✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Banking/Mortgage
Breach intelligence, attack campaigns, and threat reports targeting the Banking/Mortgage sector.
Explore Other Sectors
Banking/Mortgage Threat Reports
Operation Endgame 2025: Law Enforcement Disrupts Rhadamanthys, Venom RAT, and Elysium Botnet
Between November 10 and 13, 2025, international law enforcement agencies led by Europol and Eurojust conducted Operation Endgame, a sweeping crackdown targeting malicious cyber infrastructures. The operation succeeded in dismantling key components of the Rhadamanthys Stealer, Venom RAT, and Elysium botnet, disrupting networks that facilitated global credential theft, remote access, and command-and-control activities. The coordinated seizures involved simultaneous server takedowns across multiple countries and the arrest of key individuals behind these malware operations, significantly diminishing the power and reach of these cybercriminal networks. This incident highlights an increasing trend of robust international cooperation in targeting advanced malware and botnet ecosystems. The disruption of these criminal infrastructures sends a strong message to threat actors, demonstrating both the technical capabilities and resolve of law enforcement to combat cybercrime at scale.
6 months ago
Kill Chain
Malicious ‘Safery’ Chrome Extension Steals Ethereum: Anatomy of a 2025 Infostealer Attack
In November 2025, cybersecurity researchers identified a malicious Chrome extension named "Safery: Ethereum Wallet," which masqueraded as a legitimate cryptocurrency management tool but was designed to steal users' Ethereum wallet seed phrases. The extension was covertly uploaded to the Chrome Web Store, targeting unsuspecting cryptocurrency holders by promising enhanced security and flexible settings. After users entered their wallet credentials, the extension exfiltrated sensitive seed phrases via transactions on the Sui blockchain, effectively enabling attackers to compromise and drain user wallets. The incident rapidly gained attention due to its stealthy distribution and use of decentralized channels for data exfiltration. This breach underscores a growing trend of sophisticated infostealers leveraging browser extensions and blockchain-based exfiltration routes to exploit gaps in endpoint and cloud application security. The persistent evolution of phishing and credential theft tactics increases regulatory pressure and demands more robust zero trust and egress policy enforcement across digital ecosystems.
6 months ago
Kill Chain
Google Targets Smishing Triad: 2025 Lawsuit Disrupts Phishing-as-a-Service Operations
In November 2025, Google filed a landmark lawsuit in the Southern District of New York targeting the so-called "Smishing Triad," a China-based phishing-as-a-service group responsible for operating the Lighthouse phishing kit. This kit empowers cybercriminals to impersonate over 400 brands and conduct high-volume SMS attacks, luring victims worldwide into divulging payment information and one-time passcodes. Attackers leveraged the compromised data to enroll payment cards in mobile wallets on Apple and Google devices, allowing them to transact and cash out at scale. Google identified over a million victims in 120 countries, with Smishing Triad operators rotating up to 25,000 phishing domains in an eight-day window. The case highlights an increasing sophistication and industrialization of mobile phishing schemes, where threat actors utilize automation, rapid domain turnover, and collaboration across specialized roles. Legal escalation by a major tech company reflects growing efforts to disrupt cross-border cybercrime ecosystems that evade technical and regulatory countermeasures.
6 months ago
Kill Chain
Coyote & Maverick Banking Trojans: 2024 Banking Attacks Sweep Brazil
In 2024, cybersecurity researchers observed a surge in banking Trojan activity in Brazil, notably from two malware strains named Coyote and Maverick. These Trojans specifically target financial institutions and individual banking customers by using advanced phishing campaigns, malicious email attachments, and fake banking apps to infiltrate devices. Once installed, they deploy credential-stealing modules, monitor browser activity, and intercept authentication data, often leveraging encrypted and east-west network traffic to evade security controls. Maverick is engineered to self-terminate if it detects a target located outside Brazil, indicating a strong geo-targeting component. The campaign’s impact includes stolen banking credentials, financial fraud, and operational disruption for affected users and banks in the region. The continued advancement and targeted nature of these Brazilian banking Trojans demonstrate a significant evolution in threat actor sophistication, especially toward region-specific attacks. Organizations need to heighten their defenses and monitor emerging tactics as financially motivated cybercrime rises across Latin America.
6 months ago
Kill Chain
Operation Endgame 2024: Global Law Enforcement Strikes Down Major Malware Networks
In November 2024, a coalition of law enforcement agencies from 11 countries coordinated Operation Endgame, a major crackdown disrupting some of the most prolific malware networks globally. The operation targeted Rhadamanthys infostealer, VenomRAT remote access trojan, and the Elysium botnet—malware that collectively infected hundreds of thousands of computers and enabled the theft of millions of credentials. Authorities arrested the principal VenomRAT suspect in Greece, searched 11 sites across Europe, and dismantled more than 1,000 criminal servers and 20 illicit domains. With assistance from 30-plus cybersecurity companies, the operation also notified thousands of victims and exposed users of these illicit services, mitigating ongoing criminal campaigns. Operation Endgame underscores the rapidly evolving, cross-border nature of malware infrastructure and the growing need for coordinated responses by both public and private sectors. As attackers innovate and leverage distributed networks to evade law enforcement, regular collaborative enforcement actions and heightened detection capability are now critical to cybersecurity defenses worldwide.
6 months ago
Kill Chain
DanaBot Returns: Windows Banking Trojan Resurges After Global Takedown
In early 2024, the notorious DanaBot banking Trojan resurfaced after a six-month hiatus following major international law enforcement crackdowns under Operation Endgame in May 2023. This new version targets Windows systems through phishing campaigns, using malicious email attachments to gain initial access. Once deployed, DanaBot leverages modular capabilities for credential theft, lateral movement, and potential data exfiltration, threatening organizations and individuals with financial losses and malware proliferation. The resurgence highlights the continuously evolving tactics of threat actors in the financial malware ecosystem despite decisive takedown efforts. DanaBot's return signals the persistent threat posed by adaptive malware campaigns, with attackers quickly retooling to evade detection and capitalize on lapses in endpoint security. This incident stresses the importance of modern inbound threat detection measures and rapid response to evolving banking malware tactics.
6 months ago
Kill Chain
2025 Microsoft Kernel Zero-Day: Privilege Escalation Risks & Response
In November 2025, Microsoft disclosed and patched 63 security flaws across its platforms, including a Windows Kernel zero-day vulnerability (CVE-2025-XXXX) that was exploited in the wild prior to the update. Attackers leveraged this privilege escalation flaw to gain elevated access on targeted devices, enabling them to bypass security controls, move laterally, and potentially deploy additional malicious payloads. While the majority of these vulnerabilities were rated as important, four—including the actively exploited zero-day—were rated critical, underlining the heightened risk for organizations that were slow to apply updates. The prompt response in releasing patches aimed to minimize further exploitation and potential operational disruptions for Microsoft enterprise customers globally. This incident highlights increasing attacker focus on privilege escalation flaws within widely-used platforms, particularly those with a large installed base like Windows. The ongoing exploitation of zero-days demonstrates the urgency of timely patch management, robust endpoint defenses, and threat detection as adversaries accelerate the weaponization of newly discovered vulnerabilities.
6 months ago
Kill Chain
Fantasy Hub Android Trojan Turns Telegram into a Hotspot for Mobile Hackers
In November 2025, cybersecurity researchers uncovered a new Android remote access trojan (RAT) named Fantasy Hub, distributed via Russian-speaking Telegram channels under a Malware-as-a-Service (MaaS) model. This sophisticated threat enabled cybercriminals to remotely control infected devices, steal sensitive data such as SMS messages, contacts, call logs, images, and videos, and intercept or reply to communications. By leveraging Telegram's anonymity, the operators accelerated widespread infections, targeting individuals and organizations across multiple regions. The attack resulted in extensive data exfiltration, privacy breaches, and elevated risks of further compromise through device-level espionage and lateral movement. The Fantasy Hub incident is particularly notable for exemplifying the growing commoditization of mobile malware and the use of mainstream encrypted messaging apps for criminal operations. Its discovery highlights the urgent need for organizations to enforce robust mobile security, review east-west security policies, and remain vigilant as mobile-focused threats and malware-as-a-service proliferate.
6 months ago
Kill Chain
Maverick Malware Exploits WhatsApp to Target Brazil's Largest Banks
In November 2025, cybersecurity researchers identified a new banking malware called Maverick targeting users in Brazil via malicious WhatsApp messages. Leveraging similarities to the known Coyote strain, Maverick is written in .NET and specifically attacks customers of major Brazilian banks. The malware deceives users into installing it, then hijacks browser sessions, intercepts banking credentials, and enables real-time monitoring of financial transactions to facilitate fraud. This attack underscores the growing sophistication of financially-motivated threats exploiting popular messaging platforms as infection vectors, while leveraging encrypted communications to bypass traditional security controls. This incident is indicative of a rising trend in banking malware that utilizes encrypted and social engineering channels, challenging established security models. It highlights the need for organizations—particularly in financial services—to adopt advanced detection, segmentation, and encrypted traffic monitoring to reduce the impact of evolving threats.
6 months ago
Kill Chain
Yanluowang Ransomware & Access Broker Target U.S. Firms: Volkov Convicted
Between July 2021 and November 2022, multiple U.S. businesses—including an engineering firm and a bank—were targeted by the Yanluowang ransomware group, using access broker Aleksei Olegovich Volkov to gain initial entry. Volkov, operating as “chubaka.kor,” exploited vulnerabilities in victim networks, facilitated data theft and encryption, and coordinated ransom payments, some of which totaled $1.5 million. Victims suffered operational disruption, including temporary shutdowns and extortion attempts such as DDoS attacks and executive harassment. Forensic analysis linked the activities to Volkov via cryptocurrency tracing and communication evidence; $24 million in ransoms was demanded in total. This case highlights growing cooperation among cybercriminals, where access brokers sell or share footholds with ransomware operators, fueling larger-scale, multi-faceted cyber-extortion campaigns. The high-profile prosecution also sets precedent for international arrests and restitution, amid increasingly aggressive ransomware trends and evolving attack tactics.
6 months ago
Kill Chain
WhatsApp’s Screen-Sharing Feature: The 2024 Social Engineering Scam You Didn’t See Coming
In early 2024, a growing wave of cyber scams exploited WhatsApp’s new screen-sharing feature. Threat actors, posing as trusted contacts or customer support agents, lured victims into screen-sharing sessions under false pretenses—most often by claiming to offer help or resolve issues. Once shared, attackers gained access to sensitive information displayed on victims’ devices, including banking credentials and one-time passwords (OTPs), resulting in significant financial losses and compromised personal data. The scam’s speed and sophistication allowed fraudsters to bypass traditional awareness training and exploit even tech-savvy users. This incident highlights how social engineering threats adapt quickly to new app features, and underscores the need for rapid security responses. With mobile devices playing a pivotal role in personal and financial life, the exploitation of trusted communication platforms marks a critical evolution in phishing and remote fraud tactics.
6 months ago
Kill Chain
Capital One’s 2019 Cloud Breach: Insider Threats & Misconfiguration Risks
In 2019, Capital One suffered a major data breach when Paige Thompson, a former AWS engineer, exploited a cloud misconfiguration—specifically a poorly secured firewall running in Capital One's AWS environment—to access the personal information of over 100 million customers. The attacker leveraged insider knowledge and a misconfigured identity and access management policy to move laterally and exfiltrate sensitive data, including social security numbers and bank account details. The breach resulted in substantial financial costs, regulatory scrutiny, and reputational damage to Capital One, with Thompson ultimately convicted of wire fraud and computer intrusion. This incident remains relevant as organizations increasingly migrate to the cloud and face similar risks of configuration errors, compounded by the complexity of managing access controls and real-time monitoring in cloud-native infrastructures. The Capital One breach exemplifies the critical need for robust cloud security measures and continuous compliance with evolving regulatory requirements.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports