Validated Containment Architectures are here. →Explore

Industry Category

Capital Markets/Hedge Fund/Private Equity

Breach intelligence, attack campaigns, and threat reports targeting the Capital Markets/Hedge Fund/Private Equity sector.

62 threat reports
Page 1 of 6

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Capital Markets/Hedge Fund/Private Equity Threat Reports

Showing 112 / 62 reports
New macOS Malware Campaign Drains Cryptocurrency Wallets via 'ClickFix' Attacks
Impact· MEDIUM

New macOS Malware Campaign Drains Cryptocurrency Wallets via 'ClickFix' Attacks

In August 2026, a sophisticated macOS malware campaign was identified, leveraging 'ClickFix' social engineering techniques to distribute a Go-based infostealer. This malware targets sensitive user data, including browser-stored passwords, Apple iCloud Keychain data, and cryptocurrency wallets. The attack initiates when users are deceived into executing a command in the Terminal, leading to the download of a shell script that profiles the system and fetches a Mach-O payload compatible with the device's architecture. The payload then exfiltrates the harvested data to a remote server controlled by the attackers. Notably, the malware includes a 'DRAIN' function capable of siphoning funds from various cryptocurrency wallets, such as Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and Ripple's XRP, by transferring a portion or the entirety of the funds to attacker-controlled accounts. The infrastructure supporting these malicious activities has been traced back to Aeza Group, a Russian bulletproof hosting provider previously sanctioned by the U.S., U.K., and Australia for facilitating cybercriminal operations. This incident underscores the evolving threat landscape targeting macOS users, highlighting the need for heightened vigilance against social engineering tactics and the importance of robust security measures to protect sensitive information and digital assets.

2 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
UNC6671's 2026 Cyberattacks on Hedge Funds: A Wake-Up Call
Impact· HIGH

UNC6671's 2026 Cyberattacks on Hedge Funds: A Wake-Up Call

In August 2026, a series of cyberattacks targeted prominent hedge funds and private-equity firms, including Point72 Asset Management, Millennium Management, Two Sigma Investments, and Citadel. The attackers, identified as UNC6671 and associated with the BlackFile group, employed sophisticated voice phishing (vishing) techniques to impersonate corporate IT helpdesks. By directing employees to fraudulent login pages, they captured credentials and session cookies, enabling unauthorized access to corporate systems. This breach led to significant data exfiltration and subsequent extortion attempts, with ransom demands reaching up to $3 million, though settlements often averaged around $750,000. This incident underscores a concerning trend in cyber threats, where attackers leverage social engineering to bypass traditional security measures. The financial sector's increasing reliance on cloud-based services and single sign-on (SSO) platforms presents new vulnerabilities, emphasizing the need for enhanced employee training and robust security protocols to mitigate such risks.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
ClickFix Campaign Deploys Go-Based Infostealer on macOS to Steal Cryptocurrency
Impact· HIGH

ClickFix Campaign Deploys Go-Based Infostealer on macOS to Steal Cryptocurrency

In August 2026, a sophisticated ClickFix campaign targeted macOS users, deploying a Go-based infostealer designed to exfiltrate sensitive data, including browser-stored passwords, Apple Keychain information, and cryptocurrency assets. The attack initiated through deceptive emails directing users to execute commands in the Terminal, leading to the download of a Bash script that gathered system information and retrieved a Mach-O payload tailored to the victim's processor architecture. The malware established persistence by masquerading as a legitimate macOS process and circumvented security alerts by removing quarantine attributes. Notably, it could intercept and modify cryptocurrency transactions, diverting a configurable percentage of funds to the attacker, affecting assets like Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and Ripple's XRP. This incident underscores the evolving threat landscape where attackers employ advanced social engineering techniques to bypass traditional security measures. The use of Go-based malware highlights a trend towards cross-platform capabilities, increasing the potential reach and impact of such attacks. Organizations must remain vigilant, educating users on the risks of executing unverified commands and enhancing endpoint detection mechanisms to identify and mitigate such sophisticated threats.

3 days ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Unitel Cyberattack Disrupts Services Ahead of IPO
Impact· HIGH

Unitel Cyberattack Disrupts Services Ahead of IPO

On July 28, 2026, Unitel, Angola's leading telecommunications provider, experienced a significant cyberattack targeting its technological infrastructure. Detected at approximately 2:20 AM local time, the attack disrupted voice, mobile data, and internet services nationwide, affecting over 21 million customers. The incident occurred just one day before Unitel's scheduled listing on the Angola Debt and Securities Exchange (BODIVA), following a public offering of a 15% stake in the company. In response, Unitel activated its response and containment mechanisms, mobilizing technical and cybersecurity teams to mitigate the effects and restore services. As of the latest reports, services remain affected, with ongoing efforts to fully stabilize and normalize the network. ([businessday.co.za](https://www.businessday.co.za/world/international-companies/2026-07-28-cyberattack-hits-angolas-unitel-a-day-before-its-listing/?utm_source=openai)) This incident underscores the escalating threat landscape facing critical infrastructure sectors, particularly telecommunications. The timing of the attack, coinciding with Unitel's IPO, highlights the potential for cyber adversaries to exploit significant corporate events. Organizations must prioritize robust cybersecurity measures and incident response strategies to safeguard against such disruptions, especially during pivotal business milestones.

4 days ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Coldcard Hardware Wallet Flaw Results in Massive Bitcoin Theft
Impact· CRITICAL

Coldcard Hardware Wallet Flaw Results in Massive Bitcoin Theft

In July 2026, a critical vulnerability in Coldcard hardware wallets led to the theft of approximately $70.2 million in Bitcoin. The flaw, introduced in a March 2021 firmware update, caused the devices to use a deterministic software pseudorandom number generator (PRNG) instead of the intended hardware random number generator (RNG) for seed generation. This oversight allowed attackers to predict wallet seeds by analyzing device-specific information and prior RNG states, enabling unauthorized access to funds. Coinkite, the manufacturer, released emergency firmware updates on July 31, 2026, but emphasized that updating the firmware does not secure existing seeds. Users were advised to generate new seeds using the patched firmware and transfer their assets accordingly. This incident underscores the critical importance of robust entropy sources in cryptographic systems and highlights the potential risks associated with firmware updates that inadvertently introduce vulnerabilities.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
DPRK-Linked macOS Malvertising Campaign Targets Cryptocurrency Users
Impact· HIGH

DPRK-Linked macOS Malvertising Campaign Targets Cryptocurrency Users

In July 2026, North Korean threat actors launched a sophisticated macOS malvertising campaign targeting cryptocurrency users. The attack involved redirecting victims to fake web pages that displayed full-screen, non-existent update sequences. These deceptive pages prompted users to execute malicious commands via the Terminal app, leading to the installation of malware designed to steal data from 157 cryptocurrency wallets and deploy a malicious Chrome extension. The campaign utilized blockchain-hosted command-and-control (C2) infrastructure, extracting live server addresses from Ethereum smart contracts, a technique known as EtherHiding. This approach enhances the malware's resilience against takedown efforts. This incident underscores the evolving tactics of state-sponsored cyber actors, particularly in leveraging advanced social engineering and blockchain technologies to target the cryptocurrency sector. The use of EtherHiding and sophisticated malvertising techniques highlights the need for heightened vigilance and robust security measures among macOS users and cryptocurrency stakeholders.

1 week ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
SourTrade Malvertising Campaign: A New Era of Browser-Based Threats
Impact· HIGH

SourTrade Malvertising Campaign: A New Era of Browser-Based Threats

In July 2026, a sophisticated malvertising campaign named SourTrade was identified, targeting retail traders and cryptocurrency investors across 12 countries. Active since late 2024, the attackers impersonated reputable platforms like TradingView, Solana, and Luno to lure victims. Instead of delivering a static malicious file, the campaign utilized the victims' browsers to assemble unique Windows executables in memory, leveraging a legitimate Bun runtime. This method effectively evaded traditional security detections by ensuring no complete malware existed on the network. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/malicious-sites-use-javascript-to-build-malware-in-browser-memory/?utm_source=openai)) The SourTrade operation underscores a significant evolution in malvertising tactics, highlighting the increasing sophistication of threat actors in circumventing security measures. This incident serves as a critical reminder for organizations to enhance their cybersecurity defenses, particularly against advanced browser-based threats. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/malicious-sites-use-javascript-to-build-malware-in-browser-memory/?utm_source=openai))

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
SourTrade Malvertising Campaign: A New Era of In-Browser Malware Assembly
Impact· HIGH

SourTrade Malvertising Campaign: A New Era of In-Browser Malware Assembly

In July 2026, a sophisticated malvertising campaign named 'SourTrade' was identified, targeting retail traders and cryptocurrency investors across 12 countries, primarily in the Asia-Pacific and Latin American regions. The attackers employed fake websites impersonating platforms like Solana, Luno, and TradingView, utilizing malicious JavaScript to assemble malware directly within the browser's memory. This method involved registering service workers and shared workers to incrementally build a unique malware payload for each session, effectively bypassing traditional static detection mechanisms. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/malicious-sites-use-javascript-to-build-malware-in-browser-memory/amp/?utm_source=openai)) The campaign's innovative approach underscores a growing trend among cybercriminals to exploit browser functionalities for malware delivery, making detection and analysis more challenging. This incident highlights the urgent need for enhanced security measures and user vigilance, especially within the cryptocurrency and financial sectors, to counteract evolving threats that leverage in-browser execution and memory-based payload assembly. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/malicious-sites-use-javascript-to-build-malware-in-browser-memory/amp/?utm_source=openai))

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Ostium's $23.75 Million Crypto Theft: A Wake-Up Call for DeFi Security
Impact· HIGH

Ostium's $23.75 Million Crypto Theft: A Wake-Up Call for DeFi Security

In July 2026, Ostium, a decentralized trading platform on the Arbitrum blockchain, suffered a significant security breach resulting in the theft of approximately $23.75 million from its liquidity provider vault. The attacker compromised off-chain infrastructure responsible for feeding price data into the protocol, submitting falsified price reports to artificially generate profits. This manipulation allowed the attacker to rapidly open and close large positions, effectively draining the vault. Notably, trader collateral held in separate contracts remained unaffected, and existing positions were preserved. This incident underscores the critical vulnerabilities associated with off-chain components in decentralized finance (DeFi) platforms. As DeFi continues to gain traction, the reliance on external data feeds presents a substantial risk vector. The Ostium breach highlights the urgent need for enhanced security measures and robust validation mechanisms to protect against similar exploits in the future.

2 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
US Charges Two Over $43 Million Investment Fraud Laundering
Impact· HIGH

US Charges Two Over $43 Million Investment Fraud Laundering

In July 2026, U.S. prosecutors charged Zhuoying Chen and Haojie Zhang, residents of New York, for orchestrating a sophisticated money laundering network between 2020 and 2022. The duo managed over a dozen individuals who opened approximately 140 bank accounts under 45 shell companies, facilitating the transfer of at least $43 million from cyber investment fraud victims to bank accounts in China. The fraudulent schemes involved contacting victims via social media, building trust, and persuading them to invest in fake opportunities, ultimately leading to significant financial losses. This case underscores the escalating threat of cyber-enabled financial fraud and the critical need for robust cybersecurity measures. With investment fraud accounting for 49% of all scam-related incidents in 2025, resulting in losses of $8.6 billion, organizations must prioritize the implementation of advanced security protocols to protect against such pervasive threats.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Silent Swap Crypto Clipper: A New Threat to Cryptocurrency Security
Impact· MEDIUM

Silent Swap Crypto Clipper: A New Threat to Cryptocurrency Security

In June 2026, cybersecurity researchers identified a malicious campaign named 'Silent Swap,' which targets cryptocurrency users through a fake 'Google Notes' browser extension. Delivered via unsigned .NET and Golang installers, this extension infiltrates Chromium-based browsers by modifying their settings to install itself without user consent. Once active, it monitors the system clipboard for cryptocurrency wallet addresses and replaces them with attacker-controlled addresses, leading to unauthorized fund transfers. The campaign employs advanced techniques like 'EtherHiding,' utilizing blockchain technology to dynamically update command-and-control servers, enhancing its resilience and evasion capabilities. This incident underscores a growing trend of sophisticated attacks leveraging trusted platforms and applications to distribute malware. The use of blockchain for command-and-control infrastructure highlights the evolving tactics of threat actors, making detection and mitigation more challenging. Organizations and individuals must remain vigilant, ensuring that browser extensions are sourced from reputable developers and regularly reviewing installed extensions for unauthorized additions.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
Crypto Heist Leveraging Fake Reputation Networks to Distribute Malware
Impact· MEDIUM

Crypto Heist Leveraging Fake Reputation Networks to Distribute Malware

In June 2026, cybercriminals orchestrated a sophisticated campaign to distribute a Rust-based clipboard hijacking malware targeting both Windows and macOS users. The attackers created a comprehensive fake reputation network, utilizing GitHub repositories, SourceForge projects, AI-generated YouTube videos, and manipulated VirusTotal comments to lend credibility to their malicious tools. These tools, masquerading as crypto trading and gambling aids, were designed to steal cryptocurrency by intercepting wallet addresses copied to the clipboard, affecting assets like Bitcoin, Ethereum, Monero, Binance Chain, and Solana. This incident underscores a significant evolution in cybercriminal tactics, highlighting their ability to exploit multiple trusted platforms to build false credibility and deceive users. The campaign's success demonstrates the urgent need for enhanced vigilance and skepticism towards online reputation signals, especially in the cryptocurrency domain, where the allure of quick profits can cloud judgment.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports