✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Banking/Mortgage
Breach intelligence, attack campaigns, and threat reports targeting the Banking/Mortgage sector.
Explore Other Sectors
Banking/Mortgage Threat Reports
Marquis Software 2025 Ransomware Breach: A Wake-Up Call for Third-Party Risk Management
In August 2025, Marquis Software Solutions, a fintech firm serving over 70 banks and credit unions, suffered a ransomware attack that compromised sensitive personal and financial data of more than 1.3 million individuals. The breach was attributed to a vulnerability in SonicWall's firewall backup service, which allowed attackers to access Marquis's internal network. Exposed information included names, addresses, Social Security numbers, and financial account details. This incident underscores the critical importance of securing third-party services and the potential cascading effects of supply chain vulnerabilities. ([claimdepot.com](https://www.claimdepot.com/data-breach/marquis-software-solutions-2025?utm_source=openai)) The Marquis breach highlights the escalating risks associated with third-party service providers in the financial sector. As cyberattacks become more sophisticated and supply chain vulnerabilities more prevalent, organizations must adopt comprehensive security measures, including continuous monitoring and regular penetration testing, to safeguard sensitive data and maintain regulatory compliance.
1 month ago
Kill Chain
U.S. Treasury Sanctions Nobitex for IRGC-Linked Transactions
In June 2026, the U.S. Treasury's Office of Foreign Assets Control (OFAC) sanctioned Nobitex, Iran's largest cryptocurrency exchange, for facilitating transactions linked to the Islamic Revolutionary Guard Corps (IRGC), including those associated with IRGC-affiliated ransomware actors. Nobitex processed over 50% of Iran's digital asset inflows in 2025 and assisted the Central Bank of Iran in accessing hundreds of millions of dollars in stablecoins to support the Iranian rial. This action is part of the U.S. government's "Economic Fury" campaign targeting financial networks supporting terrorism and sanctions evasion. The sanctions underscore the increasing scrutiny of cryptocurrency platforms used to circumvent international sanctions and finance illicit activities. Organizations must enhance their compliance measures to prevent inadvertent involvement in such networks, as regulatory bodies intensify efforts to disrupt financial channels linked to state-sponsored cyber threats.
1 month ago
Kill Chain
Google's June 2026 Android Security Update: Addressing 124 Vulnerabilities, Including Actively Exploited CVE-2025-48595
In June 2026, Google released security updates addressing 124 vulnerabilities in the Android operating system, notably including CVE-2025-48595—a high-severity privilege escalation flaw in the Framework component. This vulnerability affects Android versions 14 through 16 QPR2 and allows attackers to gain elevated privileges without user interaction, potentially leading to full device compromise. Google has acknowledged indications of limited, targeted exploitation of this flaw in the wild. The active exploitation of CVE-2025-48595 underscores the persistent threat posed by privilege escalation vulnerabilities in widely used mobile platforms. Organizations and individuals are urged to promptly apply the June 2026 security patches to mitigate potential risks associated with this and other addressed vulnerabilities.
1 month ago
Kill Chain
SideCopy's Operation XENOFISCAL: A Targeted Cyber Espionage Campaign
In May 2026, the Pakistan-linked threat group SideCopy launched a spear-phishing campaign, dubbed Operation XENOFISCAL, targeting Afghanistan's Ministry of Finance and provincial finance officials. The attackers used ZIP archives containing malicious LNK files with Pashto-language filenames to deliver the open-source remote access trojan Xeno RAT. Once executed, the malware established persistence, enabling the attackers to exfiltrate sensitive data and maintain long-term access to compromised systems. This campaign underscores the persistent cyber threats facing governmental institutions in South Asia, highlighting the need for enhanced cybersecurity measures and vigilance against sophisticated phishing attacks.
1 month ago
Kill Chain
Urgent Alert: Active Exploitation of Critical Windows Netlogon Vulnerability (CVE-2026-41089)
In May 2026, Microsoft disclosed CVE-2026-41089, a critical stack-based buffer overflow vulnerability in the Windows Netlogon service, affecting all supported Windows Server versions, including Windows Server 2025. This flaw allows unauthenticated attackers to execute arbitrary code on domain controllers by sending specially crafted network requests. The Centre for Cybersecurity Belgium (CCB) reported active exploitation of this vulnerability in June 2026, emphasizing the urgency for organizations to apply the available security patches promptly. The exploitation of CVE-2026-41089 underscores a growing trend of attackers rapidly leveraging newly disclosed vulnerabilities to compromise critical infrastructure. This incident highlights the necessity for organizations to maintain vigilant patch management practices and to implement robust monitoring systems to detect and respond to such threats swiftly.
1 month ago
Kill Chain
Palo Alto GlobalProtect VPN Auth Bypass Flaw (CVE-2026-0257) Exploited in Attacks
In May 2026, Palo Alto Networks disclosed an authentication bypass vulnerability (CVE-2026-0257) in their PAN-OS GlobalProtect portal and gateway, allowing unauthenticated attackers to establish unauthorized VPN connections. Initially rated as medium severity, the flaw's risk escalated when active exploitation was observed starting May 17, 2026, leading to unauthorized access attempts on corporate networks. ([security.paloaltonetworks.com](https://security.paloaltonetworks.com/CVE-2026-0257?utm_source=openai)) The active exploitation of CVE-2026-0257 underscores the critical need for organizations to promptly apply security patches and review VPN configurations to prevent unauthorized access, especially as attackers increasingly target remote access solutions.
1 month ago
Kill Chain
Google Chrome's New DBSC Feature: A Leap Forward in Browser Security
In May 2026, Google announced the general availability of Device Bound Session Credentials (DBSC) in Chrome, a security feature designed to prevent session cookie theft. DBSC cryptographically binds session cookies to a user's device using hardware-backed security modules like the Trusted Platform Module (TPM) on Windows and the Secure Enclave on macOS. This binding ensures that even if session cookies are exfiltrated, they cannot be used on unauthorized devices, thereby mitigating risks associated with session hijacking and account takeovers. ([developer.chrome.com](https://developer.chrome.com/docs/web-platform/device-bound-session-credentials?hl=en&utm_source=openai)) The introduction of DBSC addresses the growing threat posed by infostealer malware, which has been increasingly used to extract session cookies and bypass multi-factor authentication. By implementing DBSC, Google enhances user security by proactively preventing unauthorized access through stolen session cookies, marking a significant advancement in browser security measures. ([techradar.com](https://www.techradar.com/pro/security/google-chrome-rolls-out-a-new-tool-to-try-and-stop-infostealer-malware-in-its-tracks?utm_source=openai))
1 month ago
Kill Chain
Malicious Sicoob NuGet Package Compromises Banking Credentials
In May 2026, cybersecurity researchers discovered a malicious NuGet package named 'Sicoob.Sdk' that impersonated a C# software development kit for Sicoob, one of Brazil's largest cooperative financial systems. Versions 2.0.0 through 2.0.4 of this package were found to exfiltrate sensitive information, including client IDs and PFX certificates, which are crucial for secure communications. This incident underscores the growing trend of supply chain attacks targeting software development ecosystems to steal sensitive data. The discovery of 'Sicoob.Sdk' aligns with a series of recent supply chain attacks where malicious packages infiltrate trusted repositories. For instance, the 'TrapDoor' campaign targeted npm, PyPI, and Crates.io ecosystems to distribute credential-stealing malware. These incidents highlight the urgent need for enhanced vigilance and security measures within software supply chains to protect against such threats.
1 month ago
Kill Chain
BTMOB: The No-Code Android Malware Service Empowering Cybercriminals
In May 2026, cybersecurity researchers identified BTMOB, an Android remote access trojan (RAT) offered as a malware-as-a-service (MaaS) platform. BTMOB provides cybercriminals with a no-code APK builder, enabling the creation of customized phishing payloads without programming expertise. The malware grants attackers extensive control over infected devices, including data exfiltration, financial transaction interception, screenshot capture, and remote operation. Distributed primarily through phishing websites impersonating legitimate services, BTMOB has been notably active in Brazil and Latin America. Its accessibility and comprehensive feature set pose a significant threat to Android users globally. The emergence of BTMOB underscores a concerning trend in the cyber threat landscape: the commoditization of sophisticated malware through MaaS platforms. This development lowers the barrier to entry for cybercriminals, facilitating the rapid proliferation of advanced threats. Organizations must remain vigilant, as the ease of deploying such malware increases the risk of widespread attacks targeting mobile devices.
1 month ago
Kill Chain
BTMOB RAT: A New Android Malware-as-a-Service Threat
In May 2026, cybersecurity researchers identified BTMOB, an Android Remote Access Trojan (RAT), actively targeting users in Brazil and Latin America. Distributed through phishing campaigns that mimic legitimate services, BTMOB is sold as a malware-as-a-service (MaaS), allowing attackers to create malicious apps without coding expertise. Once installed, it exploits Android's Accessibility Services to gain elevated permissions, enabling data exfiltration, screen capture, and full remote control of infected devices. This comprehensive access poses significant risks, including financial theft and privacy breaches. The emergence of BTMOB underscores a growing trend in the commoditization of sophisticated malware, lowering the barrier for cybercriminals and expanding the threat landscape. Its MaaS model facilitates rapid adaptation and distribution, making it a formidable challenge for cybersecurity defenses worldwide.
1 month ago
Kill Chain
Grandoreiro and BTMOB Malware Campaigns: A 2026 Cybersecurity Threat
In May 2026, cybersecurity firms WatchGuard and ESET identified two sophisticated banking trojan campaigns targeting Windows and Android users in Latin America and Europe. The Grandoreiro malware, active since 2016, employs DLL side-loading techniques to infiltrate Windows systems, primarily targeting financial institutions in Portugal. Concurrently, the BTMOB remote access trojan (RAT) compromises Android devices, enabling attackers to exfiltrate sensitive data and gain remote control. These campaigns utilize phishing emails and deceptive websites to distribute malicious payloads, posing significant threats to both individual users and organizations. The persistence and evolution of these malware families underscore the adaptability of financially motivated threat actors. By leveraging legitimate services and employing advanced evasion techniques, such as WebRTC communications and anti-analysis checks, these campaigns highlight the increasing complexity of modern cyber threats and the necessity for robust, multi-layered security defenses.
2 months ago
Kill Chain
BTMOB Android RAT: Unveiling a Stealthy Mobile Threat
In early 2025, the BTMOB Android Remote Access Trojan (RAT) emerged as a significant cybersecurity threat, evolving from the SpySolr malware. Unlike traditional banking trojans, BTMOB offers adversaries extensive capabilities, including data exfiltration, screenshot capture, activity recording, and full remote control of infected devices. Distributed primarily through phishing campaigns that mimic legitimate services, victims are lured into downloading malicious APKs from fake app stores. Once installed, BTMOB exploits Android's Accessibility Services to gain elevated permissions, enabling it to operate stealthily and grant attackers comprehensive access to the device. The malware's commercialization through a no-code APK builder interface lowers the barrier for cybercriminals, allowing rapid generation of new payloads and tailored phishing lures without coding expertise. This ease of customization and distribution has led to its proliferation beyond initial detections in Brazil, posing a global threat to Android users. ([welivesecurity.com](https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/?utm_source=openai))
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports