The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Investment Banking/Venture
Breach intelligence, attack campaigns, and threat reports targeting the Investment Banking/Venture sector.
Explore Other Sectors
Investment Banking/Venture Threat Reports
Kaspersky Uncovers 26 Fake Crypto Wallet Apps on Apple App Store
In April 2026, Kaspersky identified 26 fraudulent applications on the Apple App Store that impersonated popular cryptocurrency wallets such as MetaMask, Ledger, and Coinbase. These apps redirected users to phishing pages mimicking the App Store, leading to the installation of trojanized wallet applications designed to steal recovery phrases and private keys, thereby draining users' cryptocurrency holdings. The campaign, active since at least fall 2025, is attributed with moderate confidence to the threat actors behind SparkKitty. ([kaspersky.co.uk](https://www.kaspersky.co.uk/about/press-releases/kaspersky-finds-26-fake-crypto-wallet-apps-on-apples-app-store-that-can-drain-digital-assets?utm_source=openai)) This incident underscores the evolving sophistication of cyber threats targeting cryptocurrency users, highlighting the need for heightened vigilance and robust security measures. The exploitation of trusted platforms like the Apple App Store for distributing malicious apps signifies a concerning trend in cybercriminal tactics.
5 months ago
Kill Chain
Lazarus Group's 'ClickFix' Campaign: A Wake-Up Call for macOS Security
In April 2026, North Korea's Lazarus Group initiated a cyberattack campaign targeting macOS users in the fintech and cryptocurrency sectors. Utilizing a social engineering technique known as 'ClickFix,' attackers impersonated trusted contacts to send fake online meeting invitations via platforms like Telegram. Victims were deceived into executing malicious commands in their macOS Terminal, leading to the installation of a malware toolkit named 'Mach-O Man.' This malware facilitated credential theft, system profiling, and data exfiltration, compromising corporate systems and financial resources. This incident underscores the evolving sophistication of state-sponsored cyber threats, particularly against macOS platforms previously considered less vulnerable. The use of social engineering tactics like ClickFix highlights the critical need for organizations to enhance user awareness and implement robust security measures to mitigate such deceptive attack vectors.
5 months ago
Kill Chain
Robinhood Account Creation Flaw Exploited for Phishing Attacks
In April 2026, threat actors exploited a flaw in Robinhood's account creation process to send phishing emails from the legitimate noreply@robinhood.com address. By embedding malicious HTML into device metadata fields during account registration, attackers generated emails alerting users to 'unrecognized device' logins, prompting them to click on links leading to credential-stealing phishing sites. This method bypassed standard email security checks, making the phishing attempts highly convincing. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/robinhood-account-creation-flaw-abused-to-send-phishing-emails/?utm_source=openai)) This incident underscores the evolving sophistication of phishing tactics, particularly those leveraging legitimate communication channels to deceive users. Organizations must continuously assess and fortify their email security protocols to prevent similar exploits.
5 months ago
Kill Chain
FakeWallet Campaign: Crypto-Stealing Apps Infiltrate China's Apple App Store
In April 2026, a campaign named 'FakeWallet' was discovered, involving 26 malicious applications on China's Apple App Store that impersonated popular cryptocurrency wallets like Metamask, Coinbase, Trust Wallet, and OneKey. These apps were designed to steal users' recovery or seed phrases, enabling attackers to drain cryptocurrency assets. The threat actors employed typosquatting and fake branding to deceive users into downloading these apps, which were disguised as games or calculator applications to circumvent regional restrictions. Upon installation, the apps redirected users to phishing sites that mimicked legitimate crypto services, prompting them to download trojanized wallet apps via iOS provisioning profiles. These malicious apps intercepted mnemonic phrases during wallet setup or recovery processes, encrypted them, and transmitted the data to the attackers, facilitating unauthorized access to victims' cryptocurrency funds. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/chinas-apple-app-store-infiltrated-by-crypto-stealing-wallet-apps/?utm_source=openai)) This incident underscores a growing trend of sophisticated cyber threats targeting cryptocurrency users through official app stores, highlighting the need for enhanced vigilance and security measures. The use of legitimate enterprise features like iOS provisioning profiles for malicious purposes indicates an evolution in attack vectors, emphasizing the importance of continuous monitoring and user education to mitigate such risks.
5 months ago
Kill Chain
KelpDAO's $290 Million DeFi Breach: A Wake-Up Call for Cross-Chain Security
In April 2026, KelpDAO, a decentralized finance (DeFi) platform, suffered a significant security breach resulting in the theft of approximately $290 million worth of rsETH tokens. The attackers exploited vulnerabilities in KelpDAO's cross-chain bridge, specifically targeting the verification layer by compromising remote procedure call (RPC) nodes. This manipulation allowed them to forge cross-chain messages and illicitly transfer funds. Preliminary investigations attribute the attack to North Korea's state-sponsored Lazarus Group, known for sophisticated cyber operations targeting financial institutions. This incident underscores the critical importance of robust security configurations in DeFi platforms, particularly concerning cross-chain interoperability. The reliance on a single-verifier setup without redundancy exposed KelpDAO to this exploit. As DeFi continues to evolve, ensuring multi-layered security measures and adhering to best practices in system architecture are imperative to mitigate such risks.
5 months ago
Kill Chain
FakeWallet Crypto Stealer: A New Threat in the Apple App Store
In March 2026, over twenty phishing apps masquerading as popular cryptocurrency wallets were discovered on the Apple App Store. These malicious applications redirected users to browser pages resembling the App Store, distributing trojanized versions of legitimate wallets designed to steal recovery phrases and private keys. Metadata indicates this campaign has been active since at least late 2025. ([securelist.com](https://securelist.com/fakewallet-cryptostealer-ios-app-store/119482/?utm_source=openai)) This incident underscores the evolving tactics of cybercriminals targeting cryptocurrency users, highlighting the need for enhanced vigilance and security measures within app marketplaces to prevent such deceptive practices.
5 months ago
Kill Chain
Operation Atlantic 2026: A Landmark in Combating Cryptocurrency Fraud
In March 2026, Operation Atlantic, a collaborative effort led by the UK's National Crime Agency (NCA) alongside the U.S. Secret Service, Ontario Provincial Police, and Ontario Securities Commission, targeted cryptocurrency fraud across the UK, Canada, and the United States. The operation identified over 20,000 victims and froze more than $12 million in suspected criminal proceeds obtained through 'approval phishing' scams, where victims were deceived into granting access to their cryptocurrency wallets. Additionally, the operation uncovered over $45 million in stolen cryptocurrency linked to global fraud schemes. ([nationalcrimeagency.gov.uk](https://www.nationalcrimeagency.gov.uk/news/fraudsters-targeting-cryptocurrency-stopped-and-12-million-frozen-in-nca-led-operation-atlantic?utm_source=openai)) This incident underscores the escalating threat of sophisticated phishing attacks in the cryptocurrency sector, highlighting the necessity for enhanced security measures and international cooperation to protect digital assets. The success of Operation Atlantic demonstrates the effectiveness of public-private partnerships in combating cybercrime and sets a precedent for future collaborative efforts to safeguard investors and maintain trust in the cryptocurrency market.
5 months ago
Kill Chain
Drift Protocol's $285 Million Loss: A Wake-Up Call for Crypto Security
On April 1, 2026, Drift Protocol, a Solana-based decentralized exchange, suffered a significant security breach resulting in the theft of approximately $285 million in various cryptocurrencies. The attackers employed a sophisticated social engineering campaign over six months, culminating in the compromise of administrative controls through the exploitation of durable nonces. This allowed them to manipulate governance mechanisms and execute unauthorized transactions, leading to substantial financial losses and operational disruption for Drift Protocol. This incident underscores the escalating threat posed by state-sponsored cyber actors, particularly those from the Democratic People's Republic of Korea (DPRK), who have increasingly targeted the cryptocurrency sector to fund national programs. The attack highlights the critical need for robust operational security measures, including stringent access controls and vigilant monitoring of administrative activities, to mitigate the risks associated with social engineering and insider threats.
5 months ago
Kill Chain
Drift Protocol's $280 Million Loss: A Case Study in Advanced Cyber Attacks
In April 2026, Drift Protocol, a decentralized finance platform on the Solana blockchain, suffered a significant security breach resulting in the loss of approximately $280 million. The attackers employed a sophisticated strategy involving durable nonce accounts and pre-signed transactions to gain unauthorized administrative control over Drift's Security Council. This method allowed them to execute malicious transactions at a predetermined time, effectively transferring control and draining funds from the platform. Notably, the breach did not exploit any vulnerabilities in Drift's smart contracts or programs, and no seed phrases were compromised. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/drift-loses-280-million-north-korean-hackers-seize-security-council-powers/?utm_source=openai)) This incident underscores the evolving tactics of cybercriminals targeting the cryptocurrency sector, particularly the use of social engineering and advanced transaction manipulation techniques. The attribution to North Korean state-sponsored actors highlights the persistent threat posed by nation-state cyber operations in the digital asset space. Organizations must remain vigilant and enhance their security protocols to mitigate such sophisticated attacks.
5 months ago
Kill Chain
Drift Protocol's $285 Million Exploit: A Case Study in DeFi Vulnerabilities
On April 1, 2026, Solana-based decentralized exchange Drift Protocol suffered a significant security breach resulting in the loss of approximately $285 million. The attackers employed a sophisticated strategy involving the creation of a fictitious asset, CarbonVote Token (CVT), which was manipulated to appear as legitimate collateral through wash trading and oracle exploitation. Utilizing pre-signed durable nonce transactions and social engineering tactics, the attackers gained unauthorized access to Drift's administrative controls, enabling them to list CVT as valid collateral and remove withdrawal limits. This allowed for rapid, large-scale withdrawals of genuine assets, including USDC, SOL, and JLP tokens, within a 12-minute window. The stolen funds were swiftly bridged to Ethereum, complicating recovery efforts. ([trmlabs.com](https://www.trmlabs.com/resources/blog/north-korean-hackers-attack-drift-protocol-in-285-million-heist?utm_source=openai)) This incident underscores the evolving threat landscape in decentralized finance (DeFi), highlighting the vulnerabilities associated with governance mechanisms, oracle dependencies, and administrative controls. The use of durable nonce transactions and social engineering reflects a trend towards more complex and coordinated attacks targeting DeFi platforms. Additionally, the suspected involvement of North Korean state-sponsored actors emphasizes the geopolitical dimensions of cyber threats in the cryptocurrency sector. ([thehackernews.com](https://thehackernews.com/2026/04/drift-loses-285-million-in-durable.html?utm_source=openai))
5 months ago
Kill Chain
Drift Protocol's $280 Million Admin Takeover Exploit in 2026
In April 2026, Drift Protocol, a Solana-based decentralized finance (DeFi) platform, suffered a significant security breach resulting in the loss of approximately $280 million. The attacker employed a sophisticated strategy involving durable nonce accounts and pre-signed transactions to gain unauthorized administrative control over Drift's Security Council. This method allowed the execution of malicious transactions at a predetermined time, leading to the rapid transfer of administrative powers and subsequent draining of funds. Notably, the breach did not exploit any vulnerabilities in Drift's smart contracts or programs, and there was no compromise of seed phrases. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/drift-loses-280-million-as-hackers-seize-security-council-powers/?utm_source=openai)) This incident underscores the evolving nature of cyber threats targeting DeFi platforms, highlighting the need for enhanced security measures beyond traditional smart contract audits. The use of advanced techniques such as durable nonces and social engineering to manipulate governance structures presents a new challenge for the industry, emphasizing the importance of robust administrative controls and vigilant monitoring to prevent similar exploits.
5 months ago
Kill Chain
Casbaneiro Banking Trojan's 2026 Campaign: A Wake-Up Call for Financial Cybersecurity
In early 2026, the Brazilian cybercrime group known as Augmented Marauder launched a sophisticated phishing campaign targeting Spanish-speaking users across Latin America and Europe. Utilizing the Horabot malware, they distributed the Casbaneiro banking trojan through deceptive emails containing password-protected PDFs. Once executed, Casbaneiro monitored victims' online banking activities, capturing credentials and facilitating unauthorized financial transactions. The campaign's worm-like propagation via compromised email accounts significantly amplified its reach and impact. This incident underscores the evolving tactics of cybercriminals in deploying banking trojans, highlighting the need for enhanced email security measures and user awareness. The use of dynamic PDF lures and self-propagating malware reflects a broader trend of increasingly sophisticated phishing techniques aimed at financial institutions and their customers.
5 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports