The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Investment Banking/Venture
Breach intelligence, attack campaigns, and threat reports targeting the Investment Banking/Venture sector.
Explore Other Sectors
Investment Banking/Venture Threat Reports
GodRAT: New RAT Targets Financial Institutions via Skype with Evolved Tactics in 2024
In late 2024, a targeted campaign leveraged a new remote access trojan, GodRAT, to infiltrate trading and brokerage firms across Hong Kong, the UAE, and other countries. Attackers, likely linked to the Winnti APT group, distributed malicious .scr and .pif files disguised as financial documents via Skype. These files deployed GodRAT—an evolved variant of Gh0st RAT—using innovative techniques like steganography to evade detection. Once inside victim networks, the campaign used file management plugins and browser password stealers to exfiltrate sensitive credentials, while also deploying secondary implants such as AsyncRAT for persistent control. This ongoing incident highlights both the durability of legacy RAT codebases and the adaptability of threat actors employing advanced delivery and evasion tactics. It reflects a wider trend where financial institutions face persistent threats from intelligent, identity- and credential-focused attacks using proven malware frameworks.
8 months ago
Kill Chain
European Crypto Fraud Ring Dismantled After €100 Million Theft
In September 2025, European law enforcement agencies coordinated by Eurojust and Europol dismantled a cryptocurrency investment fraud ring, arresting five suspects linked to more than €100 million ($118 million) in stolen funds. The operation, spanning several countries including Spain, Portugal, Bulgaria, Italy, Lithuania, and Romania, targeted a sophisticated group that lured victims with promises of high returns through professional online platforms. Funds from over 100 victims across 23 countries were diverted into controlled accounts, masked by additional recovery fees and subsequent website takedowns, resulting in substantial losses and significant reputational damage. This incident underscores the growing scale and sophistication of crypto-based financial fraud targeting both individuals and organizations globally. The case highlights the necessity for robust fraud prevention, regulatory vigilance, and proactive threat detection in the rapidly evolving crypto investment landscape.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports