✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Capital Markets/Hedge Fund/Private Equity
Breach intelligence, attack campaigns, and threat reports targeting the Capital Markets/Hedge Fund/Private Equity sector.
Explore Other Sectors
Capital Markets/Hedge Fund/Private Equity Threat Reports
UAC-0050's Expansion: European Financial Institution Targeted with RMS Malware
In February 2026, the Russia-aligned threat actor UAC-0050, also known as Mercenary Akula, targeted a European financial institution involved in regional development and reconstruction initiatives. The attack began with a spear-phishing email that spoofed a Ukrainian judicial domain, directing the recipient—a senior legal and policy advisor—to download a malicious archive file. This file initiated a multi-layered infection chain, ultimately deploying the Remote Manipulator System (RMS), a legitimate remote desktop software, granting the attackers persistent and stealthy access to the victim's system. This incident underscores a significant shift in UAC-0050's operations, expanding their focus beyond Ukraine to entities supporting the nation. The use of legitimate remote access tools like RMS highlights the evolving tactics of threat actors to evade detection. Organizations, especially those involved in sensitive geopolitical areas, must remain vigilant against such sophisticated social engineering attacks.
5 months ago
Kill Chain
OpenClaw 2026: Malicious Skills Distribute Password-Stealing Malware
Between January 27 and February 1, 2026, over 230 malicious 'skills' were uploaded to OpenClaw's official registry and GitHub repositories. These skills, masquerading as legitimate utilities, contained malware designed to steal sensitive information such as API keys, wallet private keys, SSH credentials, and browser passwords. The attackers exploited OpenClaw's plugin system to distribute these malicious packages, leading to significant data breaches for users who installed them. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/malicious-moltbot-skills-used-to-push-password-stealing-malware/?utm_source=openai)) This incident underscores the growing trend of supply chain attacks targeting open-source platforms. The ease of publishing and distributing plugins or extensions in such ecosystems presents a lucrative vector for cybercriminals. Organizations must exercise heightened vigilance when integrating third-party tools, ensuring thorough vetting processes to mitigate potential security risks.
5 months ago
Kill Chain
OpenClaw's ClawHub Compromised: A 2026 Supply Chain Attack
In early 2026, security researchers uncovered a significant supply chain attack within the ClawHub marketplace, a platform for OpenClaw AI assistant extensions. Over 340 malicious 'skills' were identified, many masquerading as cryptocurrency tools, which, upon installation, executed obfuscated commands leading to the deployment of the Atomic macOS Stealer (AMOS) malware. This malware targeted sensitive user data, including browser information and cryptocurrency wallets, affecting both Windows and macOS users. The incident underscores the vulnerabilities in open-source ecosystems and the critical need for rigorous vetting of third-party extensions. The proliferation of such attacks highlights the evolving tactics of cybercriminals, emphasizing the importance of user vigilance and the implementation of robust security measures to protect against sophisticated social engineering and malware distribution strategies.
5 months ago
Kill Chain
CIRO 2023 Data Breach Exposes Sensitive Data of 750,000 Canadian Investors
In late 2023, the Canadian Investment Regulatory Organization (CIRO) disclosed that a cyberattack compromised the personal and financial data of approximately 750,000 Canadian investors. The breach, involving unauthorized access to sensitive investor information, stemmed from an attack on a third-party IT provider responsible for maintaining the data. The breach's detection and subsequent investigation prompted CIRO to initiate notification procedures with impacted individuals and regulatory bodies. The incident highlighted critical weaknesses in third-party vendor security, raising concerns about the protection of confidential financial data within the regulated investment sector. This event is particularly relevant as it underscores a growing trend of attacks targeting regulatory and financial organizations via supply chain vectors. With increasing regulatory scrutiny and heightened risks from third-party service providers, organizations face renewed pressure to modernize data protection strategies and enforce robust vendor risk management frameworks.
6 months ago
Kill Chain
Malicious Chrome Extension Breach Drains MEXC Crypto Accounts via API Key Theft
In January 2026, cybersecurity researchers uncovered a malicious Chrome extension called "MEXC API Automator" targeting users of the MEXC cryptocurrency exchange. Deployed via the Chrome Web Store, the extension masqueraded as a legitimate trading tool to covertly generate new API keys on behalf of users, surreptitiously enabling withdrawal permissions. It then exfiltrated these sensitive credentials to a Telegram bot controlled by the attacker, granting potential full access to victims' MEXC accounts, including the ability to automate trades and drain balances. The campaign leveraged authenticated browser sessions, evading traditional credential protections, and tampered with the user interface to conceal its malicious activity. This incident highlights a sophisticated shift in attack vectors targeting API workflows and browser sessions, rather than direct password theft. It underscores urgent risks inherent in trusted browser extensions, particularly as infostealers increasingly exploit the digital supply chain and cryptographic asset platforms.
6 months ago
Kill Chain
Crypto Phishing 2026: How Chatbots and Telegra.ph Power Modern Scams
Between October 2025 and early 2026, a persistent cryptocurrency phishing campaign leveraged fake chatbot websites and phishing emails to target users, primarily using minimalist publishing platforms such as telegra.ph and Google Forms. The attackers distributed scam emails promising recipients substantial payouts in Bitcoin, directing them to malicious pages purporting to automate cryptocurrency mining profits. Victims were eventually asked to pay a fraudulent conversion fee to claim their non-existent funds, with payments funneled into wallets controlled by the attackers. The campaign’s simplicity and abuse of free digital services allowed it to evade basic filtering and reach a wide audience repeatedly. This incident highlights an ongoing rise in abuse of cloud-based publishing and forms services for elaborate phishing scams. Attackers are increasingly automating social engineering techniques, combining chatbots and “cash out” lures that have proven cost-effective and resilient even as major platforms improve traditional anti-phishing measures.
- Banking/Mortgage
- Capital Markets/Hedge Fund/Private Equity
- Investment Management/Hedge Fund/Private Equity
6 months ago
Kill Chain
SEC Uncovers $14M Crypto Scam Using Fake AI-Themed Investment Clubs
In late 2025, the U.S. Securities and Exchange Commission charged a network of fraudulent crypto trading platforms and investment clubs for orchestrating a $14 million scam targeting retail investors. The scammers operated platforms such as Morocoin Tech Corp., Berge Blockchain Technology Co., Ltd., and Cirkor Inc., as well as front groups like AI Wealth Inc. and others, leveraging social media ads and WhatsApp messages promising AI-driven trading tips. Victims were enticed to buy into phony 'Security Token Offerings' with guarantees of high returns, only to be tricked a second time by advance withdrawal fees before all funds were siphoned to overseas accounts, predominantly in Asia. This incident underscores the urgent risk of AI-wash fraud and the exploitation of digital messaging channels to build investor trust. As cryptocurrency scams grow more sophisticated and regulatory scrutiny intensifies, organizations and individuals should exercise heightened vigilance against elaborate schemes blending false credentials, social engineering, and AI-themed deception.
6 months ago
Kill Chain
LastPass 2022 Breach Fuels Years-Long Cryptocurrency Heists by Russian Actors
In 2022, LastPass suffered a significant data breach that enabled attackers to steal encrypted password vaults, exposing sensitive customer credentials, including cryptocurrency wallet keys and seed phrases. According to research by TRM Labs, Russian cybercriminals exploited weak master passwords over subsequent years, decrypting vaults offline and siphoning more than $35 million in digital assets as recently as late 2025. Stolen funds were laundered using advanced cryptocurrency mixing and routed through sanctioned Russian exchanges. The incident underscores a persistent threat model: stolen encrypted data can remain exploitable for years if password hygiene and vault security are neglected. The breach’s fallout continues to evolve, heightening urgency for organizations to reassess encryption, password management, and layered defense strategies.
6 months ago
Kill Chain
North Korea’s $2 Billion Crypto Heist: 2025’s Largest Nation-State Cyber Attack
In 2025, threat actors closely tied to North Korea orchestrated a record-breaking $2.02 billion in cryptocurrency thefts, representing over half of the global digital asset losses for the year. These attackers leveraged sophisticated intrusion techniques, advanced persistent threat (APT) operations, and exploited vulnerabilities in decentralized finance (DeFi) platforms and exchanges from January through early December. High-value thefts were often facilitated by exploiting weak internal controls, compromised credentials, and security gaps in cross-chain bridges, resulting in severe financial losses for both exchanges and their clients. This incident marks a significant escalation in nation-state cybercrime and highlights evolving attacker sophistication in targeting cryptocurrency infrastructure. It underscores escalating regulatory scrutiny and the necessity for organizations to bolster east-west traffic controls, threat detection, and zero trust architectures in response to persistent, financially-motivated adversaries.
6 months ago
Kill Chain
Malicious Chrome Extension Diverts Solana in Raydium Swaps: Supply Chain Breach 2024
In May 2024, researchers identified a malicious Chrome extension named 'Crypto Copilot' that was surreptitiously injecting unauthorized Solana (SOL) transfer instructions during Raydium swap transactions, redirecting user assets to an attacker-controlled wallet. Initially published on the Chrome Web Store by a developer under the alias 'sjclark76,' the extension posed as a crypto utility tool but covertly modified transaction data to exfiltrate funds without user knowledge. The breach highlighted the growing risk of supply-chain malware within browser ecosystems and exposed users to direct financial theft via manipulated decentralized finance (DeFi) operations. This incident exemplifies a broader trend of attackers leveraging browser extensions to exploit DeFi and cryptocurrency users at scale. With the proliferation of novel supply-chain vectors and the rise of open-source and web-based crypto tools, organizations and individuals must exercise heightened due diligence and implement robust extension vetting and monitoring practices.
6 months ago
Kill Chain
California Crypto Laundering: $230M Theft and Tracing the Mixers – 2024 Incident
In 2024, a California resident pleaded guilty to laundering over $25 million in cryptocurrency, part of a broader $230 million theft stemming from a major cyber heist targeting a cryptocurrency platform. The attacker leveraged sophisticated tactics to siphon digital assets and enlisted money-laundering services to funnel proceeds through a series of mixers, obscuring the criminal origins. Investigators traced the flows across multiple wallets and exchanges over several months—ultimately apprehending the facilitator in the U.S. This multi-jurisdictional operation illustrated both the scale of modern crypto theft and challenges in asset recovery for victims and exchanges. The case underscores the mounting trend of advanced laundering techniques following crypto thefts, as decentralized financial ecosystems and global regulatory gaps give threat actors new cover. Organizations handling digital assets face heightened pressure for compliance, zero trust, and full-spectrum monitoring.
6 months ago
Kill Chain
European Authorities Bust €600M Crypto Fraud Network in Pan-European Operation
In late October 2025, European authorities led by Europol and Eurojust dismantled a sophisticated cryptocurrency money laundering network responsible for stealing €600 million (around $688 million) through large-scale crypto fraud schemes. The coordinated operation spanned Cyprus, Spain, and Germany, resulting in the arrest of nine suspects linked to elaborate investment scams, phishing, and online fraud. The network leveraged complex cross-border laundering methods, making use of encrypted digital transactions and a web of services to obfuscate stolen funds, ultimately victimizing thousands of individuals across multiple nations. The case spotlights the emergence of organized crime groups exploiting cryptocurrency platforms for large-scale financial fraud and money laundering. It underscores the urgent need for robust regulatory frameworks and advanced monitoring tools, as law enforcement agencies worldwide face growing challenges combating tech-enabled fraud tied to the volatile, largely unregulated crypto sector.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports