✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Banking/Mortgage
Breach intelligence, attack campaigns, and threat reports targeting the Banking/Mortgage sector.
Explore Other Sectors
Banking/Mortgage Threat Reports
Microsoft Uncovers Sophisticated Windows Clipper Malware Campaign
In June 2026, Microsoft disclosed a sophisticated malware campaign targeting Windows users through USB drives containing malicious LNK files. Once executed, these shortcuts leveraged Windows Script Host and ActiveX to initiate a Tor proxy, establishing a connection to a hidden command-and-control (C2) server. The primary objective of this campaign was to deploy a cryptocurrency clipper, designed to intercept and alter clipboard contents, thereby redirecting cryptocurrency transactions to attacker-controlled wallets. This incident underscores the persistent threat posed by USB-based malware and the evolving tactics of cybercriminals who exploit legitimate Windows functionalities to evade detection. The use of Tor for C2 communication highlights the increasing adoption of anonymization techniques by threat actors, complicating traditional network defense strategies.
1 month ago
Kill Chain
Crypto Clipper Malware: A New Threat Leveraging Tor and Worm-Like Propagation
In February 2026, Microsoft identified a Windows-based cryptocurrency clipper malware that propagates via malicious shortcut (.lnk) files. This malware comprises a worm component for self-propagation and a stealer component that harvests and exfiltrates cryptocurrency wallet information. Notably, it utilizes Windows Script Host and ActiveX to launch a bundled Tor proxy, enabling communication with a hidden-service command-and-control (C2) server. The malware performs high-frequency clipboard monitoring, screenshot exfiltration, and wallet-address substitution, effectively turning a financially motivated stealer into a lightweight backdoor. The incident underscores the evolving sophistication of malware leveraging anonymized communication channels like Tor and worm-like propagation methods. Organizations should be vigilant about script-based threats and implement behavioral detection mechanisms to identify suspicious activities such as script interpreters spawning unexpected child processes, localhost proxy usage, and clipboard inspection behaviors.
1 month ago
Kill Chain
Mastra npm Supply Chain Attack: A 2026 Case Study
In June 2026, a significant supply chain attack targeted the Mastra npm ecosystem, compromising over 140 packages. The attack originated from the hijacking of the 'ehindero' npm maintainer account, which was used to publish malicious versions of Mastra packages. These versions introduced 'easy-day-js,' a typosquat of the popular 'dayjs' library. Upon installation, 'easy-day-js' executed a postinstall script that disabled TLS certificate verification, contacted attacker-controlled command-and-control infrastructure, downloaded a second-stage payload, and executed it as a hidden process. This sophisticated attack posed substantial risks to developers and organizations relying on the affected packages. This incident underscores the escalating threat of supply chain attacks within the open-source ecosystem. The attackers' use of typosquatting and account hijacking highlights the need for enhanced security measures in package management and distribution. Organizations must remain vigilant, regularly audit their dependencies, and implement robust security practices to mitigate such risks.
1 month ago
Kill Chain
Crypto Clipper Campaign: A New Era of Cyber Deception
In June 2026, a sophisticated cyber campaign was uncovered wherein an unidentified threat actor utilized multiple platforms to distribute a Rust-based cryptocurrency clipboard hijacker targeting Windows and macOS users. The malware was disseminated through a dedicated WordPress phishing page, GitHub and SourceForge projects promoted by fake accounts, and a YouTube channel featuring AI-generated narrators. Additionally, the actor manipulated reputation systems by posting benign votes and "safe" comments on VirusTotal to misclassify the malicious files as harmless. This campaign highlights the evolving tactics of cybercriminals who exploit trust mechanisms across various platforms to deceive users into downloading malicious software. The use of AI-generated content and coordinated fake reviews underscores the need for heightened vigilance and advanced detection methods to combat such deceptive practices.
1 month ago
Kill Chain
Attacker Exploits Tailscale and OpenSSH for Persistent Access in French Automotive Business Breach
In April 2026, a French-speaking attacker, identified as 'Poisson,' infiltrated a small French automotive business. Utilizing a VBScript stager and PowerShell loader, he deployed the Havoc Demon agent in memory, avoiding disk detection. For persistence, he established scheduled tasks and injected shellcode into Explorer.exe. Notably, before his command-and-control (C2) server went offline, Poisson installed OpenSSH and Tailscale on a compromised machine, creating an independent access route. This allowed him to maintain control even after the C2 server was deactivated, leading to the theft of banking and email credentials. This incident underscores the evolving tactics of cybercriminals who leverage legitimate tools like Tailscale and OpenSSH to establish resilient backdoors. The use of such tools complicates detection and remediation efforts, highlighting the need for organizations to monitor for unauthorized installations and unusual network configurations.
1 month ago
Kill Chain
Phantom Stealer: The Rise of Fileless Malware Targeting Financial Institutions
In June 2026, a sophisticated phishing campaign targeted banks and high-value organizations, deploying Phantom Stealer—a fileless malware designed to evade traditional endpoint defenses. The attack began with phishing emails containing seemingly legitimate business documents. Upon opening, a heavily obfuscated batch file initiated a multistage infection chain, injecting Phantom Stealer into the Windows Explorer process. Operating entirely in memory, the malware silently exfiltrated browser credentials, session cookies, and financial data through multiple channels, including Telegram, Discord, FTP, and SMTP. This incident underscores the evolving tactics of cybercriminals, highlighting the increasing use of fileless malware and advanced evasion techniques. Organizations must enhance their security posture by adopting behavior-based detection systems and educating employees on recognizing sophisticated phishing attempts to mitigate such threats.
1 month ago
Kill Chain
Understanding the MongoBleed Vulnerability (CVE-2025-14847) and Its Impact
In December 2025, a critical vulnerability known as MongoBleed (CVE-2025-14847) was disclosed, affecting multiple versions of MongoDB Server from 3.6 through 8.2.3. This flaw allows unauthenticated attackers to exploit improper handling of zlib-compressed network traffic, leading to the leakage of uninitialized heap memory. As a result, sensitive data such as credentials, session tokens, and API keys could be exfiltrated from affected servers. The vulnerability has been actively exploited in the wild, with approximately 87,000 MongoDB instances exposed globally, primarily in the United States, China, and Germany. Organizations are strongly advised to apply security patches immediately or disable compression and restrict network exposure to mitigate the risk. ([infoq.com](https://www.infoq.com/news/2026/01/mongodb-mongobleed-vulnerability/?utm_source=openai)) The MongoBleed incident underscores the critical importance of timely patch management and the need for robust security measures to protect against vulnerabilities in widely used database systems. The rapid exploitation of this flaw highlights the evolving threat landscape and the necessity for organizations to remain vigilant in securing their infrastructure.
1 month ago
Kill Chain
Rokarolla Android Malware: A New Threat to Mobile Banking Security
In June 2026, a sophisticated Android banking Trojan named Rokarolla emerged, targeting 217 banking and cryptocurrency applications. Distributed through malicious websites masquerading as legitimate Google Chrome or TikTok apps, Rokarolla gains complete administrative control over infected devices. Its capabilities include stealing lock screen credentials, contact lists, SMS data, and continuously recording user input via keyloggers. The malware employs overlays to display fake login screens, capturing sensitive financial information when users access targeted applications. Additionally, Rokarolla disables Google Play Protect, hides its icon, and maintains persistence by preventing device sleep, thereby evading detection and removal. The emergence of Rokarolla underscores a significant evolution in Android malware, combining financial data theft with extensive device surveillance and control. This trend highlights the increasing sophistication of threat actors and the urgent need for enhanced mobile security measures to protect sensitive user information and maintain device integrity.
1 month ago
Kill Chain
Rokarolla Android Trojan: A New Era of Mobile Threats
In June 2026, the Rokarolla Android Trojan emerged, distributed through malicious websites masquerading as legitimate applications like Google Chrome and TikTok. This sophisticated malware not only compromised 217 banking and cryptocurrency apps to steal credentials but also executed 137 commands to gain full administrative control over infected devices. Its capabilities included harvesting lock screen credentials, exfiltrating sensitive data, deploying keyloggers, and rendering devices unusable by blocking calls, suppressing audio, and disabling security features such as Google Play Protect. ([darkreading.com](https://www.darkreading.com/endpoint-security/rokarolla-android-trojan?utm_source=openai)) The Rokarolla Trojan signifies a significant evolution in mobile malware, combining traditional banking fraud with extensive device surveillance and control. Its advanced persistence and evasion techniques highlight the increasing complexity of threats targeting Android devices, underscoring the necessity for robust mobile security measures and user vigilance against downloading apps from untrusted sources.
1 month ago
Kill Chain
FBI Issues Warning on New Cryptocurrency Scam Involving In-Person Couriers
In June 2026, the FBI issued a warning about a new tactic in cryptocurrency investment scams, commonly referred to as 'pig butchering' or 'romance baiting.' Fraudsters initiate contact through social media, dating sites, and messaging apps, building trust with victims before introducing them to fake investment schemes. When traditional financial institutions block suspicious transactions, these scammers dispatch couriers to collect cash directly from victims, often using agreed-upon passwords or specific dollar bill serial numbers for identification. Victims are led to believe their investments are growing, but when they attempt to withdraw funds, they are prompted to provide additional cash for fraudulent taxes and penalties, perpetuating the cycle. This incident underscores the evolving nature of cryptocurrency scams, highlighting the shift towards in-person interactions to circumvent financial safeguards. The FBI's alert serves as a critical reminder for individuals to exercise caution when approached with unsolicited investment opportunities, especially those involving direct cash transactions facilitated by couriers.
1 month ago
Kill Chain
FBI Dismantles AI-Powered Phishing Operation 'Outsider Enterprise'
In June 2026, the FBI, in collaboration with Google and Black Lotus Labs, dismantled 'Outsider Enterprise,' a Chinese phishing-as-a-service operation active since at least 2023. This cybercrime network utilized AI to distribute phishing kits, creating over 9,000 fake websites and more than a million fraudulent URLs. These sites impersonated trusted brands, leading to the theft of approximately 3.8 million credit card records and causing an estimated $1.9 billion in losses. The takedown, part of Operation Riptide, involved seizing multiple servers, a Shopify storefront, and around $100,000 USDT from Outsider's payment wallets. Thousands of phishing domains now redirect to an FBI splash page. This incident underscores the escalating use of AI in cybercrime, enabling large-scale, sophisticated phishing campaigns. The success of Operation Riptide highlights the importance of coordinated efforts between law enforcement and private sector entities in combating such threats.
1 month ago
Kill Chain
FBI Dismantles Outsider Cybercrime Network Responsible for $1.9 Billion in Losses
In June 2026, the FBI, in collaboration with Google and Lumen Technologies, dismantled a significant China-based cybercrime network known as Outsider Enterprise. This operation, dubbed 'Operation Ghost Hook,' targeted a phishing-as-a-service platform that had been active since July 2023. Outsider provided cybercriminals with phishing kits and hosted infrastructure, enabling them to impersonate trusted brands and defraud victims across 55 countries, including the United States. The takedown resulted in the seizure of several core admin server domains, a Shopify storefront, approximately $100,000 from Outsider's payment wallets, and thousands of domains registered through U.S.-based providers. Authorities linked Outsider's phishing domains to nearly 3.9 million stolen credit cards, contributing to an estimated $1.9 billion in losses. This incident underscores the evolving sophistication of cybercriminal operations, particularly the use of AI to enhance phishing campaigns. The Outsider platform's integration of AI tools like Google's Gemini allowed for the creation of highly convincing phishing lures, making it increasingly challenging for individuals and organizations to detect and prevent such attacks. The takedown highlights the necessity for continuous advancements in cybersecurity measures and the importance of international cooperation in combating cyber threats.
1 month ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports