✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
HybridPetya Ransomware: How Attackers Bypassed Secure Boot to Compromise UEFI
In June 2024, cybersecurity researchers uncovered a new ransomware strain called 'HybridPetya' that combines elements of the notorious Petya and NotPetya malware families. This advanced ransomware specifically targets UEFI-based systems, bypassing Secure Boot protections by leveraging sophisticated bootkit techniques. HybridPetya infiltrates environments via spear-phishing and lateral movement, then encrypts critical system files at the firmware level, effectively crippling affected organizations and creating significant hurdles for recovery. Its wiper-like capabilities echo NotPetya’s destructive impacts, raising major concerns for enterprises with critical infrastructure or legacy firmware defenses. The emergence of HybridPetya underscores an escalation in attacker sophistication, with a resurgence in supply-chain and firmware-level attacks. The incident highlights the urgent need for proactive firmware security, robust patch management, and Zero Trust architectures to counter ransomware operators increasingly weaponizing advanced, persistent threat techniques.
7 months ago
Kill Chain
Emerging Yurei Ransomware Claims First Victims in 2024
In early June 2024, a new ransomware operation identified as Yurei, reportedly originating from Morocco and named after Japanese spirits, claimed its first set of confirmed victims. The Yurei group leveraged a customized variant of the Prince-Ransomware binary, successfully breaching targets by deploying file-encrypting malware through typical ransomware vectors. Notably, researchers discovered that the malware implementation contained a technical flaw permitting partial data recovery, though this did not nullify the criminal extortion threats made against affected businesses. The attack has led to data loss, service interruption, and urgent incident response at affected organizations. This incident spotlights the evolving ransomware landscape, where new actors rapidly weaponize existing malware tools, often introducing subtle encryption modifications. Yurei’s activity shows how flaws in ransomware code do not necessarily mitigate risk, as extortion and operational disruption remain impactful. Organizations must adapt controls to defend against agile threat actors, even when exploits are imperfectly engineered.
7 months ago
Kill Chain
The FileFix Phishing Campaign: Obfuscation, Steganography, and Multilingual Threats Hit Globally
In early 2024, security researchers identified a sophisticated, widescale phishing campaign leveraging a malicious tool called FileFix. The campaign utilized advanced code obfuscation, steganography, and localization in at least 16 languages to distribute phishing payloads globally. Attackers delivered FileFix through deceptive emails and malicious attachments, successfully bypassing traditional security filters. Once executed, the malware embedded within attachments enabled remote access, data theft, and credential harvesting, affecting organizations in multiple sectors and exposing sensitive business data to potential fraud and operational disruption. FileFix highlights a new wave of phishing threats combining obfuscation, multilingual lures, and novel payload delivery. Its rapid evolution and global reach underscore the increasing sophistication of social engineering attacks, making robust detection and segmentation capabilities essential for all enterprises.
7 months ago
Kill Chain
'Vane Viper': PropellerAds Tied to 2025’s Largest Malvertising & Cybercrime Network
In September 2025, cybersecurity researchers uncovered that the 'Vane Viper' threat group had leveraged the commercial adtech platform PropellerAds to orchestrate one of the largest malvertising and cybercrime operations observed in recent years. The threat actor, active for over a decade, used compromised websites and malicious ads to funnel internet users through complex redirection chains—culminating in exploit kits, malware, ransomware, and scam campaigns. Investigations tied PropellerAds and its parent AdTech Holding, via shared infrastructure and business links, to a sprawling web of entities facilitating the operation and exposing untold numbers of enterprise and consumer users to cyber risk. This incident is particularly significant because it demonstrates the co-mingling of legitimate commercial digital ad infrastructure with cybercriminal activity, challenging the line between victimized platforms and complicit actors. The case spotlights growing regulatory and enterprise security concerns around malvertising, supply chain integrity, and weaponized ad ecosystems.
7 months ago
Kill Chain
Shai-Hulud Worm: Self-Propagating Malware Hits 180+ NPM Packages in Major Supply Chain Breach
In September 2025, a novel self-replicating worm, dubbed 'Shai-Hulud,' targeted the JavaScript NPM ecosystem by infecting over 180 code packages. The malware exploited developer authentication tokens found on Linux and macOS devices, replicating itself into the top 20 packages accessible to the compromised account and rapidly publishing malicious package versions. Stolen credentials were published in new, public GitHub repositories, compounding the supply chain risk. Though the initial infection included several packages managed by CrowdStrike, the company quickly removed the compromised code and rotated secrets, preventing wider impact to its flagship products. This incident highlights the increasing sophistication and automation of supply chain compromise, especially in open-source software development. The self-propagating nature of Shai-Hulud, combined with credential harvesting and public exposure, represents a growing risk trend for organizations relying on software registries.
7 months ago
Kill Chain
Salty2FA: The Next Wave of Enterprise Phishing-as-a-Service in 2024
In early 2024, cybersecurity researchers uncovered the Salty2FA Phishing-as-a-Service (PhaaS) kit, designed to bypass multi-factor authentication (MFA) protections for enterprise environments. The kit enables attackers to launch highly convincing phishing campaigns by emulating trusted authentication flows and harvesting credentials—including two-factor tokens—using adversary-in-the-middle proxy techniques. Salty2FA's modular architecture, scalability, and integration with encrypted communication channels make it particularly appealing to cybercriminals targeting corporate user bases. Compromised accounts can facilitate credential stuffing, lateral movement, and data exfiltration in victim organizations. This incident highlights the growing professionalization of cybercriminal groups and a trend toward sophisticated PhaaS offerings that significantly lower barriers for conducting enterprise-level breaches. Organizations should note the surge in attacks able to circumvent standard MFA and adapt their defenses accordingly.
7 months ago
Kill Chain
2024 Shai-hulud Worm: Major Supply Chain Attack Strikes NPM
In September 2024, a self-replicating malware dubbed "Shai-hulud" infiltrated the open source ecosystem by targeting hundreds of NPM (Node Package Manager) packages. The worm initiates its campaign by compromising a single software component, and automatically harvests secrets, tokens, and credentials present in affected developers' environments. By leveraging compromised NPM accounts, Shai-hulud spreads itself through subsequent package uploads, injecting malicious payloads into new releases and perpetuating a chain reaction across software supply chains. Impacted parties range from individual developers to prominent tech companies and security vendors. This incident highlights a concerning escalation in supply chain threats, demonstrating advanced automation in malware propagation and the weaponization of interconnected open source dependencies. The attack underscores the rising prevalence of highly automated, lateral-moving malware and the systemic risks posed by compromised development ecosystems.
7 months ago
Kill Chain
Raven Stealer Uses Telegram to Pilfer Chromium Data in 2024
In early 2024, security researchers identified a new infostealer variant, Raven Stealer, being distributed via underground forums and cracked software packages. The malware targets Windows systems and focuses on stealthy extraction of browser data, particularly from Chromium-based browsers such as Google Chrome. Once installed, Raven Stealer harvests credentials, cookies, browser histories, and cryptocurrency wallets before exfiltrating the data through encrypted Telegram channels. The attack exploits unmonitored endpoints and capitalizes on users’ download of pirated or repackaged software, resulting in widespread compromise of sensitive authentication data across multiple organizations. This incident underscores the ongoing evolution of commodity malware and demonstrates the sophistication with which even low-cost infostealers are leveraging encrypted communications and social engineering. As attackers continue to innovate with new TTPs and delivery vectors, organizations must strengthen endpoint monitoring and policy enforcement to reduce exposure to similar threats.
7 months ago
Kill Chain
Microsoft September 2025 Patch Tuesday: Critical Privilege Escalation Flaws Demand Immediate Action
In September 2025, Microsoft disclosed 81 security vulnerabilities across its portfolio, with a significant focus on escalation of privilege (EoP) flaws. Of the CVEs released, 38 enabled attackers to gain elevated access after initial compromise, affecting modules like SMB and NTLM. Notably, CVE-2025-55234 (SMB) and CVE-2025-54918 (NTLM)—both rated CVSS 8.8—were publicly known and considered high impact, allowing attackers to leverage relay and crafted packet attacks for system takeover. Additional critical vulnerabilities were identified in Windows UI XAML and HPC components. While no active exploitation was confirmed at release, the breadth of affected products and criticality prompted urgent patching recommendations. This wave of privilege escalation vulnerabilities underscores the ongoing risk posed by identity-based attacks and lateral movement, compelling organizations to accelerate patch deployment and strengthen segmentation controls. With the end-of-life of Windows 10 and expanded MFA mandates on the horizon, the incident reinforces the necessity for layered defenses and up-to-date asset management.
7 months ago
Kill Chain
K2 Think AI Model Jailbroken Within Hours of 2024 Release
On September 9, 2024, the UAE-backed 'K2 Think' large language model (LLM) was released with the goal of industry-leading transparent reasoning. Within hours, however, cybersecurity researchers discovered a critical vulnerability known as Partial Prompt Leakage. This flaw allowed adversaries to observe the model's internal logic in plain text, making it easier to methodically bypass safeguards and jailbreak the AI system. The exploit was demonstrated by researcher Alex Polyakov, who publicly documented how attackers could uncover and iterate against the model’s defenses, enabling harmful behaviors such as malware generation. The breach did not result in immediate large-scale misuse, but it revealed a key tradeoff between transparency and security in modern LLM development. This incident is emblematic of new AI security risks emerging as open, auditable models grow in popularity. It underscores the urgency for vendors to balance transparency with robust protection, as attackers quickly adapt to and exploit unique model features. With increased regulatory scrutiny and rising enthusiasm for open-source AI, safeguarding model reasoning is now a critical surface organizations cannot ignore.
7 months ago
Kill Chain
Lies-in-the-Loop: When AI Coding Agents Become Supply Chain Threats
In June 2024, researchers at Checkmarx Zero demonstrated a novel supply chain attack called 'Lies-in-the-Loop' (LITL) targeting AI-assisted coding agents, specifically Anthropic's Claude Code. By leveraging prompt injection, attackers manipulated the AI into concealing malicious code execution behind benign prompts, effectively tricking human operators into approving dangerous actions. The attack exploited trust in the 'human-in-the-loop' workflow, showing that malicious context within public resources like GitHub issues could hide remote code execution triggers. Successful exploitation enabled attackers to deploy arbitrary commands and potentially introduce malicious packages into software repositories, increasing the risk of downstream supply chain compromise. This incident highlights a concerning trend: as AI coding agents are rapidly adopted, their interfaces become a ripe target for adversaries using social engineering and prompt manipulation. The attack underscores the evolving sophistication of supply chain threats, especially those that blur the lines between human fallibility and machine autonomy in development environments.
7 months ago
Kill Chain
Vidar Infostealer Returns in 2024 with Stealthier Malware Campaigns
In June 2024, cybersecurity researchers observed a significant resurgence of the Vidar infostealer malware, marked by notable advancements in evasion and data exfiltration techniques. Vidar, which originated as a variant of Arkei and has remained active since 2018, now leverages encrypted command-and-control (C2) channels, sophisticated PowerShell-based delivery, and covert exfiltration methods to siphon credentials, cookies, authentication tokens, and sensitive financial information. The latest campaigns employ phishing, malvertising, and compromised websites as entry vectors. Tactics such as obfuscated PowerShell scripts, living-off-the-land binaries (LOLBins), Windows Defender exclusion manipulation, persistence via scheduled tasks, and exfiltration over TLS have enabled Vidar to bypass traditional detection controls and ensure lasting presence within infected enterprise and individual user environments. The rapid iteration and adaptability of Vidar reflect broader trends in malware-as-a-service (MaaS) operations—demonstrating how popular infostealers continually implement new stealth and evasion tactics. This highlights the urgent need for organizations to adopt layered security defenses and proactive threat detection, as infostealers like Vidar push the boundaries of stealth and data theft in an era of increasing hybrid work, regulatory scrutiny, and sophisticated social engineering.
7 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports