Financial Services
Breach intelligence, attack campaigns, and threat reports targeting the Financial Services sector.
Explore Other Sectors
Financial Services Threat Reports
Fake Claude App via Bing Ads Delivers SectopRAT Malware
In July 2026, a sophisticated malvertising campaign named 'FakeAgent' exploited Bing advertisements to distribute the SectopRAT malware. Attackers created a fake Claude desktop application installer, hosted on a legitimate Claude.ai domain, which was promoted through Bing ads. Unsuspecting users searching for the Claude desktop app were redirected to this malicious installer, leading to the compromise of at least 29 organizations over a two-day period. The malware, SectopRAT, is a remote access trojan with information-stealing capabilities, allowing attackers to exfiltrate sensitive data and maintain persistent access to infected systems. This incident underscores the evolving tactics of cybercriminals who leverage legitimate platforms and advertising services to disseminate malware. The use of authentic domains and sophisticated social engineering techniques highlights the need for heightened vigilance among users and organizations. It also emphasizes the importance of downloading software exclusively from official and verified sources to mitigate the risk of such deceptive attacks.
2 months ago
Kill Chain
Dolphin X Malware: AI-Powered Threat Targeting High-Value Victims
In July 2026, cybersecurity researchers identified 'Dolphin X,' a sophisticated Windows-based remote access trojan (RAT) and infostealer. This malware targets over 300 applications, including browsers, cryptocurrency wallets, password managers, and cloud command-line tools. Notably, Dolphin X incorporates an AI-powered profiling system that analyzes infected systems' application usage, browsing history, and installed software to assign risk scores. These scores enable attackers to prioritize high-value targets, such as developers with access to sensitive cloud production environments. The malware is marketed on cybercrime forums under a malware-as-a-service model, with subscription tiers offering varying levels of obfuscation and feature sets. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/new-dolphin-x-malware-uses-ai-to-rank-high-value-targets/?utm_source=openai)) The emergence of Dolphin X underscores a concerning trend: the integration of artificial intelligence into cybercriminal tools to enhance operational efficiency and target selection. This development highlights the need for organizations to bolster their cybersecurity defenses, particularly in protecting developer workstations and sensitive credentials, to mitigate the risks posed by such advanced threats.
2 months ago
Kill Chain
Russian Espionage Group Exploits Zimbra Zero-Day Vulnerability
In July 2025, the Russian state-sponsored threat group known as Laundry Bear initiated a sophisticated cyber-espionage campaign targeting Western government and commercial organizations. By exploiting a zero-day vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite's webmail client, the attackers deployed a 'view-based exploit' that activated upon merely viewing a malicious email. This allowed them to exfiltrate sensitive data, including recent emails, entire email directories, browser-saved passwords, and two-factor authentication recovery codes. The vulnerability was patched in November 2025, but unpatched systems remain at risk. ([nsa.gov](https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/4553352/nsa-and-partners-alert-zimbra-collaboration-suite-users-of-a-russian-state-supp/?utm_source=openai)) This incident underscores the persistent threat posed by state-sponsored cyber actors exploiting zero-day vulnerabilities. The use of 'zero-click' exploits, which require no user interaction beyond viewing an email, highlights the evolving sophistication of cyber threats and the critical need for timely patch management and robust cybersecurity measures. ([darkreading.com](https://www.darkreading.com/cyberattacks-data-breaches/russian-hackers-zimbra-zero-day-us-ukraine-targets?utm_source=openai))
2 months ago
Kill Chain
Origin Energy Data Breach: A Wake-Up Call for Critical Infrastructure Security
In July 2026, Origin Energy, Australia's largest energy retailer, confirmed a data breach involving unauthorized access to customer information. The compromised data includes names, addresses, dates of birth, contact numbers, account details, and partial financial information (last four digits of credit cards or last three digits of bank accounts). The company is working to determine the total number of affected customers and has engaged with the Australian Cyber Security Centre, the Australian Federal Police, and the Office of the Australian Information Commissioner to investigate the incident. ([originenergy.com.au](https://www.originenergy.com.au/about/investors-media/update-on-data-security-incident/?utm_source=openai)) This breach underscores the escalating threat of cyberattacks targeting critical infrastructure sectors. The exposure of personal information increases the risk of identity theft and sophisticated phishing scams, particularly with the rise of AI-driven cybercrime. Organizations must enhance their cybersecurity measures to protect sensitive customer data and maintain public trust. ([abc.net.au](https://www.abc.net.au/news/2026-07-24/origin-breach-could-fuel-wave-of-ai-powered-scams/106951588?utm_source=openai))
2 months ago
Kill Chain
TAG-195's Modular Malware: A New Era in Cyber Threats
In July 2026, Insikt Group identified four new malware families—TinyEgg, ChonkyChicken, a modularized variant of ChonkyChicken, and ChromEggscalator—developed by TAG-195, also known as "Golden Chickens" or "Venom Spider." These developments signify a strategic shift towards modular, operator-driven tools within the TAG-195 malware-as-a-service (MaaS) ecosystem. The modularized ChonkyChicken variant employs a controller-and-plugin architecture, allowing the base implant to dynamically load specific capability modules from attacker-controlled infrastructure, thereby reducing its static detection footprint. All four malware families exhibit consistent command-and-control mechanisms, shared persistence methods, string obfuscation, and execution via legitimate Windows binaries. This evolution underscores TAG-195's commitment to enhancing the adaptability and stealth of its offerings, catering to a diverse range of operational requirements. The emergence of these advanced, modular malware families highlights the ongoing sophistication of MaaS providers and the necessity for organizations to bolster their detection and response strategies against such evolving threats.
2 months ago
Kill Chain
LummaStealer's 2026 Resurgence: The Role of CastleLoader and ClickFix Techniques
Between December 2025 and January 2026, cybersecurity researchers observed a significant resurgence of LummaStealer infections, facilitated by the deployment of CastleLoader malware through sophisticated ClickFix social engineering techniques. Attackers lured victims to malicious websites mimicking legitimate services, where fake CAPTCHA verifications tricked users into executing malicious PowerShell commands. These commands installed CastleLoader, which subsequently delivered LummaStealer, an infostealer targeting sensitive data such as credentials, cryptocurrency wallets, and session cookies. This campaign marked a notable evolution in malware delivery methods, combining advanced loaders with deceptive social engineering tactics to bypass traditional security measures. The resurgence of LummaStealer, despite previous law enforcement disruptions, underscores the adaptability and persistence of cybercriminals. The use of CastleLoader and ClickFix techniques highlights a trend towards more sophisticated and deceptive attack vectors, emphasizing the need for continuous vigilance and advanced security protocols to protect sensitive information.
2 months ago
Kill Chain
SANDWORM_MODE: Unveiling the npm Supply Chain Attack on AI Development Tools
In February 2026, the SANDWORM_MODE malware campaign targeted the npm ecosystem by distributing 19 typosquatted packages under aliases 'official334' and 'javaorg'. Upon installation, these packages executed a multi-stage attack: initially harvesting developer credentials and environment variables, followed by deploying a malicious MCP server to compromise AI coding assistants. The malware propagated by injecting itself into GitHub repositories and CI/CD pipelines, exfiltrating sensitive data, and, if thwarted, activating a destructive fallback to erase user files. ([crowdstrike.com](https://www.crowdstrike.com/en-us/blog/denying-the-worm-sandworm-mode-and-ai-toolchain-supply-chain-attacks/?utm_source=openai)) This incident underscores the escalating sophistication of supply chain attacks, particularly those exploiting AI development tools. Organizations must enhance their security measures to detect and prevent such multi-faceted threats that blend into legitimate development workflows.
2 months ago
Kill Chain
Critical Flaws in Microsoft's Passkey Implementation Uncovered
In July 2026, security researchers identified critical vulnerabilities in Microsoft's passkey implementation within Windows 11 and Microsoft Entra ID. These flaws allowed attackers to exploit weaknesses reminiscent of traditional password attacks, enabling them to impersonate privileged users and bypass phishing-resistant multifactor authentication. The vulnerabilities were disclosed to Microsoft, which subsequently released patches to address the issues. This incident underscores the importance of thorough implementation and validation of security protocols, even when adopting advanced authentication methods like passkeys. Organizations must remain vigilant, ensuring that new technologies are deployed securely to prevent exploitation by threat actors.
2 months ago
Kill Chain
Lampion Banking Trojan Resurfaces in Portugal: A 2026 Threat Analysis
In July 2026, the Brazilian banking Trojan known as Lampion was identified in an active campaign targeting Portuguese users. The malware is disseminated through phishing emails that masquerade as financial and administrative communications, leading recipients to download malicious ZIP files. Once executed, Lampion establishes persistence, connects to a remote command-and-control server, and can inject overlays into banking websites to steal credentials. This campaign has resulted in significant data breaches and financial losses for affected individuals and organizations. The resurgence of Lampion underscores the persistent threat posed by banking Trojans, especially those leveraging social engineering tactics. Organizations must remain vigilant, as attackers continue to exploit language and cultural similarities to enhance the effectiveness of their campaigns.
2 months ago
Kill Chain
RefluXFS (CVE-2026-64600): Critical Linux Kernel XFS Vulnerability
On July 22, 2026, a critical vulnerability known as RefluXFS (CVE-2026-64600) was disclosed, affecting the Linux kernel's XFS filesystem. This flaw allows unprivileged local users to overwrite root-owned files, such as `/etc/passwd` or setuid-root binaries, by exploiting a race condition in the copy-on-write (CoW) mechanism. The exploit enables attackers to gain persistent root access without leaving traces in kernel logs, and the changes persist across reboots. Systems running Linux kernel version 4.11 or later with XFS filesystems created with `reflink=1` are vulnerable. Default installations of Red Hat Enterprise Linux, Fedora Server, and Amazon Linux are particularly at risk. ([blog.qualys.com](https://blog.qualys.com/vulnerabilities-threat-research/2026/07/22/refluxfs-a-linux-kernel-local-privilege-escalation-to-root-in-xfs-cve-2026-64600?utm_source=openai)) The RefluXFS vulnerability underscores the importance of timely patch management and system monitoring. With over 16.4 million systems potentially affected, organizations must prioritize updating their Linux distributions and implementing security measures to prevent unauthorized access and potential data breaches. ([secnews.gr](https://www.secnews.gr/en/723207/refluxfs-cve-2026-64600-linux-xfs-16m-systems/?utm_source=openai))
2 months ago
Kill Chain
Critical Authentication Bypass in Check Point SmartConsole (CVE-2026-16232) Exploited
In July 2026, Check Point identified a critical authentication bypass vulnerability (CVE-2026-16232) in its SmartConsole login process, allowing unauthenticated remote attackers to gain full administrative privileges. Exploitation requires internet access to the Management Server IP address and a configuration without Trusted Clients restrictions. Successful attacks enable modification of security policies and configurations. Check Point confirmed active exploitation affecting a limited number of customers. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-16232?utm_source=openai)) This incident underscores the escalating risks associated with exposed management interfaces and the necessity for stringent access controls. Organizations must prioritize timely patching and restrict management access to trusted IP addresses to mitigate such vulnerabilities.
2 months ago
Kill Chain
CISA Adds Critical Vulnerabilities to Known Exploited Vulnerabilities Catalog
On July 22, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added two critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: CVE-2026-16232 and CVE-2026-50522. CVE-2026-16232 is an authentication bypass vulnerability in Check Point SmartConsole, allowing unauthenticated remote attackers to gain administrative access and modify security policies. CVE-2026-50522 is a deserialization vulnerability in Microsoft SharePoint, enabling unauthorized remote code execution without authentication. Both vulnerabilities are actively exploited, posing significant risks to organizations using these platforms. The inclusion of these vulnerabilities in the KEV Catalog underscores the increasing trend of attackers targeting critical infrastructure through widely used enterprise applications. Organizations are urged to prioritize the remediation of these vulnerabilities to mitigate potential breaches and maintain compliance with security directives.
2 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports