✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Banking/Mortgage
Breach intelligence, attack campaigns, and threat reports targeting the Banking/Mortgage sector.
Explore Other Sectors
Banking/Mortgage Threat Reports
2024 Android Infostealer Attack: How Termux and Telegram Fueled Stealthy Mobile Data Breaches
In October 2024, researchers identified a novel Android infostealer undetected by antivirus engines, leveraging Termux—a legitimate terminal emulator app—to collect sensitive data from mobile devices. The attacker deployed a Python-based stealer designed to extract user contacts, SMS, call logs, location data, and app-specific files, including those for Facebook, WhatsApp, and banking. Exfiltration occurred via Telegram API integration, and a persistent backdoor was installed for continued access. The operation showcased clever abuse of legitimate utilities, with initial device compromise mechanics still unclear, though social engineering leading to the installation of Termux is likely. This incident highlights the evolving landscape in which infostealers now aggressively target mobile platforms as device usage and data stored on them surge. With sophisticated yet undetectable malware exploiting legitimate tools and APIs, organizations and users face heightened risks from threats previously confined mostly to Windows environments.
6 months ago
Kill Chain
Mideast & African Hackers Launch Multi-Vector Attacks on Governments, Banks, and Retailers in 2024
In early 2024, multiple threat groups originating from the Middle East and Africa executed a series of sophisticated, multi-vector cyber campaigns targeting government agencies, banks, and small to midsize retailers across the region. Attackers leveraged a blend of techniques including encrypted traffic evasion, lateral movement, cloud misconfiguration, and remote access tools. These campaigns exploited gaps in east-west security, egress controls, and cloud segmentation, resulting in data exfiltration, service disruptions, and operational downtime across multiple sectors. The tactics exposed critical weaknesses in hybrid cloud architectures, impacting regulatory compliance and eroding trust in public and financial institutions. This incident highlights the escalating trend of advanced regional threat actors targeting not just political or large economic entities, but also smaller businesses, using methods that combine traditional and cloud-native attack vectors. The frequency and sophistication of such attacks underscore the need for adaptive, zero trust security frameworks and heightened vigilance across both public and private sectors.
6 months ago
Kill Chain
The 2024 Global Smishing Deluge: China-Based SMS Phishing at Scale
In early 2024, a China-based threat group orchestrated a massive global smishing campaign, flooding mobile devices across multiple continents with fraudulent SMS messages impersonating banks, government agencies, and delivery services. Leveraging a rapidly-evolving attack ecosystem, the actors utilized wide-scale automation and regional tailoring to bypass spam filters and trick users into revealing sensitive credentials or installing malware. The attack’s magnitude caught many organizations off guard, resulting in significant credential theft, unauthorized transactions, and growing operational strain as firms raced to block fast-moving SMS domains and educate affected users. This campaign signals a sharp escalation in the sophistication and reach of smishing attacks, highlighting persistent gaps in mobile security awareness and detection. As similar TTPs gain traction among organized threat groups, critical infrastructure and commercial service providers face increased risks of large-scale credential exposure and downstream fraud.
6 months ago
Kill Chain
F5 2025 Supply-Chain Breach: Nation-State Attackers Target Update Infrastructure
In October 2025, F5 Networks—an industry-leading provider of enterprise networking and security appliances—disclosed a sophisticated supply-chain breach attributed to a nation-state threat actor. Attackers maintained long-term, covert access to F5’s internal environment, ultimately compromising systems responsible for building and distributing software updates for its widely deployed BIG-IP products. The breach allowed unauthorized access to proprietary source code, documentation of unpatched vulnerabilities, and a trove of sensitive customer configuration data, significantly enlarging the risks of downstream exploitation for thousands of major enterprises and critical infrastructure providers globally. This incident underscores the growing threat of highly persistent, technically advanced supply-chain attacks targeting the software build and delivery processes of core technology vendors. The breach reflects recent escalation in nation-state tactics and highlights the continued exposure of global businesses to supply-chain and software update system threats.
6 months ago
Kill Chain
FinWise Data Breach 2024: When Encryption Is the Last Line of Defense
In early 2024, FinWise, a financial services provider, suffered a significant data breach traced to an insider threat that circumvented internal security controls. The attacker exploited inadequate encryption of sensitive data in transit, extracting customer records via lateral movement across poorly segmented network segments. Because traffic was not properly encrypted, packet sniffing allowed the attacker to collect financial and personal data largely undetected for several weeks. The breach led to loss of confidential information, potential regulatory scrutiny, and reputational harm for FinWise. This incident highlights a rising wave of insider threats exploiting deficiencies in east-west traffic security and underscores the importance of robust, end-to-end encryption as regulatory bodies tighten requirements for securing data in transit and at rest across hybrid and multi-cloud environments.
6 months ago
Kill Chain
BetterBank DeFi 2025: How a Reward Logic Flaw Led to a $5M Crypto Breach
From August 26 to 27, 2025, BetterBank, a DeFi protocol on PulseChain, suffered a major exploit in its ESTEEM reward logic, allowing an attacker to mint unlimited bonus tokens by abusing flaws in liquidity pool validation. The vulnerability enabled the creation of fake trading pairs and a recursive loop of reward minting, resulting in an initial $5 million loss. Notably, after open negotiations, $2.7 million of the pilfered assets were returned, but the net damage remained at approximately $1.4 million to users and the protocol. The breach highlights organizational and technical oversights, as a prior security audit flagged this very issue. This incident exemplifies the growing threat of sophisticated smart contract exploits targeting DeFi platforms. As similar attacks proliferate across decentralized protocols, regulators and security teams are intensifying scrutiny and demanding higher levels of design and audit rigor.
6 months ago
Kill Chain
Fake Nethereum NuGet Package Exploited Homoglyph Trick in 2025 Supply Chain Attack
In October 2025, cybersecurity experts identified a sophisticated supply chain attack wherein a malicious NuGet package, imitating the popular Nethereum library using a homoglyph trick, was uploaded to compromise .NET developers. The attacker distributed a typosquatted package ('Netherеum.All') containing encoded command-and-control (C2) communication that secretly harvested and exfiltrated sensitive cryptocurrency wallet credentials—including private keys and mnemonic phrases—from unsuspecting developers’ systems. The campaign demonstrates a heightened level of precision in leveraging open-source repositories for credential theft, with potential widespread financial impacts for organizations developing blockchain solutions. This incident exemplifies the rapidly increasing risk posed by supply chain attacks exploiting trusted software ecosystems. It highlights both a surge in homoglyph-based typosquatting and a broader trend of targeting cryptocurrency assets via development toolchains—emphasizing the need for robust code provenance controls and package vetting.
6 months ago
Kill Chain
Canada Fines Cryptomus $176M Over Cybercrime Payment Networks
In October 2024, the Financial Transactions and Reports Analysis Center of Canada (FINTRAC) levied a record $176 million fine against Cryptomus, a digital payments platform, for violating Canada's anti-money laundering laws. Investigations uncovered that Cryptomus helped facilitate transactions for dozens of Russian cryptocurrency exchanges and cybercrime-related services without submitting suspicious transaction reports. Infractions were linked to money laundering for child sexual abuse material, fraud, ransomware, and sanctions evasion. The business used a Vancouver address also tied to numerous other questionable entities, none of which had any physical presence at the location. This enforcement action highlights intensifying global scrutiny on cryptocurrency payment processors and money service businesses (MSBs) operating as shadow facilitators for cybercriminals, particularly in regions facing heightened sanctions. As regulators ramp up pressure, organizations relying on cryptographic payment tools, or with exposure to digital currency ecosystems, must reassess their compliance, monitoring, and due diligence procedures in light of evolving financial crime threats.
6 months ago
Kill Chain
International SIM Box Fraud Network Dismantled in Major 2024 Sting Operation
In June 2024, law enforcement agencies from multiple countries executed a coordinated operation that dismantled a large-scale SIM box fraud network. This criminal enterprise facilitated the use of SIM boxes—devices housing dozens or hundreds of SIM cards—to provide fake phone numbers from over 80 countries to criminals. The network enabled anonymous communications for threat actors, facilitating various cybercrimes such as phishing, scams, and the circumvention of telecommunication safeguards. The takedown targeted both the technical infrastructure and the operators, disrupting ongoing fraudulent operations and preventing further abuse. This operation underscores an increased focus among law enforcement on telecom fraud infrastructure, which has proliferated alongside the rise in organized cybercrime and financial scams leveraging global communications. Recent trends show cybercriminals rapidly adopting new tools like SIM farms for voice spoofing, making such police action both timely and necessary.
6 months ago
Kill Chain
Astaroth Banking Trojan Leverages GitHub to Evade Takedowns in 2025
In October 2025, cybersecurity researchers uncovered a sophisticated campaign distributing the Astaroth banking trojan, which leveraged GitHub repositories as its primary command-and-control infrastructure. By shifting away from traditional, easily dismantled C2 servers, attackers used public code-hosting platforms to deploy configuration files and payloads. Targeted endpoints were infected through phishing campaigns, after which Astaroth would harvest credentials and financial data undetected. The integration with GitHub provided attackers increased operational resilience, making takedown efforts by defenders and law enforcement more challenging. Financial institutions and users experienced notable disruptions and heightened risk of unauthorized account activity due to these stealthy techniques. This incident highlights a growing trend of threat actors abusing legitimate platforms for illicit operations, undermining trust in cloud services. Organizations must reassess controls and detection strategies as adversaries increasingly exploit mainstream tools and shift to fileless, cloud-hosted malware models.
6 months ago
Kill Chain
TA585’s MonsterV2: Unveiling 2025’s Next-Gen Phishing Infostealer Threat
In October 2025, cybersecurity researchers uncovered new activities by the previously undocumented threat actor TA585, which was observed conducting sophisticated phishing attacks to deliver the MonsterV2 infostealer malware. The group leveraged advanced tactics, including web injections and traffic filtering, to evade detection and ensure payload delivery. Once deployed, MonsterV2 enabled TA585 to harvest sensitive information and credentials, posing significant risks to organizational data integrity and confidentiality. The attack chains exploited weaknesses in email security and endpoint controls, demonstrating a concerning evolution in social engineering and malware delivery. This incident highlights the growing prevalence of stealthy infostealer campaigns targeting enterprises across multiple sectors. It underscores the urgent need for organizations to reevaluate network segmentation, multi-cloud visibility, and anomaly detection strategies to counter increasingly capable threat actors and align with evolving compliance standards.
6 months ago
Kill Chain
Pixnapping: The Android Flaw Allowing Rogue Apps to Bypass 2FA Security (2025 Breach Analysis)
In October 2025, security researchers from the University of California, Berkeley, uncovered a critical vulnerability affecting Google and Samsung Android devices. The flaw, dubbed "Pixnapping," enables malicious apps to perform pixel-by-pixel side-channel attacks, covertly extracting two-factor authentication (2FA) codes, mapping data (such as Google Maps timelines), and other sensitive on-screen information—all without any special permissions or user awareness. Threat actors can exploit this vulnerability by luring users into installing rogue apps, ultimately undermining common security practices that rely on device or app isolation to keep critical data secure. This incident highlights an increasing trend of advanced side-channel techniques targeting mobile devices, even in environments with strict permission models. As mobile malware continues to evolve, organizations and individuals must stay vigilant, adapt security controls, and reevaluate the effectiveness of current detection and segmentation approaches to safeguard sensitive data.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports