The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Banking/Mortgage
Breach intelligence, attack campaigns, and threat reports targeting the Banking/Mortgage sector.
Explore Other Sectors
Banking/Mortgage Threat Reports
ToxicPanda 2.0: The Android Banking Trojan That Hijacks VPN Permissions
ToxicPanda 2.0 Android malware emerged in August 2026 with sophisticated capabilities targeting 349 banking and financial applications across 16 countries. The malware exploits VPN service permissions to create local network interfaces that block Google Play communications, preventing security updates and Play Protect interference. It leverages Accessibility Services to automatically enable Wireless ADB debugging, gaining shell-level access to execute high-privilege commands and bypass Android security restrictions. The malware supports 167 remote commands and includes invisible phishing overlays that capture credentials and device PINs while maintaining persistence across major Android device manufacturers. Mobile banking trojans are experiencing a resurgence in 2026, with threat actors increasingly targeting VPN permissions and ADB abuse techniques to circumvent Google's enhanced security measures and maintain persistent access to compromised devices.
1 month ago
Kill Chain
Manic Android Malware Introduces Peer-to-Peer Data Exfiltration via Nearby Devices
The Manic Android malware, active since February 2026, represents a sophisticated mobile threat targeting banking, government, and cryptocurrency applications across Central and Western Europe, with primary focus on Ukraine. This malware employs transparent overlays to capture user inputs, leverages Android Accessibility services for comprehensive device control, and implements an innovative peer-to-peer data exfiltration mechanism using Wi-Fi Direct and Bluetooth connections through nearby infected devices. Manic can intercept SMS messages, capture lock PINs, monitor screens, collect location data, and provide remote access to operators via WebRTC sessions, targeting over 169 applications including banking, eID, payment, and authenticator apps. This incident highlights the evolving sophistication of mobile banking malware and the increasing threat to critical infrastructure applications, particularly government eID systems, as attackers develop novel exfiltration methods that bypass traditional network-based security controls.
1 month ago
Kill Chain
Grandoreiro Banking Trojan Returns: Advanced Evasion Campaign Targets Mexico
The Grandoreiro banking Trojan has resurfaced in a sophisticated campaign targeting users in Mexico, demonstrating significant operational evolution despite law enforcement disruption in 2024. Operators are leveraging DLL sideloading techniques and legitimate file-management applications to deliver the malware, with telemetry showing additional victims across North America and Europe. The campaign employs extensive anti-analysis and anti-forensics capabilities, including sandbox evasion checks for system uptime, application combinations, memory configurations, and nearly 50 security monitoring tools. This represents a deliberate shift toward separating initial access from long-term payload capabilities, indicating the malware's adaptation to modern security environments. This incident highlights the persistent threat of banking Trojans in Latin America and their continued evolution post-takedown, with Grandoreiro operators demonstrating enhanced stealth capabilities that challenge traditional detection mechanisms.
1 month ago
Kill Chain
Advanced Android Banking Malware: ToxicPanda 2.0 and GoldDigger Threaten Global Financial Security
ToxicPanda 2.0 represents a significant evolution in Android banking malware, expanding from targeting 16 banking applications to 349 financial institutions across 16 countries. The malware leverages Android accessibility services to steal UI elements, deploy overlay-based credential theft, and abuse Android Wireless Debugging for privilege escalation. Concurrently, GoldDigger banking trojan has launched massive infection campaigns in South Africa and the U.K., impersonating airline companies and retailers while performing sophisticated on-device fraud through real-time screen access and automated transaction manipulation. These incidents highlight the rapidly evolving landscape of mobile banking threats, where attackers are leveraging cloud infrastructure for distribution and implementing advanced evasion techniques. The shift toward on-device fraud capabilities and expanded targeting scope reflects the growing sophistication of mobile threat actors and their ability to adapt to modern security measures.
1 month ago
Kill Chain
Manic Malware Breaks the Air Gap: How Wi-Fi Mesh Networks Enable Data Theft from Offline Devices
The Manic Android malware campaign emerged in February 2026, targeting Ukrainian banks, government services, and Russian financial institutions through sophisticated phishing sites and dropper applications. This hybrid banking malware and spyware employs a novel Wi-Fi mesh technique that enables infected devices to relay stolen data through nearby compromised devices with internet access, allowing data exfiltration even when the primary device is offline. The malware monitors 169 package IDs across financial, government, and messaging applications, utilizing accessibility services abuse and transparent overlays to capture sensitive data including PIN codes, authentication credentials, and location information. This incident represents a significant evolution in mobile threats, demonstrating how attackers are adapting to air-gapped security measures and developing mesh-based exfiltration techniques. The campaign's timing amid ongoing geopolitical tensions and its focus on Ukrainian infrastructure highlights the intersection of cybercrime and nation-state activities, making mobile device security and network segmentation increasingly critical for organizational defense strategies.
1 month ago
Kill Chain
Zombie Card Attack Exposes Critical Flaw in Visa Contactless Payment Security
Researchers at the University of Massachusetts Amherst demonstrated a critical vulnerability in Visa contactless payment systems that allows attackers to revive expired credit cards for fraudulent transactions. The 'Zombie Card' attack exploits a cryptographic binding weakness in Visa's Kernel 3 EMV implementation, enabling attackers with physical access to expired cards and NFC relay equipment to modify expiration dates without breaking card cryptography. Testing across five major US banks showed one bank approved fraudulent transactions up to $500, while others either declined or failed the modification. The attack requires the original account to remain open and relies on issuers not independently verifying expiration dates during authorization, exposing fundamental flaws in contactless payment security architecture. This vulnerability highlights the growing sophistication of payment card fraud techniques as contactless transactions become mainstream, with researchers identifying similar NFC relay malware like WindRelay actively targeting victims across Europe, demonstrating that theoretical academic research quickly translates into real-world criminal exploitation.
1 month ago
Kill Chain
Arup's $25 Million Deepfake Scam: A Wake-Up Call for Cybersecurity
In January 2024, a finance employee at Arup's Hong Kong office received an email, purportedly from the company's UK-based CFO, requesting a confidential transaction. To verify, the employee joined a video conference with individuals appearing as the CFO and other senior colleagues. Convinced by the authenticity of the participants, the employee executed 15 wire transfers totaling approximately $25.6 million to designated bank accounts. Subsequent investigations revealed that the video call participants were AI-generated deepfakes, and the entire scenario was orchestrated by cybercriminals. This incident underscores the evolving sophistication of cyber threats, where attackers leverage advanced AI technologies to create highly convincing social engineering schemes. Organizations must recognize that traditional verification methods, such as visual and auditory confirmation, can be compromised. Implementing multi-factor authentication, establishing robust verification protocols, and educating employees about emerging threats are crucial steps in mitigating such risks.
1 month ago
Kill Chain
Operation CameraSwarm: Massive Compromise of Dahua Devices
Between June 17 and July 22, 2026, cybersecurity researchers at Hunt.io identified a campaign, dubbed Operation CameraSwarm, that compromised over 14,530 Dahua devices. Attackers employed credential attacks, exploited authentication-bypass vulnerabilities (CVE-2021-33044 and CVE-2021-33045), and utilized a peer-to-peer (P2P) relay technique to gain unauthorized access. The breaches were predominantly concentrated in Ukraine and Russia, with 1,923 cameras configured with persistent accounts and 283 accessed via the P2P method. This incident underscores the critical need for organizations to promptly apply security patches, disable unnecessary P2P features, and regularly update device firmware to mitigate potential vulnerabilities. ([labs.itresit.es](https://labs.itresit.es/2025/10/29/dahua-beyond-cve-2025-31702-p2p-relay-exposure/?utm_source=openai))
1 month ago
Kill Chain
Kimsuky's 2026 QR Code Phishing Campaign: A Wake-Up Call for Cybersecurity
In early 2026, the FBI issued a warning about a sophisticated spear-phishing campaign conducted by the North Korean state-sponsored group Kimsuky. This campaign, active since May 2025, involved embedding malicious QR codes in emails—a technique known as 'quishing'—to target U.S. government entities, think tanks, and academic institutions. When scanned, these QR codes redirected victims to fraudulent websites designed to harvest sensitive information or deploy malware. The attackers exploited the tendency of users to scan QR codes with personal mobile devices, which often lack the robust security measures of corporate systems, thereby bypassing traditional email security filters. ([techradar.com](https://www.techradar.com/pro/security/north-korean-hackers-using-malicious-qr-codes-in-spear-phishing-fbi-warns?utm_source=openai)) The prevalence of quishing attacks has surged dramatically, with Microsoft reporting a 146% increase in QR code phishing incidents in the first quarter of 2026. This rise underscores the evolving tactics of cybercriminals who are leveraging QR codes to circumvent conventional security defenses. Organizations are urged to enhance their security protocols, educate employees about the risks associated with scanning unsolicited QR codes, and implement comprehensive mobile device management solutions to mitigate this growing threat. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/04/30/email-threat-landscape-q1-2026-trends-and-insights/?utm_source=openai))
1 month ago
Kill Chain
WindRelay Malware: A New Threat to Contactless Payments
In August 2026, cybersecurity researchers identified 'WindRelay,' a novel Android malware that exploits Near Field Communication (NFC) technology to facilitate contactless payment fraud. The attack begins with social engineering tactics, where victims are deceived into installing a Remote Access Trojan (RAT) named SpyNote. This RAT enables attackers to remotely deploy the WindRelay malware onto the victim's device. Once installed, WindRelay transforms the compromised smartphone into an unauthorized NFC relay, capturing live card data when victims are manipulated into tapping their payment cards against their own infected devices. This data is then transmitted in real-time to fraudsters, who use it to perform unauthorized transactions at payment terminals. The campaign has primarily targeted individuals in Czechia, Slovakia, and Slovenia, with at least 23 samples of WindRelay identified between November 2025 and July 2026. This incident underscores a significant evolution in mobile payment fraud, combining advanced malware capabilities with sophisticated social engineering to exploit NFC technology. The emergence of WindRelay highlights the increasing sophistication of cybercriminals in leveraging mobile technologies for financial fraud. As NFC-based payment systems become more prevalent, the risk of similar attacks is likely to rise, emphasizing the need for enhanced security measures and user awareness to mitigate such threats.
1 month ago
Kill Chain
AmnesiaStealer: A New Threat to macOS Security
In August 2026, cybersecurity researchers identified AmnesiaStealer, a sophisticated Rust-based malware targeting macOS systems. Distributed via counterfeit GitHub pages, it employs a multi-stage attack to harvest sensitive data, including Keychain credentials, browser information, and files from applications like Apple Notes and Telegram. Notably, it hijacks Chromium-based browsers, granting attackers live control over user sessions. The malware's deployment involves deceptive prompts to capture system passwords, enabling deep system access and data exfiltration. This incident underscores a growing trend of advanced malware targeting macOS platforms, exploiting user trust through social engineering tactics. The emergence of such threats highlights the necessity for enhanced security measures and user awareness to mitigate risks associated with sophisticated information stealers.
1 month ago
Kill Chain
Ukraine's Crackdown on 94 Fraudulent Call Centers in 2026
In August 2026, Ukrainian authorities conducted a large-scale operation resulting in the shutdown of 94 fraudulent call centers across the country. These centers engaged in various schemes, including posing as bank officials to extract sensitive financial information and luring victims into fake investment platforms. The coordinated effort involved 411 searches and led to the seizure of significant assets, including $2 million in cash, 64,000 euros, and 1 kilogram of gold. Additionally, 26 individuals were formally identified as suspects in connection with these fraudulent activities. This incident underscores a growing trend of sophisticated social engineering attacks targeting individuals and organizations. The scale and coordination of these fraudulent operations highlight the urgent need for enhanced cybersecurity measures and public awareness to combat such threats effectively.
1 month ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports