The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Banking/Mortgage
Breach intelligence, attack campaigns, and threat reports targeting the Banking/Mortgage sector.
Explore Other Sectors
Banking/Mortgage Threat Reports
AI-Assisted Zero-Day Exploit: A New Era in Cyber Threats
In May 2026, Google's Threat Intelligence Group identified the first documented instance of cybercriminals utilizing artificial intelligence to develop a zero-day exploit. The attackers employed AI to discover a flaw in a Python script, enabling them to bypass two-factor authentication on a widely-used open-source system. The exploit code exhibited characteristics indicative of AI assistance, such as explanatory comments and an invented severity rating. This incident underscores a significant shift in cyber threat dynamics, as AI begins to play an active role in enhancing the capabilities of cyberattacks. The discovery highlights the growing reliance of both state-sponsored and criminal cyber threat actors on AI across various stages of attack, from exploit development to social engineering. As AI models become increasingly adept at uncovering subtle software vulnerabilities, the cybersecurity landscape faces new challenges in defending against these sophisticated, AI-driven threats.
4 months ago
Kill Chain
Critical Windows Zero-Day Vulnerabilities: YellowKey and GreenPlasma Exposed
In May 2026, cybersecurity researcher Chaotic Eclipse disclosed two critical zero-day vulnerabilities in Microsoft Windows: YellowKey and GreenPlasma. YellowKey allows attackers with physical access to bypass BitLocker encryption on Windows 11 and Windows Server 2022/2025 systems by exploiting the Windows Recovery Environment (WinRE). GreenPlasma is a privilege escalation flaw that enables unprivileged users to gain SYSTEM-level access by manipulating the CTFMON process. Both vulnerabilities were publicly disclosed due to the researcher's dissatisfaction with Microsoft's handling of bug reports. The public release of these exploits underscores the ongoing challenges in securing widely used encryption and privilege management systems. Organizations must reassess their reliance on BitLocker for data protection and implement additional security measures to mitigate the risks posed by these vulnerabilities.
4 months ago
Kill Chain
TrickMo's Evolution: Leveraging TON for Enhanced Stealth in Banking Malware
In early 2026, a new variant of the TrickMo Android banking trojan emerged, leveraging The Open Network (TON) for command-and-control (C2) communications. This variant, observed by ThreatFabric between January and February 2026, actively targeted banking and cryptocurrency wallet users in France, Italy, and Austria. By utilizing TON's decentralized infrastructure, the malware effectively evaded traditional domain takedown efforts, complicating mitigation strategies. ([infosecurity-magazine.com](https://www.infosecurity-magazine.com/news/trickmo-c-ton-network-android/?utm_source=openai)) The adoption of TON for C2 communications signifies a broader trend among threat actors toward decentralized platforms to enhance stealth and resilience. This evolution underscores the need for security teams to adapt detection and response strategies to address threats that exploit decentralized networks. ([securityaffairs.com](https://securityaffairs.com/192003/malware/android-banking-trojan-trickmo-evolves-using-ton-network-for-c2.html?utm_source=openai))
4 months ago
Kill Chain
TrickMo Android Banker Leverages TON Blockchain for Covert Operations
In May 2026, a new variant of the TrickMo Android banking malware emerged, targeting users in France, Italy, and Austria. Disguised as popular apps like TikTok and streaming services, this malware employs The Open Network (TON) blockchain for covert command-and-control communications, enhancing its stealth and resilience. TrickMo's capabilities include intercepting one-time passwords (OTPs), recording screens, exfiltrating data, and executing overlay attacks to steal banking credentials. The malware's use of TON's decentralized infrastructure complicates detection and mitigation efforts. This incident underscores a growing trend of cybercriminals leveraging decentralized technologies to evade traditional security measures. The adoption of blockchain for malicious communications highlights the need for advanced detection strategies and reinforces the importance of user vigilance against social engineering tactics.
4 months ago
Kill Chain
TCLBANKER: A New Threat to Financial Platforms via WhatsApp and Outlook
In May 2026, Elastic Security Labs identified a new Brazilian banking trojan named TCLBANKER, which targets 59 banking, fintech, and cryptocurrency platforms. The malware is distributed through a trojanized Logitech installer and employs advanced anti-analysis techniques. Once installed, TCLBANKER monitors browser activity and overlays fraudulent interfaces to steal user credentials. Additionally, it propagates via WhatsApp and Outlook by sending malicious links to the victim's contacts, facilitating further infections. This incident underscores the evolving sophistication of banking trojans, particularly in their use of legitimate applications for distribution and self-propagation through popular communication platforms. Organizations must enhance their security measures to detect such advanced threats and educate users on recognizing and avoiding malicious links.
4 months ago
Kill Chain
TCLBanker: The Self-Spreading Banking Trojan Threatening Financial Security
In May 2026, a sophisticated banking trojan named TCLBanker emerged, targeting 59 banking, fintech, and cryptocurrency platforms primarily in Brazil. The malware infiltrates systems through a trojanized MSI installer for Logitech AI Prompt Builder, employing DLL side-loading to evade detection. Once installed, TCLBanker monitors browser activity, activating when users access targeted financial websites. It establishes a WebSocket connection to its command-and-control server, enabling attackers to perform live screen streaming, keylogging, clipboard hijacking, and remote command execution. Additionally, TCLBanker features self-propagating worm modules that exploit WhatsApp and Outlook to spread the malware to the victim's contacts, significantly increasing its reach and impact. The emergence of TCLBanker underscores a concerning evolution in banking malware, combining advanced evasion techniques with self-propagation capabilities. This development highlights the urgent need for enhanced cybersecurity measures, particularly in the financial sector, to counteract increasingly sophisticated threats that can rapidly disseminate through trusted communication channels.
4 months ago
Kill Chain
PCPJack Credential Stealer Exploits Multiple CVEs to Target Cloud Systems
In May 2026, cybersecurity researchers uncovered PCPJack, a sophisticated credential theft framework targeting exposed cloud infrastructures. The toolset infiltrates services such as Docker, Kubernetes, Redis, MongoDB, and RayML, harvesting credentials from cloud, container, developer, productivity, and financial services. It exfiltrates the stolen data through attacker-controlled infrastructure and propagates in a worm-like fashion by exploiting known vulnerabilities, including CVE-2025-55182, CVE-2025-29927, CVE-2026-1357, CVE-2025-9501, and CVE-2025-48703. Notably, PCPJack removes artifacts linked to the threat actor TeamPCP from compromised environments, suggesting a possible connection or rivalry between the two groups. The campaign's primary objective appears to be generating illicit revenue through credential theft, fraud, spam, extortion, or resale of stolen access. This incident underscores the evolving threat landscape in cloud security, highlighting the increasing sophistication of attacks targeting cloud infrastructures. Organizations must remain vigilant, ensuring timely patching of known vulnerabilities and implementing robust security measures to protect against such credential theft campaigns.
4 months ago
Kill Chain
Critical Zero-Day Vulnerability in Palo Alto Networks Firewalls Exploited
In May 2026, Palo Alto Networks disclosed a critical buffer overflow vulnerability (CVE-2026-0300) in the User-ID Authentication Portal of their PAN-OS software. This flaw allows unauthenticated attackers to execute arbitrary code with root privileges on PA-Series and VM-Series firewalls by sending specially crafted packets. Active exploitation of this zero-day vulnerability has been observed, particularly targeting firewalls with the User-ID Authentication Portal exposed to untrusted networks or the public internet. ([securityvulnerability.io](https://securityvulnerability.io/vulnerability/CVE-2026-0300?utm_source=openai)) The incident underscores the persistent threat posed by zero-day vulnerabilities in critical network infrastructure. Organizations are urged to implement immediate mitigations, such as restricting access to the vulnerable portal to trusted networks or disabling it if not required, until official patches are released. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/05/06/palo-alto-firewalls-vulnerability-exploited-cve-2026-0300/?utm_source=openai))
4 months ago
Kill Chain
CloudZ RAT and Pheno Plugin Exploit Windows Phone Link to Bypass 2FA
In January 2026, attackers initiated a campaign leveraging the CloudZ remote access Trojan (RAT) and a new plugin named Pheno to exploit Microsoft's Phone Link application on Windows PCs. By compromising the PC, they intercepted SMS messages and one-time passwords (OTPs) synced from connected mobile devices, effectively bypassing two-factor authentication without directly infecting the phones. ([darkreading.com](https://www.darkreading.com/cyberattacks-data-breaches/attacks-abuse-windows-phone-link-texts-bypass-2fa?utm_source=openai)) This incident underscores the evolving tactics of cybercriminals who are now targeting cross-device synchronization tools to access sensitive information. The exploitation of trusted applications like Phone Link highlights the need for enhanced security measures in endpoint management and the potential vulnerabilities in multi-factor authentication systems. ([darkreading.com](https://www.darkreading.com/cyberattacks-data-breaches/attacks-abuse-windows-phone-link-texts-bypass-2fa?utm_source=openai))
4 months ago
Kill Chain
CloudZ Malware Exploits Microsoft Phone Link to Steal SMS and OTPs
In May 2026, cybersecurity researchers identified a new variant of the CloudZ remote access tool (RAT) that employs a malicious plugin named Pheno to exploit Microsoft's Phone Link application. This malware monitors active Phone Link sessions on Windows 10 and 11 systems, accessing the application's local SQLite database to intercept SMS messages and one-time passwords (OTPs) without compromising the associated mobile device. The attack chain begins with a fake ScreenConnect update, leading to the deployment of a Rust-based loader, followed by a .NET loader that installs CloudZ RAT and establishes persistence via a scheduled task. The .NET loader includes anti-analysis checks to evade detection. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/cloudz-malware-abuses-microsoft-phone-link-to-steal-sms-and-otps/?utm_source=openai)) This incident underscores the evolving tactics of threat actors who are increasingly targeting desktop applications that bridge connections to mobile devices. By compromising the Phone Link application, attackers can bypass traditional mobile security measures and directly access sensitive authentication codes, highlighting the need for enhanced security protocols in cross-device applications. ([csoonline.com](https://www.csoonline.com/article/4167092/stealthy-malware-abuses-microsoft-phone-link-to-siphon-sms-otps-from-enterprise-pcs.html?utm_source=openai))
4 months ago
Kill Chain
Quasar Linux Malware: A New Threat to Software Developers in 2026
In May 2026, cybersecurity researchers identified Quasar Linux (QLNX), a sophisticated malware targeting software developers' systems. QLNX combines rootkit, backdoor, and credential-stealing functionalities, deploying across development environments like npm, PyPI, GitHub, AWS, Docker, and Kubernetes. It achieves stealth and persistence through in-memory execution, log wiping, process name spoofing, and multiple persistence mechanisms, including LD_PRELOAD and systemd. The malware's capabilities include interactive shell access, file and process management, credential harvesting (SSH keys, browser data, cloud configurations), keylogging, and lateral movement via SSH-based techniques. By compromising developer workstations, QLNX poses a significant supply chain risk, potentially enabling attackers to publish malicious packages to public repositories. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/new-stealthy-quasar-linux-malware-targets-software-developers/amp/?utm_source=openai)) The emergence of QLNX underscores a growing trend of sophisticated malware targeting development environments to facilitate supply chain attacks. This incident highlights the critical need for enhanced security measures within software development pipelines to prevent unauthorized access and mitigate potential threats to software supply chains.
4 months ago
Kill Chain
Understanding the 'Copy Fail' Linux Vulnerability (CVE-2026-31431) and Its Implications
In April 2026, Theori disclosed a critical local privilege escalation vulnerability, CVE-2026-31431, dubbed 'Copy Fail,' affecting Linux kernels since 2017. This flaw resides in the 'algif_aead' cryptographic interface, allowing unprivileged users to escalate privileges to root, thereby gaining full system control. Major distributions like Ubuntu 24.04 LTS, Amazon Linux 2023, RHEL 10.1, and SUSE 16 are impacted. The vulnerability has been actively exploited in the wild, prompting the Cybersecurity and Infrastructure Security Agency (CISA) to add it to its Known Exploited Vulnerabilities catalog. ([tomshardware.com](https://www.tomshardware.com/software/linux/cisa-flags-actively-exploited-copy-fail-linux-kernel-flaw-enabling-root-takeover-across-major-distros-unpatched-systems-may-remain-vulnerable-to-attack?utm_source=openai)) The rapid public disclosure and the availability of a reliable proof-of-concept exploit have heightened concerns, especially in cloud and multi-tenant environments where untrusted code execution is common. Organizations are urged to apply patches promptly and consider temporary mitigations, such as disabling the affected cryptographic modules, to protect against potential exploitation. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/05/01/cve-2026-31431-copy-fail-vulnerability-enables-linux-root-privilege-escalation/?utm_source=openai))
4 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports