Executive Summary
In the first half of 2026, cybercriminals executed sophisticated campaigns exploiting trusted systems to deliver malware. One campaign involved compromised corporate email accounts sending legitimate-looking business emails with malicious attachments, leading to banking malware that manipulated proxy settings and browser extensions to intercept financial transactions. Another campaign utilized a Rust-based clipboard hijacker that monitored and replaced cryptocurrency wallet addresses copied to the clipboard, redirecting funds to attacker-controlled wallets. These incidents highlight a shift towards attacks that exploit existing trust mechanisms, making detection and prevention more challenging. Organizations must enhance their security measures to monitor for unusual activities within trusted workflows and educate users on verifying transaction details to mitigate such threats.
Why This Matters Now
These incidents underscore the evolving tactics of cybercriminals who are increasingly exploiting trusted systems and workflows to execute attacks. As these methods become more prevalent, it is imperative for organizations to adapt their security strategies to detect and prevent such sophisticated threats.
Attack Path Analysis
Attackers compromised corporate mailboxes to send phishing emails with malicious attachments. Upon opening, these attachments executed JavaScript droppers that initiated PowerShell scripts, leading to the deployment of shellcode loaders. The malware then modified proxy settings and installed browser add-ons to intercept and manipulate banking sessions, facilitating unauthorized transactions.
Kill Chain Progression
Initial Compromise
Description
Attackers gained access to corporate mailboxes and sent phishing emails with malicious attachments to target users.
MITRE ATT&CK® Techniques
Spearphishing Attachment
JavaScript
PowerShell
Process Injection
Browser Session Hijacking
Proxy
Modify Registry
System Binary Proxy Execution: Rundll32
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure that all system components and software are protected from known vulnerabilities by installing applicable security patches.
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity and Access Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Banking/Mortgage
Primary target of banking malware campaigns using compromised emails, proxy manipulation, and browser extensions to hijack banking sessions and financial transactions.
Financial Services
High risk from cryptocurrency theft campaigns using clipboard hijacking, blockchain C2 infrastructure, and wallet address replacement targeting financial transaction workflows.
Computer Software/Engineering
Critical exposure through compromised corporate mailboxes enabling malware delivery chains, requiring enhanced email security and endpoint protection against JavaScript/PowerShell staging attacks.
Insurance
Vulnerable to business email compromise leveraging legitimate accounts for malware distribution, affecting claims processing and customer communication channels with regulatory compliance implications.
Sources
- Real emails, hijacked payments: Two H1 2026 attack chainshttps://www.bleepingcomputer.com/news/security/real-emails-hijacked-payments-two-h1-2026-attack-chains/Verified
- TrojanDropper:Win32/Gepys threat descriptionhttps://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=TrojanDropper%3AWin32%2FGepysVerified
- New clipper malware steals US$400,000 in cryptocurrencies via fake Tor Browserhttps://www.kaspersky.com/about/press-releases/new-clipper-malware-steals-us400000-in-cryptocurrencies-via-fake-tor-browserVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-based access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to exploit compromised mailboxes to distribute malicious attachments would likely be constrained, reducing the reach of phishing campaigns.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges through malicious scripts would likely be constrained, reducing the scope of unauthorized access.
Control: East-West Traffic Security
Mitigation: The attacker's ability to move laterally within the network would likely be constrained, reducing the reach of the malware.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish command and control channels would likely be constrained, reducing the scope of external communications.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate sensitive data would likely be constrained, reducing the scope of data loss.
The attacker's ability to conduct unauthorized transactions would likely be constrained, reducing the financial impact.
Impact at a Glance
Affected Business Functions
- Online Banking Services
- Payment Processing
- Cryptocurrency Transactions
Estimated downtime: 7 days
Estimated loss: $400,000
Customer financial data, including bank account details and cryptocurrency wallet addresses.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement and limit the spread of malware within the network.
- • Deploy East-West Traffic Security controls to monitor and control internal traffic, detecting unauthorized communications.
- • Utilize Threat Detection & Anomaly Response systems to identify and respond to unusual activities, such as unauthorized proxy modifications.
- • Enforce Egress Security & Policy Enforcement to prevent unauthorized data exfiltration and access to malicious external servers.
- • Apply Multicloud Visibility & Control to gain comprehensive insights into network activities across different cloud environments, enhancing threat detection capabilities.



