✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
MostereRAT Malware: New Era of EDR Bypass and Persistent Threats
In 2024, security researchers uncovered a sophisticated campaign deploying the 'MostereRAT' malware against Windows environments. The threat actor used advanced techniques to deliver an EDR (Endpoint Detection and Response)-killing tool, enabling long-term, covert persistence on infected systems. MostereRAT blends into legitimate network traffic, leverages encrypted channels, and systematically disables or bypasses security controls, making detection and remediation difficult. Impacted organizations faced risks of data exfiltration, lateral movement, and significant business disruption, with attackers maintaining access for extended periods before discovery. This incident highlights the increasing prevalence of anti-EDR malware designed to counter modern defensive capabilities. As organizations adopt stronger endpoint security, attackers are deploying stealthier, more evasive malware, presenting ongoing challenges for incident detection, compliance, and cyber resilience.
7 months ago
Kill Chain
Logit-Gap Steering: New Jailbreak Threat Undermines LLM Security in 2024
In mid-2024, academic security researchers unveiled a novel attack against large language models (LLMs) termed "logit-gap steering." This technique exploits the mathematical limits of alignment training by manipulating the logits—the raw output probabilities—of refusal and affirmation tokens. Attackers found that by identifying and minimizing the gap through tailored prompt suffixes, they could frequently bypass internal model guardrails and elicit harmful or disallowed responses, even on the latest open-source models such as gpt-oss-20b, LLama, Gemma, and Qwen. The published methodology demonstrated over 75% attack success rates and triggered industry-wide concern about the resilience of current AI safety controls. This incident comes at a pivotal time as organizations accelerate adoption of AI and generative language models in production. The research spotlights a significant, previously underestimated vector for LLM jailbreak attacks, amplifying regulatory scrutiny and forcing enterprises to re-evaluate security practices for AI deployments.
7 months ago
Kill Chain
2025 Retail Salesforce Data Heist: Extortion Attack Exposes Cloud Security Gaps
In mid-2025, a sophisticated data extortion campaign targeted high-end retail organizations leveraging Salesforce environments. Threat actors—identified as UNC6040 (responsible for access and reconnaissance) and Bling Libra (aka ShinyHunters, handling extortion)—gained initial access through voice-based phishing (vishing) techniques. After establishing a foothold, they conducted in-depth reconnaissance to collect sensitive customer data, including names, birthdates, contact details, and account metadata, which was then exfiltrated. The attackers threatened public disclosure unless the victim organizations paid a ransom, all while leaving minimal forensic traces due to a lack of malware deployment and custom tools. This incident highlights the increasing sophistication of financially motivated cybercrime operations and an industry-wide shift towards data theft extortion without ransomware. There is an urgent need for retail and cloud-reliant enterprises to reassess their security controls, as social engineering vectors bypass traditional perimeter defenses and regulatory scrutiny around cloud data protections intensifies.
7 months ago
Kill Chain
Remote Code Execution via Model Namespace Reuse Hits AI Supply Chains
In early 2024, security researchers identified a novel AI supply-chain attack involving 'model namespace reuse' on popular machine learning platforms such as Hugging Face. Threat actors exploited the inherent trust in model names and namespaces to upload malicious AI models, thereby enabling remote code execution upon download or integration into downstream applications. The attack allowed adversaries to compromise systems within seconds of a user or developer integrating tainted models, potentially resulting in data breach, lateral movement, or disruption of AI-driven business processes. This incident underscores the growing risk within the AI and ML ecosystem, where reliance on third-party and community-contributed models is accelerating. As more organizations rapidly adopt AI across production workloads, supply-chain vulnerabilities like namespace reuse present urgent challenges for security and compliance.
7 months ago
Kill Chain
Sextortion at Scale: Lessons from 1,900 Cryptocurrency Extortion Emails (2021–2025)
Between June 2021 and August 2025, researchers analyzed nearly 1,900 sextortion emails sent globally as part of orchestrated financial extortion campaigns. Threat actors leveraged email as the primary attack vector, issuing blackmail demands and requesting payments to over 200 unique cryptocurrency addresses (primarily Bitcoin). The attackers frequently rotated wallet addresses to hinder tracing, with most being active for only a few days. While 28% of the wallet addresses received no payments, the majority collected varied sums, with a median received amount of approximately $4,315 per address; a handful captured large sums exceeding $75,000. These campaigns underline the continuing prevalence and evolution of cryptocurrency-enabled extortion tactics. Sextortion remains a persistent cybercrime threat, with campaigns adapting to changes in cryptocurrency use and email security. Recent analysis suggests a downward trend in victim willingness to pay, potentially reflecting higher user awareness and stronger resilience to such scams, but attackers are refining techniques to maintain extortion income.
7 months ago
Kill Chain
The New Insider Threat: How a Fake Employee Infiltrated a Tech Giant in 2025
In August 2025, an advanced cyberattack targeted a major tech company when an attacker successfully joined the organization as a new employee using a fabricated identity, bypassing digital and in-person HR and IT onboarding checks. The attacker, under the alias 'Jordan from Colorado,' leveraged expertly forged credentials and references to gain legitimate system access and privileges from day one. Once inside, the attacker rapidly accessed sensitive data, established lateral footholds through internal network movement, and deployed covert remote access tools. The business suffered significant intellectual property theft and operational disruptions before the activity was detected during a routine audit. The incident demonstrates a rising trend in identity-based infiltration, where social engineering is used not to breach perimeters but to abuse trusted onboarding processes. This kind of attack highlights the urgent need for organizations to modernize identity verification and insider threat detection in response to sophisticated credential fraud and evolving attacker tradecraft.
7 months ago
Kill Chain
Gambler Panel: The Rise of Affiliate-Driven Scam Gambling Operations in 2025
In July 2025, researchers uncovered a rapid proliferation of fraudulent online gambling platforms connected to a Russia-based affiliate operation called 'Gambler Panel.' This scheme enables thousands of affiliates to launch polished scam gambling sites using a turnkey fake casino engine and aggressive social media lures—often involving fraudulent endorsements and false claims of free credits. Victims are tricked into making cryptocurrency 'verification deposits' which are subsequently stolen, with attempts to cash out consistently denied. The operation is highly organized, offering detailed playbooks and infrastructure supporting over 1,200 domains run by a network of more than 20,000 affiliates. This incident highlights a new, scalable model for financial fraud: cybercriminals outsourcing risk and execution to large affiliate networks via sophisticated, multi-platform campaigns. The case underscores the dangers posed by accessible, turnkey scam infrastructure and the challenges organizations face in monitoring affiliate-driven threat activity targeting consumers globally.
7 months ago
Kill Chain
Sitecore Zero-Day Breach: ViewState Exploits Lead to Remote Code Execution
In early 2024, threat actors exploited a zero-day vulnerability in Sitecore's ASP.NET-based content management system by weaponizing exposed machine keys, enabling remote code execution via malicious ViewState deserialization. Attackers bypassed authentication controls to inject arbitrary code and gain persistent control over vulnerable web servers, leading to potential data exfiltration and site takeover. Multiple Sitecore installations globally were at risk, highlighting weaknesses in secure key management and web application security monitoring. Organizations faced reputational and operational impacts as attackers abused trusted digital experiences to deliver malware and conduct further intrusions. The incident is part of a broader surge in deserialization and code injection attacks targeting legacy .NET applications. Zero-day exploitation against business-critical CMS platforms increases urgency for robust segmentation, runtime detection, and zero trust controls to defend against rapidly evolving attack techniques.
7 months ago
Kill Chain
Sitecore Vulnerabilities: Cache Poisoning and RCE Exploit Chain Uncovered (2025)
In August 2025, researchers disclosed an exploit chain in the Sitecore Experience Platform involving three newly uncovered vulnerabilities—CVE-2025-53693 (HTML cache poisoning), CVE-2025-53691 (remote code execution via insecure deserialization), and CVE-2025-53694 (not yet detailed). The flaws allow attackers to first poison cached content by manipulating reflected inputs, and then leverage insecure deserialization to remotely execute arbitrary code on targeted Sitecore servers. If exploited, these issues can expose sensitive data and potentially compromise the full web application environment of affected organizations, particularly in sectors relying on large-scale digital experience management. This incident highlights the persistent risk of chained application vulnerabilities enabling critical attacks, such as lateral movement and RCE, within enterprise environments. With web applications being frequent targets and exploit code often surfacing soon after disclosures, organizations must prioritize proactive vulnerability management and robust segmentation to contain blast radius.
7 months ago
Kill Chain
Attackers Exploit Velociraptor Forensics Tool for Covert C2 Tunneling With Visual Studio Code
In June 2025, cybersecurity researchers reported a sophisticated incident in which attackers abused the open-source forensic tool Velociraptor to deploy Visual Studio Code on compromised endpoints and establish an encrypted command-and-control (C2) channel. Threat actors leveraged the legitimate forensic software as a Living Off The Land Binary (LOLBin) to evade detection, achieve execution, and enable covert lateral movement within enterprise environments. This innovative TTP circumvented traditional perimeter detections, and resulted in unauthorized access to sensitive internal systems, raising concerns over the misuse of trusted IT tools in targeted intrusions and potential data exfiltration. The incident highlights a growing trend of blending legitimate IT and developer software within attack chains, making malicious activity harder to distinguish from normal operations. Organizations face increasing regulatory and operational pressure to implement robust east-west traffic monitoring, behavioral detection, and zero trust controls as attackers adopt stealthier methods.
7 months ago
Kill Chain
Amazon Stops APT29 Watering Hole Leverage of Microsoft Device Code
In August 2025, Amazon Security Intelligence teams detected and disrupted a sophisticated nation-state watering hole campaign attributed to the Russian-linked APT29 group. The attackers compromised multiple legitimate websites, redirecting unsuspecting visitors to malicious infrastructure designed to exploit Microsoft's device code authentication flow. By tricking users into authorizing attacker-controlled devices, APT29 was able to gain unauthorized access to victim accounts and sensitive data. The rapid response by Amazon limited the scope of the compromise, but the incident highlights evolving tactics by advanced persistent threats targeting cloud identity systems. This incident is notable for its exploitation of widely used authentication protocols and the opportunistic use of trusted websites for redirection. It reflects a broader escalation in targeted attacks on cloud identities and authentication flows, as well as the sophistication of nation-state threat actors seeking persistent access to corporate and government assets.
7 months ago
Kill Chain
Q2 2025 Vulnerability Exploitation: Multi-Platform Attacks and C2 Automation
In Q2 2025, there was a surge in the exploitation of both newly reported and longstanding software vulnerabilities across enterprise environments. Threat actors leveraged critical CVEs—targeting platforms like Microsoft Windows, Linux, document-editing suites, UEFI firmware, AI frameworks, and remote access tools—to gain initial access and escalate privileges on victim systems. Notably, advanced persistent threat (APT) groups demonstrated increased use of C2 frameworks such as Sliver, Metasploit, Havoc, and Brute Ratel to automate exploitation and maintain persistence, highlighting attackers’ growing sophistication and automation. The operational impact ranged from data theft and malware deployment to strategic risks, as attackers pivoted laterally and disabled security mechanisms. The Q2 2025 wave underscores a broader industry trend: attackers are rapidly exploiting both legacy and emerging weaknesses, especially as vulnerability disclosure volumes continue to rise. Automation within C2 frameworks and exploitation targeting multi-cloud and hybrid environments reinforce the urgency to modernize detection and patch-management programs to keep pace with evolving threats.
7 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports