✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Investment Banking/Venture
Breach intelligence, attack campaigns, and threat reports targeting the Investment Banking/Venture sector.
Explore Other Sectors
Investment Banking/Venture Threat Reports
Balancer DeFi Protocol Hit by $128M Crypto Heist: How the 2023 Breach Happened
In August 2023, the Balancer DeFi protocol suffered a sophisticated cyberattack when unidentified hackers exploited vulnerabilities in its v2 pools’ smart contract logic. By manipulating pool configurations and utilizing flash loans, attackers drained over $128 million worth of cryptocurrency assets. Balancer immediately paused affected pools, notified users, and worked to contain losses. The exploit drew industry-wide concern due to the depth and speed of the attack, which bypassed several security checks and resulted in substantial losses for protocol users and liquidity providers. This incident underscores the growing security challenges facing decentralized finance platforms, as attackers increasingly target smart contracts and protocol logic. The Balancer breach highlights the need for advanced anomaly detection, smart contract auditing, and zero trust security controls in Web3 environments as DeFi adoption accelerates.
6 months ago
Kill Chain
Inside the GhostCall & GhostHire Malware Campaigns: BlueNoroff’s 2025 Cryptocurrency Heists
In October 2025, cybersecurity researchers uncovered new attack chains, GhostCall and GhostHire, attributed to BlueNoroff—a sub-group of North Korea's Lazarus Group—targeting the Web3 and blockchain sectors. The campaigns form part of SnatchCrypto, an ongoing operation active since 2017, characterized by sophisticated spear-phishing, malware-laden documents, and social engineering tactics to infiltrate cryptocurrency firms and financial technology startups. Once initial access is gained, attackers deploy custom malware, bypass defenses, and ultimately exfiltrate sensitive data and digital assets, resulting in significant cryptocurrency thefts and disruption across targeted organizations. This campaign is especially concerning amid a surge of advanced persistent threats exploiting trust gaps in rapidly evolving blockchain and cryptocurrency environments. Regulators and cybersecurity teams are on high alert as major financial losses and reputational impacts drive urgency for improved controls, detection, and Zero Trust strategies.
6 months ago
Kill Chain
Fake Nethereum NuGet Package Exploited Homoglyph Trick in 2025 Supply Chain Attack
In October 2025, cybersecurity experts identified a sophisticated supply chain attack wherein a malicious NuGet package, imitating the popular Nethereum library using a homoglyph trick, was uploaded to compromise .NET developers. The attacker distributed a typosquatted package ('Netherеum.All') containing encoded command-and-control (C2) communication that secretly harvested and exfiltrated sensitive cryptocurrency wallet credentials—including private keys and mnemonic phrases—from unsuspecting developers’ systems. The campaign demonstrates a heightened level of precision in leveraging open-source repositories for credential theft, with potential widespread financial impacts for organizations developing blockchain solutions. This incident exemplifies the rapidly increasing risk posed by supply chain attacks exploiting trusted software ecosystems. It highlights both a surge in homoglyph-based typosquatting and a broader trend of targeting cryptocurrency assets via development toolchains—emphasizing the need for robust code provenance controls and package vetting.
6 months ago
Kill Chain
Officials Dismantle Major Southeast Asia Cybercrime Network in $15B Bitcoin Seizure
In early 2024, federal authorities from the U.S. and U.K. conducted a large-scale operation against Southeast Asia cybercrime networks, seizing 127,271 Bitcoins worth approximately $15 billion from Chen Zhi, the alleged head of the Prince Group based in Cambodia. The Prince Group, operating since 2015, is accused of running transnational scam compounds utilizing human trafficking and forced labor to enact wide-reaching financial fraud across over 30 countries, including the U.S. where a Brooklyn network victimized more than 250 individuals. The operation resulted in sanctions on 146 people and organizations, the severing of Huione Group from the U.S. financial system, and the dismantling of 117 illicit Prince Group-affiliated businesses. This record-breaking crackdown underscores the severity and international scale of cyber-enabled financial fraud, money laundering, and the role of organized crime groups leveraging technology across borders. The incident highlights growing regulatory and enforcement focus, as well as the evolving threat posed by sophisticated scam and laundering operations exploiting multi-region financial networks.
6 months ago
Kill Chain
US Seizes $15B in Crypto from Global 'Pig Butchering' Syndicate
In October 2025, the U.S. Department of Justice seized $15 billion in bitcoin from the leader of the Prince Group, a transnational criminal organization responsible for orchestrating large-scale cryptocurrency investment scams, widely known as 'pig butchering.' Operating from Cambodia since 2015, Prince Group exploited social media, dating apps, and messaging platforms to lure victims into fraudulent investment schemes, funneling billions via complex laundering tactics and a vast network of shell companies in over 30 countries. The syndicate trafficked and forced thousands into labor-intensive scam compounds, evading law enforcement and leveraging bribery, automated call centers, and violence. The stolen funds were laundered and spent on luxury assets and high-value goods. The Prince Group incident underscores the escalating threat of organized cyber-enabled financial fraud, particularly those leveraging cryptocurrency to obfuscate illicit gains. Despite large-scale law enforcement crackdowns, similar tactics—ranging from romance baiting to advanced obfuscation—have proliferated globally, highlighting persistent regulatory and security challenges for fintech and law enforcement agencies.
6 months ago
Kill Chain
UK’s £5.5B Bitcoin Seizure: ‘Bitcoin Queen’ Convicted in Landmark Crypto Laundering Case
In September 2025, UK authorities secured a conviction in the world’s largest cryptocurrency seizure, arresting Zhimin Qian, also known as "Bitcoin Queen," for orchestrating a multi-billion pound fraudulent Bitcoin investment scheme between 2014 and 2017. Promising returns of up to 300%, Qian defrauded over 128,000 victims in China, amassing 40 billion yuan, which she later converted into Bitcoin and laundered through the UK after fleeing China. Metropolitan Police seized 61,000 Bitcoin—worth over £5.5 billion today—after a complex multi-year investigation involving international law enforcement and property laundering attempts. This landmark case highlights both the scale and sophistication of modern financial cybercrime, underscoring the growing global focus on cryptocurrency abuse for money laundering. As regulators and law enforcement agencies adapt, similar techniques threaten new sectors and jurisdictions, making robust compliance, asset tracing, and cross-border cooperation critical in cyber risk management.
6 months ago
Kill Chain
GitHub Notification Phishing Abuses Y Combinator Brand for Crypto Theft (2025)
In September 2025, a widespread phishing campaign exploited GitHub's notification system to target software developers for cryptocurrency theft. Attackers impersonated the reputable startup accelerator Y Combinator and generated hundreds of fake issue notifications across GitHub repositories, tagging users to trigger authentic-looking emails. Victims were lured to a spoofed Y Combinator website with a subtle domain misspelling, where they were prompted to connect cryptocurrency wallets for 'verification.' Behind the scenes, obfuscated scripts authorized malicious transactions, draining wallets once users signed in. The fraudulent repositories were quickly reported and taken down, but it's unclear how many users suffered financial losses. This attack highlights the growing trend of threat actors leveraging trusted platforms for sophisticated social engineering, particularly as notification-based phishing campaigns increase and cryptocurrency remains a lucrative target. The evolving tactics underscore the urgent necessity for enhanced vigilance, technical controls, and authentication checks across digital collaboration tools.
6 months ago
Kill Chain
Interpol's 2024 Crackdown: $439 Million Seized from Global Cybercrime Networks
In 2024, Interpol coordinated a global operation targeting cybercrime rings responsible for large-scale financial crimes. Over a period of five months, law enforcement agencies from 61 countries worked together to investigate and disrupt online scams that included business email compromise (BEC), investment fraud, romance scams, and e-commerce fraud. The operation resulted in the seizure of more than $439 million in cash and cryptocurrency, exposing elaborate money laundering networks and identifying approximately 1,300 suspects linked to cyber-enabled financial crime groups. Thousands of victims worldwide were impacted by these schemes. This incident highlights the growing sophistication and international reach of financially motivated cybercrime, as well as the increasingly effective law enforcement collaborations to disrupt illicit networks. The operation reflects a heightened urgency for organizations to strengthen controls against online fraud and cyber-enabled theft, as attackers continually evolve their tactics.
6 months ago
Kill Chain
Eurojust 2025: €100M Cryptocurrency Fraud Unraveled Across 23 Countries
In September 2025, Eurojust and European law enforcement agencies coordinated the arrest of five individuals linked to an extensive cryptocurrency investment fraud ring that defrauded victims of over €100 million ($118 million) across at least 23 countries. Operating mainly out of Spain, Portugal, Italy, Romania, and Bulgaria, the suspects lured victims with promises of high returns from fake crypto investment platforms before illegally transferring funds using sophisticated laundering channels. The campaign targeted high-net-worth individuals in France, Germany, Italy, and Spain, and the operation included simultaneous raids and seizures of assets, including bank accounts and electronic devices. This case highlights the persistent threat of cross-border financial crimes leveraging digital currencies and online investment schemes. The complexity and scale of the operation reflect a broader shift towards technology-enabled fraud, making swift international law enforcement collaboration and strong cyber defense practices more critical than ever.
- Investment Banking/Venture
- Capital Markets/Hedge Fund/Private Equity
- Investment Management/Hedge Fund/Private Equity
6 months ago
Kill Chain
GodRAT: New RAT Targets Financial Institutions via Skype with Evolved Tactics in 2024
In late 2024, a targeted campaign leveraged a new remote access trojan, GodRAT, to infiltrate trading and brokerage firms across Hong Kong, the UAE, and other countries. Attackers, likely linked to the Winnti APT group, distributed malicious .scr and .pif files disguised as financial documents via Skype. These files deployed GodRAT—an evolved variant of Gh0st RAT—using innovative techniques like steganography to evade detection. Once inside victim networks, the campaign used file management plugins and browser password stealers to exfiltrate sensitive credentials, while also deploying secondary implants such as AsyncRAT for persistent control. This ongoing incident highlights both the durability of legacy RAT codebases and the adaptability of threat actors employing advanced delivery and evasion tactics. It reflects a wider trend where financial institutions face persistent threats from intelligent, identity- and credential-focused attacks using proven malware frameworks.
6 months ago
Kill Chain
European Crypto Fraud Ring Dismantled After €100 Million Theft
In September 2025, European law enforcement agencies coordinated by Eurojust and Europol dismantled a cryptocurrency investment fraud ring, arresting five suspects linked to more than €100 million ($118 million) in stolen funds. The operation, spanning several countries including Spain, Portugal, Bulgaria, Italy, Lithuania, and Romania, targeted a sophisticated group that lured victims with promises of high returns through professional online platforms. Funds from over 100 victims across 23 countries were diverted into controlled accounts, masked by additional recovery fees and subsequent website takedowns, resulting in substantial losses and significant reputational damage. This incident underscores the growing scale and sophistication of crypto-based financial fraud targeting both individuals and organizations globally. The case highlights the necessity for robust fraud prevention, regulatory vigilance, and proactive threat detection in the rapidly evolving crypto investment landscape.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports