Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
CERT-FR Uncovers Advanced Apple Spyware Exploitation in 2024
In June 2024, a CERT-FR advisory revealed the exploitation of a zero-day vulnerability within Apple operating systems, alleged to be leveraged in targeted spyware attacks against select individuals. Discovered after reports of 'sophisticated' exploitation, the flaw allowed attackers to covertly gain access to devices, harvest sensitive data, and monitor communications by bypassing security defenses. Attackers deployed advanced tactics to deliver the payload, focusing on high-profile victims with a history of surveillance targeting. Apple has since released security updates to address the vulnerability, but the impact underscores persistent risks to user privacy and national security. This incident is particularly relevant amid a surge in zero-day exploitation by sophisticated threat actors, highlighting the elevated risks posed by commercial spyware and surveillance tools. It also reinforces regulatory and enterprise urgency to enhance detection, patch management, and mobile endpoint security strategies.
8 months ago
Kill Chain
FBI Alert: UNC6040 & UNC6395 Target Salesforce Customers with Cloud Attacks (2024)
In early 2024, the FBI’s Internet Crime Complaint Center (IC3) issued an alert detailing active campaigns by threat groups UNC6040 and UNC6395 targeting Salesforce customer environments. The attackers leveraged phishing and social engineering to obtain valid Salesforce credentials, subsequently exploiting misconfigurations and inadequate security controls in customer cloud instances. This enabled unauthorized access to sensitive data, including customer information and corporate records, leading to multiple data theft and extortion attempts. Salesforce itself was not breached, but its customers suffered direct operational impacts due to data compromise and disruption. This incident underscores a rising trend of advanced threat actors targeting supply chain and SaaS ecosystems, exploiting both human and technical gaps in cloud security. As cloud adoption accelerates, enterprises must address credential hygiene, proper configuration, and real-time anomaly detection to thwart similar attacks.
8 months ago
Kill Chain
HybridPetya Ransomware: How Attackers Bypassed Secure Boot to Compromise UEFI
In June 2024, cybersecurity researchers uncovered a new ransomware strain called 'HybridPetya' that combines elements of the notorious Petya and NotPetya malware families. This advanced ransomware specifically targets UEFI-based systems, bypassing Secure Boot protections by leveraging sophisticated bootkit techniques. HybridPetya infiltrates environments via spear-phishing and lateral movement, then encrypts critical system files at the firmware level, effectively crippling affected organizations and creating significant hurdles for recovery. Its wiper-like capabilities echo NotPetya’s destructive impacts, raising major concerns for enterprises with critical infrastructure or legacy firmware defenses. The emergence of HybridPetya underscores an escalation in attacker sophistication, with a resurgence in supply-chain and firmware-level attacks. The incident highlights the urgent need for proactive firmware security, robust patch management, and Zero Trust architectures to counter ransomware operators increasingly weaponizing advanced, persistent threat techniques.
8 months ago
Kill Chain
Emerging Yurei Ransomware Claims First Victims in 2024
In early June 2024, a new ransomware operation identified as Yurei, reportedly originating from Morocco and named after Japanese spirits, claimed its first set of confirmed victims. The Yurei group leveraged a customized variant of the Prince-Ransomware binary, successfully breaching targets by deploying file-encrypting malware through typical ransomware vectors. Notably, researchers discovered that the malware implementation contained a technical flaw permitting partial data recovery, though this did not nullify the criminal extortion threats made against affected businesses. The attack has led to data loss, service interruption, and urgent incident response at affected organizations. This incident spotlights the evolving ransomware landscape, where new actors rapidly weaponize existing malware tools, often introducing subtle encryption modifications. Yurei’s activity shows how flaws in ransomware code do not necessarily mitigate risk, as extortion and operational disruption remain impactful. Organizations must adapt controls to defend against agile threat actors, even when exploits are imperfectly engineered.
8 months ago
Kill Chain
The FileFix Phishing Campaign: Obfuscation, Steganography, and Multilingual Threats Hit Globally
In early 2024, security researchers identified a sophisticated, widescale phishing campaign leveraging a malicious tool called FileFix. The campaign utilized advanced code obfuscation, steganography, and localization in at least 16 languages to distribute phishing payloads globally. Attackers delivered FileFix through deceptive emails and malicious attachments, successfully bypassing traditional security filters. Once executed, the malware embedded within attachments enabled remote access, data theft, and credential harvesting, affecting organizations in multiple sectors and exposing sensitive business data to potential fraud and operational disruption. FileFix highlights a new wave of phishing threats combining obfuscation, multilingual lures, and novel payload delivery. Its rapid evolution and global reach underscore the increasing sophistication of social engineering attacks, making robust detection and segmentation capabilities essential for all enterprises.
8 months ago
Kill Chain
'Vane Viper': PropellerAds Tied to 2025’s Largest Malvertising & Cybercrime Network
In September 2025, cybersecurity researchers uncovered that the 'Vane Viper' threat group had leveraged the commercial adtech platform PropellerAds to orchestrate one of the largest malvertising and cybercrime operations observed in recent years. The threat actor, active for over a decade, used compromised websites and malicious ads to funnel internet users through complex redirection chains—culminating in exploit kits, malware, ransomware, and scam campaigns. Investigations tied PropellerAds and its parent AdTech Holding, via shared infrastructure and business links, to a sprawling web of entities facilitating the operation and exposing untold numbers of enterprise and consumer users to cyber risk. This incident is particularly significant because it demonstrates the co-mingling of legitimate commercial digital ad infrastructure with cybercriminal activity, challenging the line between victimized platforms and complicit actors. The case spotlights growing regulatory and enterprise security concerns around malvertising, supply chain integrity, and weaponized ad ecosystems.
8 months ago
Kill Chain
Shai-Hulud Worm: Self-Propagating Malware Hits 180+ NPM Packages in Major Supply Chain Breach
In September 2025, a novel self-replicating worm, dubbed 'Shai-Hulud,' targeted the JavaScript NPM ecosystem by infecting over 180 code packages. The malware exploited developer authentication tokens found on Linux and macOS devices, replicating itself into the top 20 packages accessible to the compromised account and rapidly publishing malicious package versions. Stolen credentials were published in new, public GitHub repositories, compounding the supply chain risk. Though the initial infection included several packages managed by CrowdStrike, the company quickly removed the compromised code and rotated secrets, preventing wider impact to its flagship products. This incident highlights the increasing sophistication and automation of supply chain compromise, especially in open-source software development. The self-propagating nature of Shai-Hulud, combined with credential harvesting and public exposure, represents a growing risk trend for organizations relying on software registries.
8 months ago
Kill Chain
Salty2FA: The Next Wave of Enterprise Phishing-as-a-Service in 2024
In early 2024, cybersecurity researchers uncovered the Salty2FA Phishing-as-a-Service (PhaaS) kit, designed to bypass multi-factor authentication (MFA) protections for enterprise environments. The kit enables attackers to launch highly convincing phishing campaigns by emulating trusted authentication flows and harvesting credentials—including two-factor tokens—using adversary-in-the-middle proxy techniques. Salty2FA's modular architecture, scalability, and integration with encrypted communication channels make it particularly appealing to cybercriminals targeting corporate user bases. Compromised accounts can facilitate credential stuffing, lateral movement, and data exfiltration in victim organizations. This incident highlights the growing professionalization of cybercriminal groups and a trend toward sophisticated PhaaS offerings that significantly lower barriers for conducting enterprise-level breaches. Organizations should note the surge in attacks able to circumvent standard MFA and adapt their defenses accordingly.
8 months ago
Kill Chain
2024 Shai-hulud Worm: Major Supply Chain Attack Strikes NPM
In September 2024, a self-replicating malware dubbed "Shai-hulud" infiltrated the open source ecosystem by targeting hundreds of NPM (Node Package Manager) packages. The worm initiates its campaign by compromising a single software component, and automatically harvests secrets, tokens, and credentials present in affected developers' environments. By leveraging compromised NPM accounts, Shai-hulud spreads itself through subsequent package uploads, injecting malicious payloads into new releases and perpetuating a chain reaction across software supply chains. Impacted parties range from individual developers to prominent tech companies and security vendors. This incident highlights a concerning escalation in supply chain threats, demonstrating advanced automation in malware propagation and the weaponization of interconnected open source dependencies. The attack underscores the rising prevalence of highly automated, lateral-moving malware and the systemic risks posed by compromised development ecosystems.
8 months ago
Kill Chain
Raven Stealer Uses Telegram to Pilfer Chromium Data in 2024
In early 2024, security researchers identified a new infostealer variant, Raven Stealer, being distributed via underground forums and cracked software packages. The malware targets Windows systems and focuses on stealthy extraction of browser data, particularly from Chromium-based browsers such as Google Chrome. Once installed, Raven Stealer harvests credentials, cookies, browser histories, and cryptocurrency wallets before exfiltrating the data through encrypted Telegram channels. The attack exploits unmonitored endpoints and capitalizes on users’ download of pirated or repackaged software, resulting in widespread compromise of sensitive authentication data across multiple organizations. This incident underscores the ongoing evolution of commodity malware and demonstrates the sophistication with which even low-cost infostealers are leveraging encrypted communications and social engineering. As attackers continue to innovate with new TTPs and delivery vectors, organizations must strengthen endpoint monitoring and policy enforcement to reduce exposure to similar threats.
8 months ago
Kill Chain
Microsoft September 2025 Patch Tuesday: Critical Privilege Escalation Flaws Demand Immediate Action
In September 2025, Microsoft disclosed 81 security vulnerabilities across its portfolio, with a significant focus on escalation of privilege (EoP) flaws. Of the CVEs released, 38 enabled attackers to gain elevated access after initial compromise, affecting modules like SMB and NTLM. Notably, CVE-2025-55234 (SMB) and CVE-2025-54918 (NTLM)—both rated CVSS 8.8—were publicly known and considered high impact, allowing attackers to leverage relay and crafted packet attacks for system takeover. Additional critical vulnerabilities were identified in Windows UI XAML and HPC components. While no active exploitation was confirmed at release, the breadth of affected products and criticality prompted urgent patching recommendations. This wave of privilege escalation vulnerabilities underscores the ongoing risk posed by identity-based attacks and lateral movement, compelling organizations to accelerate patch deployment and strengthen segmentation controls. With the end-of-life of Windows 10 and expanded MFA mandates on the horizon, the incident reinforces the necessity for layered defenses and up-to-date asset management.
8 months ago
Kill Chain
K2 Think AI Model Jailbroken Within Hours of 2024 Release
On September 9, 2024, the UAE-backed 'K2 Think' large language model (LLM) was released with the goal of industry-leading transparent reasoning. Within hours, however, cybersecurity researchers discovered a critical vulnerability known as Partial Prompt Leakage. This flaw allowed adversaries to observe the model's internal logic in plain text, making it easier to methodically bypass safeguards and jailbreak the AI system. The exploit was demonstrated by researcher Alex Polyakov, who publicly documented how attackers could uncover and iterate against the model’s defenses, enabling harmful behaviors such as malware generation. The breach did not result in immediate large-scale misuse, but it revealed a key tradeoff between transparency and security in modern LLM development. This incident is emblematic of new AI security risks emerging as open, auditable models grow in popularity. It underscores the urgency for vendors to balance transparency with robust protection, as attackers quickly adapt to and exploit unique model features. With increased regulatory scrutiny and rising enthusiasm for open-source AI, safeguarding model reasoning is now a critical surface organizations cannot ignore.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports