The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Banking/Mortgage
Breach intelligence, attack campaigns, and threat reports targeting the Banking/Mortgage sector.
Explore Other Sectors
Banking/Mortgage Threat Reports
Cosmos EVM Vulnerability: How Poor Disclosure Processes Led to $5.7M in Losses
Between August 20-25, 2026, attackers exploited a critical balance-handling flaw (GHSA-7g4w-cg88-2cq2) in the Cosmos EVM module to drain funds from six blockchains, stealing approximately $5.72 million. The vulnerability was initially reported through Cosmos Labs' bug bounty program on April 25, 2026, but was incorrectly assessed as posing no risk to live networks. By August 13, Cosmos Labs confirmed all Cosmos EVM chains were affected regardless of decimal configuration, yet proceeded with a public silent patch process instead of private distribution to affected networks. The flaw allowed attackers to manipulate vesting account balances through unchecked arithmetic operations, causing balance wrapping to approximately 2^256 and enabling unauthorized fund drainage. This incident highlights critical gaps in vulnerability disclosure processes and supply chain security management, particularly relevant as blockchain infrastructure becomes increasingly interconnected and organizations struggle with coordinated security updates across distributed networks.
- Banking/Mortgage
- Capital Markets/Hedge Fund/Private Equity
- Investment Management/Hedge Fund/Private Equity
3 weeks ago
Kill Chain
AI-Powered HTTP Terminator Unleashes Novel Desync Attacks on Financial Websites
In 2026, security researcher James Kettle from PortSwigger developed HTTP Terminator, an AI-powered open source tool that autonomously discovers novel HTTP request smuggling vulnerabilities. The tool successfully identified and exploited previously unknown desync attack vectors against live enterprise websites, including multiple financial services companies. HTTP Terminator operates by analyzing successful exploits to inspire new attack techniques, creating a self-improving feedback loop that enhances its discovery capabilities over time. This research demonstrates AI's capability to conduct genuinely novel security research beyond simple vulnerability detection, marking a significant evolution in autonomous threat discovery. As AI-driven attack tools become more sophisticated and accessible through open source releases, organizations face an accelerated threat landscape where traditional defensive measures may struggle to keep pace with machine-generated exploit techniques.
4 weeks ago
Kill Chain
Dark Caracal's GoCaracal Malware Pioneers Ethereum Smart Contract C2 Infrastructure
In June 2026, threat actors linked to Dark Caracal deployed GoCaracal, a previously undocumented Go-based malware framework, against a Venezuelan communications organization. Arctic Wolf discovered this sophisticated malware uses Ethereum smart contracts as a fallback mechanism to retrieve replacement command-and-control (C2) server addresses when primary servers fail. GoCaracal provides remote shell access, payload execution, browser data theft, keylogging, and remote desktop control capabilities, delivered through phishing campaigns using malicious SVG files. This incident demonstrates the evolution of C2 resilience mechanisms as threat actors adapt to increased infrastructure takedowns and incorporate blockchain technology for operational persistence, highlighting the need for comprehensive egress filtering and behavioral anomaly detection.
4 weeks ago
Kill Chain
Polymorphic Phishing: When Advanced Evasion Techniques Backfire
In August 2024, cybersecurity researchers identified a sophisticated polymorphic phishing campaign that generates unique variants of credential-stealing pages for each visitor. The attack uses heavily obfuscated JavaScript with randomized function names, variable declarations, and page elements to evade detection systems that rely on static signatures. However, the polymorphic generation mechanism contains coding flaws that occasionally produce non-functional pages due to improper variable scope handling, causing infinite loops that prevent successful credential harvesting. Analysis of 50 page samples revealed a 4% failure rate where broken variants would consume 100% CPU utilization instead of displaying the phishing form. This incident highlights the evolving sophistication of phishing operations and the double-edged nature of advanced evasion techniques. As threat actors increasingly adopt polymorphic methods to bypass security controls, organizations must move beyond signature-based detection to behavioral analysis and real-time inspection capabilities.
4 weeks ago
Kill Chain
North Korean APT Group Exploits AI Development Supply Chain in Sophisticated Campaign
In July 2026, Amazon's threat intelligence team identified a North Korean state-sponsored hacker group behind multiple open-source supply chain attacks targeting NPM packages including axios, debug, chalk, and typo-crypto. The DPRK-linked threat actor demonstrated evolved tradecraft leveraging generative AI to enhance their attack methodologies. Simultaneously, AWS published 21 security bulletins addressing critical vulnerabilities across open-source SDKs, MCP servers, and developer tools, with key themes including credential disclosure, SSRF attacks, command injection, and insufficient input validation in AI-integrated workflows. This incident highlights the growing sophistication of nation-state actors exploiting the software supply chain, particularly as organizations rapidly adopt AI-powered development tools and agent-based workflows that expand the attack surface through LLM integrations.
1 month ago
Kill Chain
How Interpol's Jackal IV Exposed the Hidden Infrastructure Behind Global Cybercrime
Interpol's Operation Jackal IV concluded in August 2026 as a coordinated international law enforcement effort targeting West African cybercrime syndicates across 22 countries. The operation resulted in 58 arrests and identification of 263 additional suspects, focusing particularly on Black Axe and similar transnational organized crime networks responsible for business email compromise, romance scams, and cryptocurrency fraud. Unlike previous operations, Jackal IV emphasized intelligence gathering and infrastructure disruption over arrest numbers, targeting crime-as-a-service networks that provide domains and money laundering support to cybercriminal groups. Authorities seized $3.8 million in assets across Argentina, South Africa, Romania, and Italy, dismantling call center operations and shell company networks. This operation highlights the evolving sophistication of West African cybercrime infrastructure and the increasing reliance on specialized service providers. The emphasis on disrupting criminal support networks rather than individual operators reflects law enforcement's strategic shift toward degrading entire criminal ecosystems that enable large-scale cyber-enabled financial fraud.
1 month ago
Kill Chain
INTERPOL's Massive West African Cybercrime Takedown: What Operation Jackal IV Reveals About Modern Fraud Networks
INTERPOL's eight-month Operation Jackal IV resulted in 58 arrests and identification of 263 suspects across 22 countries, targeting West African organized crime groups including Black Axe. The operation disrupted romance scams, cryptocurrency fraud, business email compromise schemes, and money laundering networks that collectively stole over €988 million. Key raids included a South African syndicate targeting English-speaking retirees ($2.67 million seized, 257 accounts blocked) and a Romanian call center promising fake cryptocurrency returns (€143 million stolen globally, 11 arrests made). This latest crackdown represents the fourth iteration of Operation Jackal, demonstrating escalating international cooperation against West African cybercrime syndicates that have become increasingly sophisticated in their crime-as-a-service operations and cross-border financial fraud schemes. This incident highlights the growing threat of organized West African cybercrime groups that operate like legitimate businesses with specialized roles for conversion and retention agents, exploiting global financial systems through sophisticated social engineering and cryptocurrency laundering schemes.
1 month ago
Kill Chain
Operation Jackal IV Dismantles Global West African Cybercrime Networks
Between November 2025 and June 2026, Operation Jackal IV, a coordinated international law enforcement effort spanning 22 countries, resulted in 58 arrests and identification of 263 suspects linked to West African cybercrime networks, particularly the Black Axe syndicate. The operation targeted sophisticated Crime-as-a-Service networks that facilitated romance scams, cryptocurrency fraud, business email compromise, and sextortion schemes targeting victims globally. Authorities seized $2.67 million, blocked 257 bank accounts, and dismantled infrastructure supporting money laundering operations across Argentina, South Africa, Romania, and Italy. This crackdown highlights the growing sophistication of African organized crime groups who increasingly leverage dark web services and international networks to scale their operations, making cross-border collaboration essential for effective cybercrime prevention.
1 month ago
Kill Chain
WordlistLoader: The Steganographic Malware Hiding in Plain English
In August 2026, Gen Threat Labs discovered WordlistLoader, a sophisticated malware loader that uses plain English word lists to disguise and reconstruct malicious code for the Amatera infostealer. The loader operates by mapping 256 ordinary English words to byte values, allowing it to rebuild shellcode while evading detection systems. WordlistLoader is distributed through ClearFake campaigns using ClickFix-style social engineering tactics targeting Windows machines. The malware includes advanced evasion techniques including security hook bypassing, Event Tracing for Windows bypass, and anti-analysis capabilities before delivering the Amatera payload. This incident reflects the growing sophistication of malware evasion techniques as threat actors adapt to improved security detection capabilities. The use of natural language obfuscation represents a significant evolution in steganographic malware delivery methods, making traditional signature-based detection increasingly ineffective against polymorphic loaders.
1 month ago
Kill Chain
Provenance Blockchain State Divergence: $500K DeFi Vulnerability Analysis
In March 2026, Trail of Bits discovered a critical vulnerability in Provenance Blockchain, a Cosmos SDK-based financial services platform, that allowed any user to grant themselves admin control over marker accounts without holding tokens. The bug affected 82 markers representing live financial assets worth approximately $500,000, including validator incentive funds and community grant programs. Exploitation required only two transactions: one to gain admin permissions through a flawed authorization check, and another to either mint new tokens or drain escrowed assets. This incident highlights the growing risks in blockchain application security as DeFi and tokenized assets become mainstream. State synchronization vulnerabilities in smart contract platforms represent a critical attack vector that can bypass traditional access controls.
1 month ago
Kill Chain
How Interpol's Operation Jackal IV Exposed Global Cybercrime Infrastructure
Operation Jackal IV, an international law enforcement operation coordinated by Interpol, resulted in 58 arrests and identification of 263 suspects across multiple countries, targeting West African organized crime groups including Black Axe. The operation disrupted extensive money laundering networks, business email compromise schemes, and romance scams that generated hundreds of millions in criminal proceeds. Authorities seized $2.67 million in cash, blocked 257 bank accounts, and uncovered a 143 million euro investment fraud operation, demonstrating the global reach and sophisticated financial infrastructure of these cybercriminal syndicates. This incident highlights the evolving threat landscape where traditional organized crime groups increasingly leverage digital platforms and cryptocurrencies to scale their operations globally, requiring enhanced international cooperation and advanced financial crime detection capabilities to combat their sophisticated money laundering networks.
1 month ago
Kill Chain
ToxicPanda 2.0: When Banking Trojans Become Enterprise Identity Threats
ToxicPanda 2.0, an evolved Android banking Trojan, has expanded from targeting 16 financial institutions to 349 banking, e-wallet, and cryptocurrency applications across 16 countries. The malware leverages Android's Wireless Debugging and ADB capabilities to achieve shell-level access and persistent device compromise. Beyond traditional banking fraud, the Trojan now captures lock-screen credentials and establishes enterprise-grade persistence, creating risks for corporate identity systems and authentication frameworks. This incident highlights the maturation of mobile banking Trojans from simple financial theft tools to comprehensive enterprise threats capable of compromising corporate identity anchors and multi-factor authentication systems.
1 month ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports