Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
Shai-Hulud 2.0: 2024 NPM Supply Chain Attack Exposes 400,000 Developer Secrets
In June 2024, the 'Shai-Hulud 2.0' campaign executed a large-scale supply chain attack against the JavaScript ecosystem by compromising over 750 packages on the NPM registry. Attackers used malicious dependencies to covertly exfiltrate environment variables and developer secrets to public GitHub repositories, exposing as many as 400,000 authentication credentials and tokens. The attack leveraged automation to rapidly disseminate malware and gather sensitive data from unwitting developers and CI systems, impacting thousands of organizations and potentially enabling downstream breaches. This incident underlines the growing risks of open-source supply chain vulnerabilities and highlights attacker innovation in automated credential harvesting. With supply chain attacks rising and developers relying on public package repositories, proactive controls and zero-trust practices have never been more essential to prevent code-integrity and data-exposure risks.
8 months ago
Kill Chain
Google Fixes 107 Android Vulnerabilities, Including 2 Exploited in the Wild
In June 2025, Google released a critical Android security update addressing 107 vulnerabilities across multiple subsystems, including Framework, System, and third-party vendor components such as Arm, MediaTek, and Qualcomm. Notably, two high-severity Framework vulnerabilities had been exploited in the wild prior to the patch, allowing attackers to potentially bypass defenses, execute code, or gain unauthorized access on unpatched devices. Attackers leveraged these flaws to target unsuspecting Android users before Google issued its advisory and fix, putting millions of devices at risk until users updated their software. This incident highlights the ongoing risk posed by zero-day vulnerabilities in widely used mobile platforms and the rapidity with which sophisticated threat actors exploit unpatched systems. The urgency of timely patching is reinforced, as targeted attacks on mobile users remain an attractive vector for cybercriminals and APT groups alike.
8 months ago
Kill Chain
GlassWorm Returns: 2025 Supply Chain Attack on Developer Tool Extensions
In late 2025, the malicious campaign known as GlassWorm reemerged, infiltrating the Microsoft Visual Studio Marketplace and Open VSX with 24 rogue extensions disguised as legitimate developer tools such as Flutter, React, Tailwind, Vim, and Vue. By impersonating trusted tools, GlassWorm tricked developers into installing compromised extensions containing hidden payloads. Once embedded, these extensions established command-and-control communication over the Solana blockchain and enabled threat actors to perform code exfiltration, credential harvesting, and potentially insert backdoors into enterprise codebases, causing major risks for organizations leveraging these tools in their software supply chain. This incident underscores the ongoing and evolving risk of supply chain attacks targeting popular software development ecosystems. With developers as high-value targets, adversaries are increasingly sophisticated in exploiting marketplaces and open-source repositories to distribute malicious code, highlighting the urgent need for stronger validation, monitoring, and zero trust controls in software development lifecycles.
8 months ago
Kill Chain
Malicious npm Package Outsmarts AI Security Tools in 2024 Supply Chain Breach
In February 2024, researchers identified a supply chain attack leveraging a malicious npm package named eslint-plugin-unicorn-ts-2, published under the guise of a TypeScript extension for ESLint by a user called "hamburgerisland." This package included hidden prompt injections and obfuscated scripts specifically designed to evade detection by AI-driven security scanners. Once integrated into a developer's project, it could execute unauthorized code, exfiltrate data, and potentially propagate laterally within developer environments. The attack highlighted how AI-oriented security tools can be manipulated through adversarial prompts and code concealment, putting countless downstream applications at risk in the dynamic JavaScript/Node.js ecosystem. The incident exemplifies sophisticated adversary adaptation, with attackers now actively engineering open-source supply chain threats to outsmart automated, AI-driven defenses. Organizations relying on package registries and automated code validation face urgent pressure to enhance both technical controls and threat intelligence around third-party dependencies.
8 months ago
Kill Chain
Lazarus APT’s Remote-Worker Ruse: How North Korean Hackers Infiltrated via Trusted IT Contractors
In late 2025, cybersecurity researchers from BCA LTD, NorthScan, and ANY.RUN captured an active infiltration by North Korea’s Lazarus Group (specifically the Famous Chollima division) leveraging remote IT workers implanted in Western organizations. This highly coordinated campaign used the appearance of legitimate remote workers—often hired via freelance and IT staffing platforms—to discreetly gain access to internal systems, exfiltrate sensitive data, and facilitate the deployment of malware directly through trusted accounts. The operation showcased sophisticated methods for circumventing east-west traffic controls and exploiting trusted relationships, posing a direct risk to organizations’ hybrid and cloud environments. This breach exemplifies the quick evolution of nation-state threat actors exploiting global remote work and cloud-native architectures. As the use of remote staff and contractors surges, organizations face mounting pressure to implement zero trust controls and granular segmentation to prevent well-resourced APTs from leveraging trusted credentials for deep access and stealthy lateral movement.
8 months ago
Kill Chain
CISA Flags Critical Android Framework Flaws in 2025: Urgent Action Required
In December 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two newly discovered Android Framework vulnerabilities—CVE-2025-48572 (Privilege Escalation) and CVE-2025-48633 (Information Disclosure)—to its Known Exploited Vulnerabilities Catalog. These flaws, which have already been actively exploited in the wild, allow malicious actors to escalate privileges and potentially access sensitive data on affected Android devices. The vulnerabilities create substantial risk, particularly for federal agencies and enterprises relying on Android in their operations, prompting CISA to mandate urgent remediation under Binding Operational Directive 22-01. This incident highlights the persistent targeting of mobile platforms and increased sophistication in privilege escalation techniques observed by threat actors. Organizations are urged to prioritize patching and reinforce security monitoring, as the exploitation of unpatched Android vulnerabilities continues to fuel regulatory and cyber risk concerns in both public and private sectors.
8 months ago
Kill Chain
Law Enforcement Dismantles Cryptomixer, Deals Major Blow to Ransomware Laundering Networks
In June 2024, a coalition of European law enforcement agencies successfully disrupted Cryptomixer, a cryptocurrency mixing service allegedly used to launder proceeds from ransomware and cybercrime. Authorities seized infrastructure and millions in digital assets linked to illicit transactions, following months of cross-border investigation and digital forensics. Cryptomixer was reportedly favored by ransomware groups to obfuscate the trail of stolen funds, complicating recovery efforts and hampering international financial tracking of illicit operations. This incident underscores the escalation of law enforcement action against cryptographic financial laundering tools, which remain instrumental to cybercriminal operations. Increasing scrutiny and regulatory collaboration highlight a growing intolerance for shadow financial ecosystems enabling ransomware and cyber extortion.
8 months ago
Kill Chain
SharePoint 2025: ToolShell In-Memory Exploit Bypasses Defenses
In August 2025, Microsoft SharePoint servers were targeted by an advanced exploit chain known as ToolShell, leveraging newly disclosed vulnerabilities CVE-2025-53770 and CVE-2025-53771. Threat actors bypassed authentication and exploited deserialization flaws on on-premises SharePoint Server 2016, 2019, and Subscription editions. Initial attacks involved file-based web shells easily detected by EDRs, but adversaries quickly shifted to highly evasive in-memory payloads, rendering detection challenging and enabling the extraction of machine keys or the execution of PowerShell commands for data exfiltration and deeper system compromise. The incident underscores the growing risks of sophisticated post-exploit activity and lack of robust network detection. This breach highlights a wider threat: attackers are increasingly adapting their techniques to evade endpoint protections by using fileless, memory-resident malware and targeting enterprise collaboration platforms. As such attack patterns spread, organizations must urgently reinforce defenses and monitor network-level traffic for signs of exploitation, especially with remote work and critical business data gravitating to such platforms.
8 months ago
Kill Chain
North Korea’s ‘Contagious Interview’ npm Supply Chain Attack Disrupts Developer Ecosystem
In October 2023, North Korean state-sponsored threat actors launched an extensive supply chain attack by distributing over 197 malicious npm packages, collectively accumulating more than 31,000 downloads. These attackers, using tactics known as the 'Contagious Interview,' targeted software developers, especially those active in open-source environments, by delivering trojanized code through compromised npm modules. The campaign aimed to infiltrate developer systems, steal sensitive information, and establish persistent access to downstream enterprise networks, significantly raising the risk to downstream software supply chains and CI/CD pipelines. This incident is especially notable for its scale, rapid spread, and focus on highly trusted open-source ecosystems, underscoring an alarming trend in software supply chain attacks. Organizations are urged to strengthen controls around package management, implement zero trust principles, and increase monitoring of development infrastructure to defend against similar threats.
8 months ago
Kill Chain
Google Issues Urgent Patch for 107 Android Vulnerabilities, Two Actively Exploited Zero-Days
In December 2025, Google released a significant Android security update that addressed 107 vulnerabilities, including two zero-day flaws (CVE-2025-48633 and CVE-2025-48572) already being actively exploited in the wild. These high-severity issues in the Android framework allowed threat actors to access sensitive information and escalate privileges, posing a substantial threat to user data and device functionality. The update also remedied several critical vulnerabilities impacting the kernel, system, and multiple vendor components such as MediaTek, Unisoc, and Qualcomm. This incident highlights the intricate security landscape of mobile operating systems and the evolving tactics of cyber adversaries in exploiting vendor fragmentation and delayed patch cycles. The breadth and urgency of this patch reflects growing concerns around mobile platform vulnerabilities, especially as targeted exploitation of zero-days intensifies. With attackers rapidly leveraging gaps before they’re widely recognized or patched, organizations face increased pressure to maintain real-time vulnerability management and swift patch deployment to minimize exposure.
8 months ago
Kill Chain
Authorities Dismantle Cryptomixer: $28 Million in Bitcoin Seized Amid Europol-Led Takedown
In June 2024, European authorities executed a coordinated operation to dismantle Cryptomixer, a cryptocurrency mixing service reportedly used to launder over $1.5 billion for global cybercriminals. Operation Olympia involved Europol, Eurojust, and law enforcement agencies from Germany and Switzerland, resulting in the seizure of nearly $28 million in Bitcoin, three physical servers, the cryptomixer.io domain, and over 12 terabytes of data. Cryptomixer functioned as an anonymizing layer for a multitude of cybercrimes, including ransomware, payment card fraud, and trafficking in illicit goods, allowing threat actors to evade detection and launder stolen assets. This takedown demonstrates mounting regulatory and law enforcement pressure on cryptocurrency-based money laundering infrastructure. The case highlights a shift among advanced threat groups—such as the North Korean Lazarus Group—from prioritizing anonymity to speed and automation in financial cybercrime operations, reflecting evolving cybercriminal tactics and the urgent need for robust digital asset tracking controls.
8 months ago
Kill Chain
Law Enforcement Dismantles Cryptomixer: Major Blow to Crypto Laundering Networks
In June 2024, a coordinated operation between Swiss and German law enforcement agencies led to the shutdown of the Cryptomixer cryptocurrency-mixing service. Since its inception in 2016, Cryptomixer is believed to have laundered over €1.3 billion in Bitcoin, providing cybercriminals with tools to obfuscate illicit financial flows from ransomware, scams, and darknet market activities. The takedown included seizure of digital infrastructure and assets, disrupting one of the major cryptocurrency laundering platforms that aided threat actors operating globally. This collaborative international action highlights increased efforts by authorities to clamp down on crypto-enabled cybercrime. The incident reflects the growing focus on digital financial transparency and signals greater scrutiny of services aiding threat actors in anonymizing transactions.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports