The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
npm Supply-Chain Breach: Malicious Package Steals WhatsApp Accounts and Messages
In June 2024, security researchers uncovered a malicious npm package masquerading as a legitimate WhatsApp Web API library. The package, downloaded from the Node Package Manager (NPM) registry, surreptitiously executed code to hijack WhatsApp accounts by stealing authentication credentials, intercepting messages, and exfiltrating contact information. Attackers leveraged this supply-chain compromise to gain unauthorized access to WhatsApp accounts, putting personal messages and sensitive user data at risk. The incident underscores growing threats targeting developer ecosystems and open-source repositories, demonstrating how a single compromised package can have widespread impact across organizations and individuals relying on shared libraries. This attack is particularly significant as adversaries increasingly exploit the software supply chain to distribute malware through trusted open-source ecosystems. Organizations face heightened regulatory scrutiny over software integrity, and similar tactics are quickly proliferating, prompting urgent calls for enhanced dependency management and real-time code vetting across the industry.
8 months ago
Kill Chain
INTERPOL Sparks Major 2024 Ransomware Takedown in Operation Sentinel
In May 2024, INTERPOL led a sweeping global cybercrime crackdown titled Operation Sentinel, targeting ransomware crews, business email compromise (BEC) groups, and extortion gangs. The coordinated action resulted in the arrest of 574 individuals across multiple countries. Six major ransomware strains were decrypted, and authorities seized over $3 million in illicit funds, effectively disrupting expansive international crime networks. Attackers leveraged a mix of phishing, malware, and lateral movement to infiltrate corporate and public-sector environments, lock critical data, and demand ransom payments. The impact was both substantial and international, affecting hundreds of organizations and drawing heavy collaboration among law enforcement agencies across continents. This case underscores the rise of global, cross-border law enforcement cooperation in tackling ransomware and financially motivated cybercrime. As threat actors become ever more sophisticated and resilient, multinational efforts and advanced decryption capabilities are now essential for effective disruption and victim support.
8 months ago
Kill Chain
Uzbekistan 2025: Wonderland Android Malware Campaign Steals Millions via Mobile Banking Fraud
In late 2025, a sophisticated cybercrime operation in Uzbekistan targeted Android users through the deployment of advanced dropper apps that installed the Wonderland malware. Disguised as legitimate Google Play or popular media files, these malicious APKs leveraged social engineering and fake landing pages to trick users into installation after enabling 'unknown sources.' The threat actor group, TrickyWonders, coordinated their campaign via Telegram, using heavily obfuscated droppers (MidnightDat and RoundRift) and dynamic C2 infrastructure. Once on a device, Wonderland enabled real-time SMS and OTP theft, phone number hijacking, lateral propagation via Telegram session compromise, and banking fraud, resulting in significant financial losses for victims. This incident underscores a broader trend: attackers are rapidly iterating their methods, shifting towards deceptive dropper-based infection chains, robust C2 agility, and hierarchically structured cybercrime operations. The campaign’s evolution, paired with similar threats like Cellik, Frogblight, and NexusRoute, signals an urgent need for improved mobile endpoint security, user awareness, and regulatory vigilance.
8 months ago
Kill Chain
MacSync Malware Bypasses macOS Gatekeeper with Notarized Infostealer in 2024
In June 2024, security researchers identified a new MacSync infostealer variant targeting macOS devices. The malware is delivered through a digitally signed and notarized Swift application that successfully evades Apple’s Gatekeeper checks, allowing it to run without typical security warnings. Once executed, MacSync exfiltrates sensitive user information including credentials, browser data, and files—leveraging encrypted command-and-control channels to avoid detection. The sophisticated dropper uses advanced evasion techniques to bypass standard macOS security controls, elevating risks for individuals and organizations running unpatched systems. This attack illustrates an evolving landscape where threat actors exploit trusted developer channels and novel evasion tactics to compromise macOS environments. With the growing adoption of macOS in enterprise and remote work settings, organizations are urged to review their controls, respond proactively, and address malware risks that legacy security tools may not detect.
8 months ago
Kill Chain
Nissan Customer Data Exposed After Red Hat Supply Chain Breach
In September 2023, Nissan Motor Co. Ltd. confirmed that the personal information of thousands of its customers was compromised due to a supply chain data breach at Red Hat, a leading software vendor. The breach stemmed from unauthorized access to customer data managed by Red Hat, which affected Nissan’s customer records, including names and contact information. While there is no current evidence of financial or highly sensitive information being lost, Nissan has notified the individuals impacted and is working with Red Hat to further assess and contain the breach’s full scope. This incident highlights the ongoing risk posed by third-party vendors in the automotive and technology sectors, as organizations increasingly rely on external service providers for software and infrastructure. The Nissan-Red Hat breach underscores the rising threats targeting supply chains, emphasizing the urgent need for robust vendor security controls and visibility into partner ecosystems.
8 months ago
Kill Chain
How Multi-Vector Attacks in 2025 Exposed Firewall and Internal Security Gaps
In December 2025, several global organizations faced a coordinated multi-vector cyber campaign in which threat actors leveraged recent vulnerabilities across enterprise firewalls, browser plugins, and connected devices. Attackers stealthily exploited zero-day flaws in network perimeter devices to access east-west traffic, deploy lateral movement, and exfiltrate sensitive data using encrypted channels. Both commercial and open-source threat detection struggled to identify activity quickly, resulting in significant operational disruptions, regulatory notification requirements, and data privacy liabilities affecting numerous sectors worldwide. This incident is indicative of a new threat paradigm in which attackers favor multi-tool, insider-style techniques, combining supply chain vulnerabilities with stealthy movements inside trusted IT environments. Security and compliance teams must now contend with adversaries who bypass traditional controls and exploit overlooked components, highlighting urgent needs for zero trust segmentation, improved traffic visibility, and robust egress monitoring.
8 months ago
Kill Chain
Uzbekistan Telegram Users Hit by Sophisticated Android SMS-Stealer Campaign in 2024
In early 2024, Android users in Uzbekistan experienced a surge of targeted attacks as cybercriminals deployed SMS-stealer malware through phishing campaigns delivered via Telegram. The attackers leveraged fake and malicious applications purpose-built to intercept and exfiltrate SMS messages, enabling unauthorized access to multi-factor authentication codes and banking credentials. Threat actors demonstrated increasing sophistication and adaptability by iterating on malware variants, incorporating obfuscation tactics, and exploiting the popularity of Telegram as a distribution channel. This resulted in significant risks of financial theft and compromised user privacy across a large segment of Uzbek Android device users. This incident highlights the evolving landscape of mobile infostealer attacks in Central Asia, with a marked uptick in the use of instant messaging platforms as malware delivery vectors. The swift adaptation of criminal tactics underscores the necessity for organizations and individuals to strengthen mobile endpoint security and remain vigilant against increasingly convincing phishing and sideloading threats.
8 months ago
Kill Chain
Malicious npm Package Exposes WhatsApp Accounts in 2025 Supply Chain Attack
In May 2025, a malicious npm package named "lotusbail" was uploaded to the JavaScript ecosystem, masquerading as a fully functional WhatsApp API. Created by a user known as "seiren_primrose," the package was downloaded over 56,000 times before discovery. Behind its legitimate capabilities, "lotusbail" stealthily exfiltrated WhatsApp credentials, intercepted all messages, harvested contacts, installed a persistent backdoor, and linked attacker devices to victims’ WhatsApp accounts for continuous unauthorized access. Data was encrypted and exfiltrated to attacker-controlled servers, with covert device pairing persisting even after package removal, compounding the risk to both individuals and organizations reliant on WhatsApp for communication. This incident highlights the growing risk of advanced supply chain attacks via trusted open-source repositories. Attackers increasingly use sophisticated evasion tactics—like anti-debugging, code obfuscation, and reputation laundering—to slip past static and reputation-based security controls. As software supply chain threats intensify, organizations must urgently reassess the hygiene, monitoring, and zero trust posture of their development pipelines.
8 months ago
Kill Chain
RansomHouse's 2025 Encryption Leap: The Rise of 'Mario' and Multi-Layered Ransomware
In December 2025, the RansomHouse ransomware-as-a-service (RaaS) group unveiled a major upgrade to its encryptor, dubbed ‘Mario’, shifting from a basic linear technique to a complex multi-layered encryption process. This variant leverages dynamic chunking, dual encryption keys, sophisticated memory organization, and non-linear file processing, making data recovery and reverse engineering significantly more challenging. Targeting environments such as VMware ESXi, the upgraded tooling enables attackers to encrypt large volumes of files efficiently, evidenced by attacks on organizations including Japanese e-commerce giant Askul, leading to substantial operational disruption and customer data compromise. RansomHouse’s encryption evolution underscores the continuing professionalization of RaaS groups, complicating detection and recovery for defenders. As multi-layered and adaptive ransomware proliferates, organizations face heightened risks, regulatory scrutiny, and the need to adopt advanced segmentation, visibility, and threat response controls.
8 months ago
Kill Chain
US DOJ Indicts 54 for Ploutus Malware ATM Jackpotting: Tren de Aragua’s US Crime Wave, 2025
In December 2025, the U.S. Department of Justice charged 54 individuals associated with the Tren de Aragua criminal gang in a far-reaching ATM jackpotting operation across the United States. By deploying Ploutus malware onto automated teller machines, the group manipulated hardware to force cash withdrawals—ultimately stealing millions of dollars. The multi-state scheme involved coordinated physical access to ATMs, installation of malicious software, and cash-out teams, highlighting significant vulnerabilities in banking infrastructure and ATM security controls. This incident underscores an escalating wave of financially motivated attacks leveraging sophisticated malware and organized criminal networks. With jackpotting attacks resurging globally and law enforcement intensifying their response, organizations must prioritize layered defenses, real-time anomaly detection, and compliance with evolving regulatory requirements.
8 months ago
Kill Chain
Cisco VPNs and Email Service Campaigns: How Multi-Vector Attacks Are Changing the Cyber Risk Landscape
In early 2024, Cisco VPN appliances and various enterprise email services were targeted in two distinct but nearly simultaneous cyber campaigns. The first, a highly coordinated attack, leveraged zero-day vulnerabilities and credential harvesting to infiltrate corporate VPNs, granting attackers lateral access to sensitive networks. Around the same period, a separate 'spray-and-pray' phishing wave indiscriminately targeted a wide swath of business email services, seeking to exploit weak authentication and unpatched systems. Combined, the incidents led to multiple business disruptions, credential leaks, and prompted extensive incident response efforts across affected organizations. This incident is part of a larger trend where cybercriminals simultaneously exploit both remote-access infrastructure and cloud-based email, reflecting a shift toward multi-vector, blended attacks. Organizations are facing heightened regulatory and operational pressure to defend against ever more sophisticated and opportunistic threats targeting identity, access points, and critical communications systems.
8 months ago
Kill Chain
FBI Reveals Years-Long Deepfake Impersonation Campaign Against U.S. Officials
From 2023 onward, unknown threat actors used AI-powered voice cloning and deepfake techniques to impersonate senior U.S. government officials, including members of the White House and Congress. These attacks targeted officials, their families, and associates via initial SMS contact, escalating to encrypted messaging platforms such as Signal, WhatsApp, and Telegram. Once rapport was established, attackers used tailored pretexts to request sensitive personal information, passport photos, device syncing, introductions, or even funds transfers, posing as, or on behalf of, high-profile government leaders. The campaign enabled further impersonation by harvesting victims’ contact lists and executing subsequent rounds of targeted smishing and vishing attacks. This incident underscores the escalation of social engineering campaigns powered by generative AI, as adversaries blend deepfake technologies with encrypted communications to evade detection and amplify deception. The evolving tactics, targeting highly sensitive circles, highlight both the sophistication of modern impersonation attacks and the urgent need for updated identity verification protocols.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports