Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
Yanluowang Ransomware & Access Broker Target U.S. Firms: Volkov Convicted
Between July 2021 and November 2022, multiple U.S. businesses—including an engineering firm and a bank—were targeted by the Yanluowang ransomware group, using access broker Aleksei Olegovich Volkov to gain initial entry. Volkov, operating as “chubaka.kor,” exploited vulnerabilities in victim networks, facilitated data theft and encryption, and coordinated ransom payments, some of which totaled $1.5 million. Victims suffered operational disruption, including temporary shutdowns and extortion attempts such as DDoS attacks and executive harassment. Forensic analysis linked the activities to Volkov via cryptocurrency tracing and communication evidence; $24 million in ransoms was demanded in total. This case highlights growing cooperation among cybercriminals, where access brokers sell or share footholds with ransomware operators, fueling larger-scale, multi-faceted cyber-extortion campaigns. The high-profile prosecution also sets precedent for international arrests and restitution, amid increasingly aggressive ransomware trends and evolving attack tactics.
8 months ago
Kill Chain
Nation-State Attack Targets U.S. Congressional Budget Office in Major 2024 Data Breach
In June 2024, the U.S. Congressional Budget Office (CBO) suffered a cybersecurity breach after a suspected foreign nation-state threat actor infiltrated its network. The intrusion was discovered when unusual network activity was detected within CBO systems. Investigations suggest attackers may have accessed sensitive internal documents and communications, exposing potentially confidential government data. Although specifics of the exploited vulnerability remain undisclosed, early reports correlate the activity with sophisticated techniques associated with advanced persistent threats focused on harvesting intelligence from federal agencies. The CBO is coordinating with federal cyber authorities to assess the intrusion’s scope and impact. This event underscores an ongoing surge of nation-state cyber operations targeting U.S. government institutions. Recent patterns reveal an escalation in targeted attacks leveraging stealthy lateral movement and encrypted traffic bypasses, highlighting regulatory and operational pressure for federal agencies to strengthen zero trust principles and enhance east-west network defenses.
8 months ago
Kill Chain
QNAP 2025 Zero-Day Breach: Pwn2Own Shatters NAS Security
In March 2025, QNAP addressed seven critical zero-day vulnerabilities after security researchers demonstrated successful exploitation against their network-attached storage (NAS) devices during the Pwn2Own Ireland cybersecurity competition. The vulnerabilities allowed attackers to gain unauthorized access, compromise stored data, and potentially escalate privileges on affected systems. Once these flaws were publicly disclosed through the competition, QNAP developed and released urgent security patches to mitigate the risk to its global customer base, which includes enterprises and individuals relying on QNAP NAS for data storage. This incident underscores the increasing attention given to storage infrastructure as an attack vector, especially as threat actors and security researchers focus on discovering and weaponizing new zero-day vulnerabilities. The Pwn2Own event continues to reveal hidden risks across common network appliances, prompting vendors to accelerate patch cycles and organizations to prioritize vulnerability management for critical data repositories.
8 months ago
Kill Chain
Cisco Firewalls Under Siege: 2024 Zero-Day Flaws Trigger DoS Attacks on ASA & FTD
In June 2024, Cisco disclosed that two actively exploited zero-day vulnerabilities in its Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) firewalls were being weaponized in the wild. Attackers leveraged these flaws (CVE-2024-20353 and CVE-2024-20359) to trigger repeated reboot loops, effectively causing Denial-of-Service (DoS) on critical network perimeter defenses. Initial exploitation began as targeted zero-days, but attackers quickly adopted the flaws in larger campaigns, dramatically impacting the availability and security of organizations relying on Cisco ASA or FTD devices. The incident underscores a growing trend of targeting infrastructure security devices as a primary attack vector, especially given the rise of ransomware actors and APT groups seeking disruption over data theft. Exploitation of device vulnerabilities for DoS attacks highlights the heightened urgency for rapid patching and robust segmentation in modern enterprise environments.
8 months ago
Kill Chain
AI-Powered Malicious VS Code Extension Triggers Supply Chain Ransomware Alert (2025)
In late 2025, cybersecurity researchers discovered a malicious Visual Studio Code extension named "susvsex" distributed through an official plugin marketplace. Created using artificial intelligence techniques, the extension exhibited overt ransomware capabilities, encrypting files on infected development environments without attempts at obfuscation. The initial infection vector was a seemingly legitimate VS Code extension, weaponized to compromise developer systems and potentially propagate within software supply chains. Organizations relying on VS Code for coding or CI/CD faced the risk of credential theft, data loss, and business disruption if infected by the extension before it was removed. This incident highlights an escalating trend in supply chain and developer ecosystem attacks, where attackers leverage trusted distribution channels and AI-generated malicious code. With open marketplaces and widespread dependency sharing, even reputable software can become a conduit for advanced threats, requiring enterprises to rethink their extension vetting, monitoring, and incident response practices.
8 months ago
Kill Chain
LandFall Spyware: Samsung Zero-Day Exploited Through WhatsApp (2024 Attack Insights)
In early 2024, cybersecurity researchers identified that a sophisticated threat actor exploited a zero-day vulnerability in Samsung’s Android image processing library to deploy a previously unknown spyware, dubbed 'LandFall.' The attackers delivered malicious images via WhatsApp messages, abusing the image parsing process to gain device access without user interaction. Once installed, LandFall enabled covert surveillance, exfiltration of private data, and remote control capabilities, putting millions of Samsung devices at risk globally—especially given the attack’s stealthy, user-independent execution method. The breach demonstrates a significant advancement in mobile spyware delivery and a major supply chain risk for mobile OS providers. This incident is highly relevant as attackers increasingly leverage messaging platforms and zero-click vulnerabilities to distribute advanced spyware. The weaponization of zero-days against widespread consumer hardware underscores the urgent need for rapid vulnerability detection and robust response protocols across the mobile ecosystem.
8 months ago
Kill Chain
Samsung 2025: LANDFALL Zero-Day Spyware Breach Exposes Enterprise Mobile Risks
In October 2025, a critical zero-day vulnerability (CVE-2025-21042) in Samsung Galaxy Android devices was actively exploited in the wild to deploy commercial-grade Android spyware known as LANDFALL. Attackers leveraged an out-of-bounds write flaw in the 'libimagecodec.quram.so' component through remote zero-click techniques, enabling arbitrary code execution without user interaction. Targeted campaigns, primarily in the Middle East, allowed adversaries to gain full device access and conduct covert surveillance until Samsung issued an urgent patch. The attacks highlight the sophistication and stealth of modern mobile threat actors and the increasing use of zero-day exploits to compromise mobile endpoints. This incident exemplifies the rise of highly targeted mobile spyware attacks leveraging zero-day vulnerabilities in globally popular hardware. It signals a broader trend in which commercial surveillance tools are abused by both state and non-state actors, driving greater urgency around mobile threat detection, zero-trust controls, and rapid patch management in enterprise environments.
8 months ago
Kill Chain
Time-Bomb Malware Hidden in NuGet Packages Signals Alarming Supply Chain Threat
In 2023 and 2024, a set of nine malicious NuGet packages, attributed to the user 'shanhai666', were found to infect software supply chains by deploying time-delayed logic bombs. These packages, available through the official NuGet repository, hid code designed to execute malicious activities—such as sabotaging database operations and corrupting industrial control systems—on predefined future dates starting in August 2027. The sophisticated campaign leveraged delayed payload triggers, allowing attackers to infiltrate developer environments undetected for years before activation, thus maximizing potential operational and business disruption. This incident highlights the ongoing risks facing software supply chains, where attackers increasingly employ delayed and concealed attack mechanisms to evade early detection. Businesses across all sectors relying on third-party code repositories must reinforce supply chain security practices and continuously monitor for latent threats that could surface well after initial compromise.
8 months ago
Kill Chain
SonicWall 2024 Breach: Nation-State Actor Steals Firewall Backups in Supply Chain Attack
In early 2024, SonicWall, a prominent network security vendor, disclosed that a sophisticated nation-state threat actor had gained unauthorized access to its systems and exfiltrated firewall backup configurations. The breach exploited the MySonicWall cloud portal as an entry vector, allowing attackers to obtain sensitive backup files from certain customers. While SonicWall emphasized that no customer credentials or direct device access occurred, the compromised backup data could potentially aid attackers in mapping internal customer network topologies, exposing configurations, or enabling tailored downstream attacks. The breach was unrelated to the recent Akira ransomware campaign targeting SonicWall appliances. This incident underscores the increasing targeting of security infrastructure suppliers in supply chain attacks. With nation-state actors focusing on backup and configuration theft, the breach highlights emergent risks to organizations relying on third-party network security providers for confidentiality and resilience.
8 months ago
Kill Chain
Ollama and Nvidia AI Infrastructure Vulnerabilities: A Wake-Up Call for Enterprise Security in 2024
In June 2024, security researchers identified multiple critical vulnerabilities within key AI infrastructure products, most notably affecting Ollama and Nvidia platforms. The most severe flaws enabled authenticated remote code execution and unauthorized access to sensitive AI environments. Attackers could exploit insecure network interfaces and misconfigurations to laterally move across workloads or escalate privileges. These risks threaten the confidentiality, integrity, and availability of AI-powered operations, exposing organizations to theft of proprietary models, service disruption, and downstream compromise. The rapidly maturing adversary tactics around supply chain and platform vulnerabilities magnified these risks. This incident highlights an urgent trend: attackers are now aggressively targeting foundational AI infrastructure in enterprise and cloud settings, focusing on underlying software weaknesses rather than solely data or application layers. As AI adoption accelerates, so does the attack surface, making robust segmentation, encryption, and zero trust approaches vital for resilience.
8 months ago
Kill Chain
LANDFALL Spyware: Exploiting CVE-2025-21042 Against Samsung Android Devices
In early 2025, the commercial-grade spyware known as LANDFALL was discovered targeting Samsung Android devices. Leveraging the newly identified CVE-2025-21042, attackers embedded the spyware in specially crafted malicious DNG image files. When unsuspecting users opened these images, the exploit chain compromised the underlying image processing library, granting attackers unauthorized access to device data, communications, and possibly real-time surveillance capabilities. This incident highlights yet another example of sophisticated supply chain exploitation aimed at high-value mobile assets, resulting in potential data exposure, loss of privacy, and reputational damage for affected organizations and individuals. LANDFALL’s attack chain signals an alarming new era for mobile threats, emphasizing the rapid weaponization of zero-days on widely deployed platforms. With growing regulatory scrutiny, businesses must closely examine mobile security controls and incident response readiness given the increasing complexity of modern spyware campaigns.
8 months ago
Kill Chain
SonicWall 2024 Cloud Backup Breach: Nation-State Attack Exposes Supply Chain Risks
In 2024, SonicWall disclosed a major supply-chain security incident where a state-sponsored threat actor exploited an API flaw to access the company's firewall cloud backup service. This breach, initially downplayed, resulted in the exposure and exfiltration of firewall configuration files for all customers leveraging SonicWall’s cloud backup. These files contained sensitive data such as firewall rules, encrypted credentials, and routing details, representing a significant risk for impacted organizations. An investigation by Mandiant confirmed the full scale of the compromise, though the specific country or threat group responsible remains undisclosed. This attack is especially relevant due to increasing targeting of security vendors and the potential for cascading risk across the customer base. The incident underscores persistent concerns over supply-chain vulnerabilities and the sophistication of nation-state actors focusing on critical infrastructure providers.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports