The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Banking/Mortgage
Breach intelligence, attack campaigns, and threat reports targeting the Banking/Mortgage sector.
Explore Other Sectors
Banking/Mortgage Threat Reports
Google Patches Actively Exploited Android Zero-Day CVE-2026-58704 on Pixel Devices
In September 2026, Google addressed CVE-2026-58704, a high-severity zero-day vulnerability in Android Pixel devices that was actively exploited in targeted attacks. The flaw stems from improper authorization and protection mechanism failures in the Modem subcomponent, allowing attackers with adjacent network access to escalate privileges without user interaction. Google's security update patched this vulnerability along with 109 other security issues, including 12 remote code execution and 89 privilege escalation flaws rated critical or high severity. This incident highlights the growing sophistication of mobile device attacks and the critical importance of rapid patch deployment in enterprise environments where mobile devices access corporate networks and sensitive data.
1 week ago
Kill Chain
KREMLIN Banking Malware Exposes Critical Browser Security Gaps
The KREMLIN banking malware operation, active since mid-2025, has been deploying sophisticated techniques to bypass browser security mechanisms and forcibly install malicious Chrome and Edge extensions. The Brazilian-based threat actors use JavaScript files disguised as legitimate business documents to initiate infections, which then utilize Node.js persistence, Ethereum smart contracts for C2 communication, and advanced browser manipulation techniques. The malicious extensions, masquerading as AVSync, steal credentials, session tokens, and sensitive data while bypassing Chromium's integrity checks through cryptographic key manipulation. Elastic Security Labs confirmed 1,515 infected systems, primarily in Brazil, with the operation generating approximately $20,800 in cryptocurrency transactions. This campaign represents a significant evolution in banking malware tactics, demonstrating how threat actors are adapting to modern browser security controls while maintaining stealth and persistence across enterprise environments.
1 week ago
Kill Chain
Black Axe Cybercrime Leaders Face US Charges: The Evolution of Romance Scam Operations
Five alleged leaders of the Black Axe cybercrime syndicate were extradited from South Africa to the United States in September 2026 to face wire fraud and money laundering charges. The defendants orchestrated a decade-long internet fraud campaign from 2011 to 2021, using romance scams and advance fee schemes to defraud victims across multiple platforms including social media and dating websites. The operation involved sophisticated social engineering tactics, including threats of publishing compromising materials when victims refused to send money. This case highlights the increasing international cooperation in cybercrime prosecution and the growing threat of transnational organized crime groups leveraging digital platforms for financial fraud at unprecedented scale.
1 week ago
Kill Chain
KREMLIN Banking Malware: How Brazilian Cybercriminals Weaponize Browser Extensions
The KREMLIN banking malware operation, tracked as REF9334, has been targeting Brazilian financial institutions since May 2025 through sophisticated browser hijacking techniques. The threat actors deploy malicious Chrome and Microsoft Edge extensions that bypass Chromium integrity mechanisms by manipulating Secure Preferences files and regenerating required HMACs. The operation leverages Ethereum smart contracts as dead drop resolvers to dynamically update command-and-control endpoints, making disruption extremely difficult. Over 1,515 infected systems have been identified, with 98% located in Brazil. This incident represents the growing sophistication of banking malware that exploits browser extension ecosystems and blockchain infrastructure for resilient operations. As financial institutions increasingly rely on web-based services and multi-factor authentication through browsers, attackers are adapting with advanced techniques that bypass traditional security controls.
1 week ago
Kill Chain
Tajin Group Exposed: Inside China's Sophisticated Guarantee Marketplace Cybercrime Network
Tajin Group, a Chinese-speaking cybercriminal organization, operates as a third-party vendor on Telegram-based guarantee marketplaces, conducting extensive phishing campaigns, payment card theft, and money laundering operations. The group has demonstrated sophisticated financial crime capabilities by testing payment cards from twelve countries on platforms like CCAvenue and Geidea, while maintaining operations across multiple guarantee marketplaces including Dabai and Xinbi. Their activities target Chinese citizens and banks, with the group depositing over 208,000 USDT as operational stakes, indicating large-scale criminal enterprise operations that pose significant risks to global financial institutions and payment processors. This incident highlights the evolving sophistication of Chinese-language cybercriminal ecosystems and their increasing use of guarantee marketplaces as force multipliers for coordinated financial crimes. The emergence of these organized criminal networks represents a growing threat to international banking systems and demonstrates the need for enhanced cross-border cybersecurity cooperation and financial transaction monitoring.
1 week ago
Kill Chain
BambooToken Malware Exploits MQTT Protocol in Global Multi-Platform Campaign
BambooToken is a sophisticated multi-platform malware campaign discovered in early 2026 that uses MQTT protocol for command and control across Windows and Linux systems. Active since February 2023, the threat actors exploit DLL sideloading techniques via Tendyron's OnKey authentication software to compromise organizations across Asia and South America. The malware demonstrates advanced evasion capabilities by leveraging legitimate PKI security tokens as attack vectors and using Cloudflare-proxied infrastructure to manage infections at scale. Researchers have identified compromised entities including mobile applications, financial organizations, hotels, and critical infrastructure systems across multiple countries. This incident highlights the evolving sophistication of threat actors who are increasingly adopting unconventional communication protocols and supply chain attack vectors to evade traditional security controls and maintain persistent access to high-value targets.
1 week ago
Kill Chain
Black Axe Cybercrime Leaders Extradited: International Crackdown on Romance Scam Network
Five alleged leaders of Black Axe's South African operations were extradited to the United States in December 2024 to face charges related to romance scams and advance fee fraud. The Nigerian nationals, including Cape Town zone founder Perry Osagiede, operated sophisticated financial fraud schemes from 2011-2021, using fake identities to manipulate victims into sending money through fabricated emergencies, business partnerships, and romantic relationships. The group leveraged business entities and compromised victim accounts to launder proceeds, with some cases involving extortion through threats to release sensitive photos. This extradition represents the latest phase of intensified global law enforcement action against Black Axe, a hierarchical cybercrime organization generating billions in annual criminal proceeds across dozens of countries. The coordinated international response demonstrates increasing capability to pursue transnational cybercriminals across jurisdictions and disrupt their financial networks.
1 week ago
Kill Chain
Revolut's 2026 Social Engineering Breach: When Trust Becomes a Vulnerability
In September 2026, fintech giant Revolut disclosed a targeted social engineering attack where threat actors impersonated a government agency to fraudulently obtain sensitive customer data. The attackers used valid domain authentication credentials to request personally identifiable information via email, successfully deceiving Revolut into sharing financial records, passport copies, transaction histories, and account details of high-net-worth customers. The company immediately blocked the fraudulent address and notified relevant authorities upon discovering the deception, though the exact number of affected customers remains undisclosed. This incident highlights the growing sophistication of social engineering attacks targeting financial institutions and the critical need for enhanced verification protocols when handling government data requests, particularly as threat actors increasingly exploit trusted communication channels to bypass security controls.
1 week ago
Kill Chain
DDRop Hardware Attack Compromises Intel and AMD Confidential Computing
Researchers from KU Leuven, ETH Zurich, Durham University, and Google disclosed the DDRop attack in September 2026, a hardware-based vulnerability that breaks memory protection in Intel TDX and AMD SEV-SNP confidential computing systems. The attack requires physical access to insert a $200 interposer device between the processor and memory module, which silently drops memory writes causing processors to read stale encrypted data. This allows attackers to gain full control of protected virtual machines, read victim memory, manipulate attestation measurements, and bypass confidential computing protections used by major cloud providers including AWS, Microsoft Azure, and Google Cloud. This attack demonstrates the growing sophistication of hardware-level threats targeting cloud infrastructure's foundational security mechanisms, highlighting critical gaps in confidential computing architectures as organizations increasingly rely on these technologies for sensitive workloads.
1 week ago
Kill Chain
How ShinyHunters Weaponized Claude AI to Harvest Secrets from 1.8 Million Android Apps
Between December 2025 and August 2026, multiple threat groups including ShinyHunters, Russian state-sponsored Midnight Blizzard, and Chinese espionage group GTG-10007 systematically abused Anthropic's Claude AI model for large-scale cyberattacks. The most significant operation involved ShinyHunters member 'frkoo' deploying an automated credential-harvesting pipeline across AWS infrastructure that extracted secrets from 1.8 million Android applications and compromised over 40 Microsoft corporate tenants within 34 hours. The AI-enhanced attacks enabled rapid progression from initial access to administrative control in under three hours, with confirmed breaches across government, healthcare, energy, and technology sectors. This incident represents a critical inflection point where AI capabilities are being weaponized at unprecedented scale and speed, fundamentally changing the threat landscape and requiring immediate reassessment of defensive strategies against AI-enhanced cybercrime operations.
1 week ago
Kill Chain
GoldFactory's Android Banking Malware Exploits Work Profiles to Steal $1M from Indonesian Banks
Between February and July 2026, the Chinese-speaking threat group GoldFactory deployed a sophisticated Android banking malware campaign targeting Indonesia, resulting in 1,469 compromised devices and nearly $1 million in losses. The attackers used the Gigabud banking Trojan in combination with Vwork, a modified app-cloning tool, to exploit Android's Work Profile feature. This technique allowed fraudsters to clone legitimate banking applications into isolated environments where security controls and fraud detection systems could not follow, enabling them to conduct transactions while evading detection mechanisms that were triggered in the victim's primary profile. This incident highlights the evolution of mobile banking threats as attackers increasingly target regions with high mobile payment adoption and develop novel evasion techniques that exploit legitimate enterprise security features for malicious purposes.
2 weeks ago
Kill Chain
Mantax Otax: The Android Threat That Encrypts, Steals, and Terrorizes Victims
Mantax Otax, a sophisticated Android malware strain discovered in September 2026, combines ransomware, spyware, and harassment capabilities to target Indonesian users through malicious APKs distributed outside Google Play. The malware uses accessibility services to gain extensive device control, encrypts files on older Android versions (9 and below) using victim-specific AES keys, and steals sensitive data including SMS messages, call logs, WhatsApp conversations, and real-time screen recordings. Beyond encryption and data theft, version 2 introduced psychological harassment features including jumpscare overlays, forced audio messages, and repeated dialog boxes to pressure victims into paying ransoms through Firebase-hosted chat negotiations. This incident highlights the growing trend of multi-vector mobile threats that combine financial extortion with psychological manipulation, demonstrating how threat actors are evolving beyond traditional ransomware to create more coercive attack campaigns targeting vulnerable mobile ecosystems in developing markets.
2 weeks ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports