✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
European Authorities Dismantle Major Call Center Fraud Ring in Ukraine (2024)
In mid-2024, European law enforcement agencies succeeded in dismantling a major organized fraud ring operating out of Ukraine. This network used illicit call centers to impersonate financial institutions, manipulating victims across Europe—especially in Germany—into divulging sensitive information or making fraudulent investments. Through sophisticated social engineering techniques and well-structured scripts, the group defrauded thousands of individuals of over 10 million euros. The operation also seized electronic equipment and led to at least five arrests. This incident highlights the ongoing evolution of transnational cybercrime syndicates that exploit human vulnerability through social engineering. Call center fraud, often leveraging modern technologies and cross-border coordination, continues to surge even as regulatory and enforcement actions intensify across Europe.
6 months ago
Kill Chain
Hypervisors Under Fire: 2024 Ransomware Blitz Hits Virtualization Core
In early 2024, organizations across multiple sectors faced a wave of targeted ransomware attacks exploiting vulnerabilities in virtualization platforms' hypervisors. Threat actors used stolen administrative credentials and leveraged known and zero-day flaws in hypervisor management interfaces to bypass segmentation controls, moving laterally from corporate networks onto host environments. Once inside, attackers deployed ransomware payloads at the hypervisor level, simultaneously encrypting dozens of virtual machines and crippling key business operations for days or weeks. The impact included downtime cascading across critical workloads, increased ransom demands due to concentrated disruption, and challenges in restoring services due to the interlocked nature of virtualized systems. This incident spotlights the growing trend of ransomware groups shifting attacks from endpoint devices to virtualization infrastructure, exploiting weak visibility and east-west segmentation at the hypervisor layer. As businesses accelerate cloud and virtual adoption, the threat landscape is rapidly evolving, making hypervisor security an urgent priority for IT and security leaders.
6 months ago
Kill Chain
Fortinet 2024 Auth Bypass Exploited: Urgent Actions for Network Security
In early June 2024, threat actors actively exploited newly disclosed authentication bypass vulnerabilities in multiple Fortinet products, including FortiOS and FortiProxy. Attackers leveraged these flaws (notably CVE-2024-21762 and CVE-2024-23113) shortly after Fortinet's patch release, gaining unauthorized admin-level access to vulnerable devices. The intruders then extracted system configuration files, risking exposure of sensitive network data and credentials. Several organizations reported compromises and system disruptions, prompting urgent advisories from Fortinet and government agencies to patch immediately and review system integrity. This incident underscores a dangerous trend: rapid mass exploitation of zero-day vulnerabilities in network security devices. The high-profile breach highlights mounting risks to organizations that delay critical patching and demonstrates the persistent targeting of edge appliances by sophisticated attackers.
6 months ago
Kill Chain
GhostPoster: Malicious Firefox Addon Logos Expose Supply Chain Security Risks
In early 2024, a supply chain attack campaign known as 'GhostPoster' was uncovered targeting users of malicious Firefox browser extensions. Threat actors embedded obfuscated JavaScript payloads within the image logos of these add-ons, leveraging steganography to evade detection and distribute malware. Once installed, the trojanized extensions—with more than 50,000 downloads—granted actors persistent access to victims' browsers, allowing for activity monitoring and enabling backdoor capabilities. The campaign exploited the trust in official browser markets while circumventing traditional security measures. This breach illustrates the rising sophistication of supply chain attacks, particularly those leveraging legitimate software distribution channels. It highlights the necessity for stronger internal and external vetting of browser add-ons, as the technique is being replicated across other software ecosystems.
6 months ago
Kill Chain
APT Groups Leverage React2Shell to Plant Linux Backdoors in 2025
In December 2025, security researchers from Palo Alto Networks Unit 42 and NTT Security discovered active exploitation of the React2Shell vulnerability targeting Linux environments worldwide. The attackers leveraged this flaw in unpatched systems to deploy advanced remote access tools such as KSwapDoor and ZnDoor. These malware families provided persistent backdoor access, enabling lateral movement and data exfiltration. The campaign was characterized by sophisticated evasion techniques, stealthy command-and-control channels, and targeted critical infrastructure, raising the risk of operational disruption and regulatory exposure for affected organizations. The exploitation of React2Shell reflects a broader surge in advanced persistent threat (APT) activity focused on Linux workloads, with threat actors increasingly targeting vulnerabilities in remote access and open-source software. This trend underscores the urgent need for enhanced east-west traffic security, rapid patching, and anomaly detection to prevent organizational compromise.
6 months ago
Kill Chain
Active Attack: Fortinet FortiGate SAML SSO Authentication Bypass Exposes Networks
In December 2025, threat actors began exploiting two critical authentication bypass vulnerabilities (CVE-2025-59718 and CVE-2025-59719, both CVSS 9.8) in Fortinet FortiGate appliances. By targeting the FortiCloud SSO feature—enabled during FortiCare registration—they leveraged crafted SAML messages to gain unauthorized access to admin accounts. Once inside, attackers exported device configuration files, risking credential compromise and broader network infiltration. The U.S. CISA quickly classified the flaws as Known Exploited Vulnerabilities, urging immediate patching. This incident demonstrates the evolving risk of identity-driven network attacks and rapid exploitation following vulnerability disclosure. With opportunistic threat actors targeting edge infrastructure, similar authentication-based attacks are likely to increase, further incentivized by regulatory and industry pressure for swift vulnerability management.
6 months ago
Kill Chain
Cellik Android Malware: The New Frontier for Trojanized Google Play Apps
In December 2025, cybersecurity researchers identified a new Android malware-as-a-service (MaaS) dubbed Cellik that enables cybercriminals to create malicious variants of popular Google Play Store apps. Distributed via underground forums, Cellik’s service allows threat actors to select legitimate apps, inject sophisticated malware, and maintain original app functionality, thereby bypassing typical user suspicion and potentially evading Google Play Protect. Cellik's features include real-time screen streaming, notification interception, filesystem browsing, data exfiltration, device wiping, and encrypted command-and-control communications. Attackers can also overlay fake login screens, inject malicious payloads into trusted apps, and exploit a hidden browser to steal credentials using stored cookies from infected devices. The emergence of Cellik signals an evolution in Android threat tooling, where MaaS kits empower less skilled actors to launch advanced attacks. This development heightens risks for organizations subject to mobile threats as attackers embrace more modular and evasive tactics, underlining the urgent need for advanced mobile security controls and proactive user education.
6 months ago
Kill Chain
Turkey Hit by Advancing Android Banking Trojan: Inside the Frogblight Campaign
In August 2025, researchers identified a sophisticated Android banking Trojan dubbed "Frogblight" targeting users in Turkey. Distributed primarily through smishing campaigns and phishing sites masquerading as official government portals, Frogblight lured victims by posing as legitimate court case or Chrome browser apps. Once installed, it harvested banking credentials, SMS, contact lists, call logs, and device data, while providing remote device control and persistence mechanisms for operators. The malware communicated via REST API and later WebSockets to exfiltrate stolen data to attacker-controlled C2 servers and was frequently updated with new spyware features, indicating ongoing development and potential adoption as Malware-as-a-Service (MaaS). Frogblight exemplifies the rapid evolution and increasing capabilities of mobile banking malware. The campaign underscores the rising threat to mobile users—particularly in markets where banks and government digital services are trusted attack vectors—and reflects a broader trend toward commoditized MaaS offerings and advanced evasion techniques. Effective mobile security controls and user awareness remain critical as adversaries refine their payloads.
6 months ago
Kill Chain
Inside the 2025 KPop Malware Hunter Takedowns: Exposing Cloud Attack Trends
In 2025, a coordinated intelligence operation led by an international alliance of cybersecurity researchers, dubbed the KPop Malware Hunters, dismantled several prolific malware campaigns targeting global cloud and data center environments. Threat actors, including the group Salt Typhoon, exploited east-west traffic routes and unencrypted data in transit to achieve lateral movement post-compromise. Using advanced encrypted traffic analytics and inline IPS, defenders identified high-volume command-and-control exchanges masked within routine inter-region traffic. The operation led to significant disruption of adversary infrastructure, restoration of business operations, and improved threat visibility for impacted organizations worldwide. This takedown is highly relevant amid heightened attacks on hybrid and multicloud architectures, where sophisticated adversaries increasingly exploit internal cloud pathways and vulnerable segmentation. 2025’s events spotlight the urgent need for zero trust, inline threat detection, and rigorous compliance alignment as attackers leverage AI-driven evasion and cloud-native persistence.
6 months ago
Kill Chain
Compromised IAM Credentials Fuel AWS Cryptomining Attack in 2025
In November 2025, Amazon Web Services (AWS) became the target of a widespread cryptomining campaign exploiting compromised Identity and Access Management (IAM) credentials. The attackers used stolen keys to access AWS accounts, deploy cryptomining operations, and leverage persistence mechanisms to avoid detection and maintain access. Amazon’s GuardDuty threat detection tools were instrumental in uncovering the activity, which leveraged novel Tactics, Techniques, and Procedures (TTPs) including lateral movement and privilege escalation, putting customer cloud resources and budgets at risk through accelerated resource consumption and possible data exposure. This incident is emblematic of an escalating trend where threat actors exploit cloud identity weaknesses for financial gain. It underscores the urgent necessity for robust multi-factor authentication, real-time anomaly detection, and comprehensive cloud security strategies as identity-driven attacks proliferate in the cloud era.
6 months ago
Kill Chain
Rogue NuGet Impersonates Tracer.Fody, Orchestrates Multi-Year Crypto Wallet Theft
Between February 2020 and December 2025, a malicious NuGet package named "Tracer.Fody.NLog" posed as the legitimate .NET tracing library, Tracer.Fody, and was covertly distributed via typosquatting and mimicking developer identities. The package, uploaded by a threat actor under the handle "csnemess," evaded detection for almost six years, collecting over 2,000 downloads. Instead of offering legitimate functionality, this package deployed a wallet stealer: scanning the default Stratis wallet directory on Windows systems, exfiltrating wallet data and passwords to threat actor infrastructure hosted in Russia, with attackers leveraging crafted code and hidden routines to bypass superficial code reviews. The prolonged success of this attack underscores the persistent risk supply chain threats pose to open-source ecosystems, especially for developer tools and libraries. It highlights attackers’ sophistication in mimicking trusted maintainers, the difficulty of detecting such manipulation, and ongoing regulatory and security pressures to improve package repository hygiene and detection.
6 months ago
Kill Chain
CISA Flags Fortinet CVE-2025-59718: Improper Signature Verification Under Active Exploitation
In December 2025, CISA added CVE-2025-59718 to its Known Exploited Vulnerabilities catalog, citing confirmed active exploitation targeting Fortinet's multiple products. This vulnerability involves improper verification of cryptographic signatures, allowing attackers to bypass security controls, execute unauthorized code, or escalate privileges on affected devices. Federal agencies, per BOD 22-01, must remediate this critical issue by the mandated deadline to protect their networks. The flaw’s exploitation risks device compromise and potential lateral movement by sophisticated threat actors, with broad implications for data integrity and operational continuity across affected organizations. This alert reflects the escalating trend of attackers rapidly weaponizing supply chain or cryptographic flaws in core network infrastructure. As organizations increasingly rely on complex integrations and encrypted communications, such vulnerabilities underscore persistent challenges in managing risk and ensuring trust in critical systems.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports