The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Banking/Mortgage
Breach intelligence, attack campaigns, and threat reports targeting the Banking/Mortgage sector.
Explore Other Sectors
Banking/Mortgage Threat Reports
Gigabud Banking Trojan Weaponizes Android Work Profiles in Advanced Evasion Campaign
The Gigabud banking trojan has evolved its attack methodology by leveraging Android work profiles to evade detection by banking applications' security checks. Active since 2022 and attributed to the GoldFactory threat group, this remote access trojan now deploys a secondary app called Vwork that creates isolated work profiles on infected devices and installs tampered banking applications within them. By operating from within these separated environments, the trojan can conduct fraudulent transactions while remaining hidden from malware detection systems that scan the device's personal space. Group-IB confirmed active infections across Indonesia with estimated losses of $960,000 between February and July 2026, though the technique has been observed targeting multiple countries including Brazil, Colombia, Egypt, Mexico, and several Southeast Asian nations. This incident represents a significant evolution in mobile banking malware, demonstrating how threat actors are adapting legitimate Android enterprise features for malicious purposes. As organizations increasingly rely on mobile banking and BYOD policies, understanding these sophisticated evasion techniques becomes critical for developing effective mobile security strategies.
2 weeks ago
Kill Chain
Google Play Early Access Exploited: How Thousands of Deceptive Apps Bypassed Security
In September 2026, cybersecurity researchers discovered threat actors systematically abusing Google Play's Early Access program to distribute thousands of deceptive Android applications. These malicious apps promised financial rewards, casino winnings, and premium content while exploiting the program's feature that prevents user reviews and ratings. Notable examples included fake casino games and a Grand Theft Auto imitator called "Vice Streets: Open World" with over 1 million downloads. The attackers promoted these apps through social media platforms using AI-generated celebrity deepfakes, ultimately generating revenue through excessive advertising while never delivering promised payouts to users. This incident highlights the growing sophistication of mobile malware campaigns that exploit legitimate platform features to bypass traditional security mechanisms. The abuse of Early Access programs represents an emerging trend where attackers leverage regulatory gaps and user trust mechanisms to distribute deceptive applications at scale.
2 weeks ago
Kill Chain
Chrome Zero-Day CVE-2026-87491: The Seventh Browser Exploit of 2026
Google patched CVE-2026-87491, a high-severity zero-day vulnerability in Chrome's V8 JavaScript engine that attackers are actively exploiting in the wild. The out-of-bounds write flaw allows remote code execution through crafted HTML pages, enabling attackers to execute arbitrary code within Chrome's sandbox and potentially access sensitive data through heap corruption. This marks the seventh Chrome zero-day patched by Google in 2026, with the vulnerability discovered by a Seoul National University researcher and patches now rolling out globally across Windows, Mac, and Linux systems. The surge in Chrome zero-day exploits reflects the browser's critical role as an attack surface in modern threat landscapes, with nation-state actors and cybercriminals increasingly targeting browser engines to establish initial access for broader campaigns including espionage and ransomware deployment.
2 weeks ago
Kill Chain
How U.S. Authorities Dismantled a $30 Billion Romance Scam Empire
In September 2026, the U.S. Department of Justice dismantled Xinbi Guarantee, a Chinese-operated Telegram marketplace facilitating pig butchering romance scams and cryptocurrency money laundering. The coordinated operation seized Telegram channels, froze $52.8 million in cryptocurrency across 52 wallets, and disrupted 13 scam compounds in Madagascar operated by Chinese organized crime syndicates. Xinbi served as an escrow service connecting scammers with vendors offering fraudulent investment websites, money laundering services, and human trafficking for scam operations, processing approximately $30 billion in transactions since 2022. This disruption highlights the escalating threat of Southeast Asian scam centers that steal billions annually from American victims, with criminal organizations increasingly leveraging cryptocurrency and messaging platforms to operate sophisticated fraud-as-a-service ecosystems beyond traditional law enforcement reach.
2 weeks ago
Kill Chain
Chrome V8 Zero-Day Exploited in Wild: Critical Browser Security Implications for Enterprise
In September 2026, Google patched CVE-2026-87491, an actively exploited zero-day vulnerability in Chrome's V8 JavaScript engine that allowed remote code execution within the browser sandbox. The out-of-bounds write flaw enabled attackers to execute arbitrary code through crafted HTML pages, representing the seventh Chrome zero-day exploited in the wild during 2026. Google acknowledged active exploitation but withheld details about the attack methods and threat actors to protect users during the patch deployment phase. This incident highlights the persistent targeting of browser engines by sophisticated threat actors who continue developing novel exploitation techniques against widely-used platforms. The frequency of Chrome zero-days in 2026 demonstrates an escalation in browser-based attacks as threat actors adapt to improved endpoint security measures.
2 weeks ago
Kill Chain
Critical Alby Hub Vulnerability Exposed Bitcoin Wallets to Complete Takeover
In September 2026, Bitcoin wallet company Alby disclosed a critical vulnerability in Alby Hub versions v1.7.0 through v1.18.5 that allowed attackers to completely take over internet-exposed Lightning wallets and drain funds. The flaw affected self-hosted Bitcoin wallets where owners had inadvertently exposed their Hub management interfaces to the public internet, often following Alby's own documentation that recommended such configurations. At least one user was confirmed affected, with the company providing limited details about the vulnerability mechanism pending responsible disclosure. The incident highlights the ongoing security challenges in cryptocurrency infrastructure, particularly as Bitcoin adoption accelerates and self-custody solutions become more mainstream. With ransomware groups increasingly targeting cryptocurrency platforms and the rise of state-sponsored attacks on financial infrastructure, vulnerabilities in wallet software present critical risks to both individual users and the broader digital asset ecosystem.
2 weeks ago
Kill Chain
Russian National's $6.3M Bank Account Takeover Scheme Exposes Critical Security Gaps
In November 2023, Russian national Sergei Anatolyevich Filimonov orchestrated a sophisticated bank account takeover scheme that defrauded financial institutions of over $6.3 million. The operation involved creating spoofed banking domains, purchasing sponsored search links to redirect victims, and harvesting over 5,000 customer login credentials. The cybercriminals specifically targeted accounts with large balances, including those belonging to corporate employees in Georgia, and built infrastructure to bypass multi-factor authentication and other security controls. This case exemplifies the growing sophistication of financially motivated cybercriminals who combine social engineering, domain spoofing, and credential harvesting to target high-value accounts. The FBI's identification of $28 million in total attempted losses demonstrates the massive scale these operations can achieve.
2 weeks ago
Kill Chain
Slim Spider's Cloud-Native Attack on Brazilian Financial Infrastructure Exposes Critical Security Gaps
In March 2026, the Brazil-based threat actor Slim Spider executed a sophisticated multi-stage attack against a Brazilian financial institution, targeting cryptocurrency custody secrets and instant payment infrastructure. The attackers leveraged custom Bash scripts to steal temporary cloud credentials, enumerated secrets in cloud credential managers, and deployed backdoors mimicking legitimate infrastructure binaries. They successfully infiltrated managed Kubernetes clusters via Azure DevOps, deployed malicious pipelines, and created automated panels for bulk Pix payment fraud. The campaign resulted in the compromise of multiple Brazilian banks and fintech organizations, with devastating potential for cryptocurrency wallet theft and unauthorized financial transactions. This incident represents a critical shift in cybercrime tactics, as threat actors increasingly demonstrate sophisticated cloud-native attack capabilities specifically targeting high-value digital financial assets and instant payment systems across Latin America.
2 weeks ago
Kill Chain
Liquid Network Suffers $320M Bitcoin Theft Through Elements Software Vulnerability
In September 2026, unknown attackers claiming to be white hat hackers exploited a vulnerability in the Elements software powering Liquid Network's Bitcoin sidechain, withdrawing nearly 4,000 bitcoin worth approximately $320 million. The attackers used a bug in Elements to create unauthorized L-BTC tokens and then executed a peg-out transaction through SideSwap's authorization key, draining 95% of Liquid's bitcoin reserves. After communicating with Blockstream through encrypted messages embedded in Bitcoin transactions, the attackers returned 3,400 bitcoin but retained approximately 598.5 bitcoin worth $47 million. This incident highlights the growing sophistication of cryptocurrency protocol attacks and the blurred lines between legitimate security research and extortion in the DeFi ecosystem, particularly as Bitcoin layer-2 solutions become increasingly targeted by threat actors.
2 weeks ago
Kill Chain
ASCII Smuggling Phishing Campaign: How Invisible Unicode Characters Evaded Email Security in 2026
In February 2026, Microsoft identified a large-scale phishing campaign that peaked at 2.37 million daily messages, employing ASCII smuggling techniques with invisible Unicode characters to evade email security filters. Threat actors inserted Unicode characters from the Tags block (U+E0000–U+E007F) within finance-related keywords, splitting terms like 'funding' into 'fun[invisible character]ding' to bypass traditional word-based detection systems. The campaign utilized 148 finance-themed sender domains and leveraged legitimate ActiveCampaign email marketing infrastructure to deliver business funding and loan-themed lures. While Microsoft Defender caught over 99% of messages through other detection signals, the technique represents a significant evolution in phishing evasion tactics. This incident highlights the growing sophistication of social engineering attacks as threat actors adapt AI prompt injection techniques for traditional phishing campaigns, demonstrating how emerging attack vectors quickly cross over between different threat landscapes.
2 weeks ago
Kill Chain
Chrome Zero-Day CVE-2026-85046: Enterprise Defense Against Browser Exploitation
In September 2026, Google patched CVE-2026-85046, a high-severity type confusion vulnerability in Chrome's V8 JavaScript engine that was actively exploited in the wild. The zero-day flaw, discovered by security researcher Salvatore Gulizia, could be triggered through specially crafted HTML pages containing malicious JavaScript, potentially enabling remote code execution within Chrome's sandboxed renderer process. This marked the sixth actively exploited Chrome zero-day patched by Google in 2026, highlighting an escalating pattern of browser-based attacks targeting the widely-used V8 engine across multiple incidents throughout the year. This incident underscores the current surge in browser exploitation campaigns as attackers increasingly target client-side vulnerabilities to establish initial access, particularly through JavaScript engines that process untrusted web content at scale across millions of users daily.
2 weeks ago
Kill Chain
39 New Attack Methods Compromise Passkey Authentication Security
Security researchers have documented 39 distinct methods for compromising passkey authentication systems, revealing critical vulnerabilities in the infrastructure surrounding FIDO2 cryptography. These attack vectors include assertion mining, prompt flooding, credential interface deception, synced vault compromise, and malicious enrollment processes. While the core FIDO2 cryptography remains intact, attackers are successfully exploiting weaknesses in browsers, operating systems, cloud synchronization services, and user interfaces to bypass authentication controls. This research highlights the urgent need for enterprises to reassess their passwordless authentication strategies, as attackers are increasingly targeting the ecosystem around passkeys rather than the cryptographic protocols themselves.
2 weeks ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports