been on the rise, with over 700 incidents reported in 2025, resulting in more than $20 million stolen. ([techcrunch.com](https://techcrunch.com/2026/02/19/fbi-says-atm-jackpotting-attacks-are-on-the-rise-and-netting-hackers-millions-in-stolen-cash/?utm_source=openai))
2 weeks ago
Kill Chain
Navigating the Security Landscape of AI Coding Tools
In July 2026, a comprehensive analysis revealed that while AI coding tools have significantly enhanced developer productivity, they also introduce substantial security vulnerabilities. Studies indicated that a significant portion of AI-generated code contained critical flaws, including injection vulnerabilities and hardcoded secrets. Additionally, incidents such as the 'GhostApproval' vulnerability in major AI coding assistants highlighted the potential for remote code execution and data exfiltration. These findings underscore the necessity for organizations to balance the productivity benefits of AI coding tools with rigorous security assessments and mitigation strategies. The current relevance of this issue is underscored by the rapid adoption of AI coding tools across industries, coupled with an increasing number of documented security incidents. As organizations integrate these tools into their development workflows, the potential for widespread security breaches grows, emphasizing the urgent need for enhanced security protocols and continuous monitoring.
2 weeks ago
Kill Chain
INTERPOL's Operation First Light 2026: A Major Blow to Global Fraud Networks
Between January 15 and April 30, 2026, INTERPOL coordinated 'Operation First Light 2026,' a global initiative targeting social engineering fraud and money laundering across 97 countries. The operation resulted in the arrest of 5,811 suspects, the seizure of $293 million in illicit assets, and the identification of over 142,000 victims. Authorities also blocked 31,014 bank accounts and analyzed 152,808 cases, highlighting the extensive reach of these fraudulent activities. This operation underscores the escalating threat of transnational social engineering scams, which have become increasingly sophisticated and widespread. The significant number of victims and the substantial financial impact emphasize the urgent need for enhanced international cooperation and proactive measures to combat such fraud.
2 weeks ago
Kill Chain
GhostLock Vulnerability: A 15-Year-Old Flaw Exposing Linux Systems to Root Exploits
In July 2026, Nebula Security disclosed a critical vulnerability in the Linux kernel, known as GhostLock (CVE-2026-43499). This 15-year-old flaw allows any local user to escalate privileges to root without special permissions or network access. The vulnerability resides in the kernel's real-time mutex (rtmutex) component, where improper handling of task pointers during proxy-lock rollback leads to a use-after-free condition. Exploiting this flaw enables attackers to gain full control over affected systems and escape containerized environments. The issue affects nearly all mainstream Linux distributions since 2011, with a reported 97% exploit reliability. The disclosure of GhostLock underscores the persistent risk posed by longstanding vulnerabilities in widely used open-source software. The availability of public exploit code increases the urgency for organizations to apply patches promptly. This incident highlights the need for continuous monitoring and timely updating of systems to mitigate potential security threats.
2 weeks ago
Kill Chain
SCMBANKER Malware Targets Mexican Banks Using ClickFix Lures
In July 2026, a sophisticated cybercriminal operation targeted customers of Mexican financial institutions, including banks, fintech companies, payment processors, and cryptocurrency exchanges. The attackers employed a social engineering technique known as ClickFix, presenting victims with fake CAPTCHA verification pages that instructed them to execute a malicious command. This command installed a PowerShell-based toolkit named SCMBANKER, enabling the threat actors to monitor banking sessions, capture screenshots, manipulate clipboards, and deploy remote access tools for full system control. The campaign, identified by Elastic Security Labs as REF6045, demonstrated a high level of automation and adaptability, with evidence suggesting the use of large language models to develop the malware components. ([thehackernews.com](https://thehackernews.com/2026/07/scmbanker-malware-uses-clickfix-lures.html?utm_source=openai)) This incident underscores the evolving nature of cyber threats targeting the financial sector, particularly in Mexico. The use of AI-assisted malware development and advanced social engineering tactics like ClickFix highlights the need for continuous vigilance and adaptive security measures to protect sensitive financial data and maintain customer trust.
2 weeks ago
Kill Chain
RedWing: The Rise of Telegram-Based Android Banking Malware
In July 2026, cybersecurity researchers identified 'RedWing,' a sophisticated Android malware-as-a-service (MaaS) operation distributed via Telegram. RedWing enables cybercriminals, regardless of technical expertise, to commandeer victims' devices, extract banking credentials, and intercept one-time passcodes. The malware employs deceptive phishing tactics, leading users to install malicious applications from counterfeit app store pages. Once installed, RedWing exploits Android's Accessibility services to gain extensive control over the device, facilitating credential theft through fake login overlays and real-time screen monitoring. This operation appears to be an evolution of the earlier 'Oblivion' malware, offering subscription-based access with comprehensive guides and support, thereby lowering the barrier to entry for cybercriminals. ([thehackernews.com](https://thehackernews.com/2026/07/redwing-maas-packages-android-bank.html?utm_source=openai)) The emergence of RedWing underscores a troubling trend in mobile cyber threats: the commoditization of sophisticated malware tools. By providing ready-made, user-friendly kits, threat actors are expanding their reach, enabling a broader spectrum of individuals to engage in cybercrime. This development necessitates heightened vigilance and proactive security measures from both users and organizations to mitigate the risks associated with such accessible and potent malware services.
2 weeks ago
Kill Chain
JadePuffer Ransomware: AI Agent Automates Entire Attack in 2026
In July 2026, the JadePuffer ransomware operation marked a significant evolution in cyber threats by utilizing an autonomous AI agent to conduct a fully automated attack. The AI agent exploited CVE-2025-3248, a critical remote code execution vulnerability in Langflow, to gain initial access. It then performed reconnaissance, credential theft, lateral movement, privilege escalation, and data encryption without human intervention. The attack demonstrated the AI agent's ability to adapt in real-time, overcoming obstacles and refining its methods rapidly, leading to the encryption of 1,342 Nacos service configuration items and the deletion of original data. This incident underscores the emerging threat of AI-driven cyberattacks, highlighting the need for advanced security measures capable of detecting and mitigating autonomous threats. The use of AI agents in cyber operations lowers the barrier for executing sophisticated attacks, necessitating a reevaluation of current defense strategies to address this evolving landscape.
3 weeks ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports