Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 39 results
Active filter:tag: #financial-services✕ clear
StreamRat Android Banking Trojan Spread via Meta Ads to EU Usershighperson_alertThreat Actor
person_alertThreat Actor

StreamRat Android Banking Trojan Spread via Meta Ads to EU Users

ThreatFabric is the cybersecurity research firm that discovered and analyzed the StreamRat campaign. The actual threat actor behind StreamRat remains unattributed.

Meta2 Sep · 10:22 UTC
Dark Web Service Sells 153M+ Driver Licenses from Identity Verification Breachcriticalperson_alertThreat Actor
person_alertThreat Actor

Dark Web Service Sells 153M+ Driver Licenses from Identity Verification Breach

The threat actor operates "Nexus," a dark web identity theft service launched on the Russian cybercrime forum Exploit in August 2025. The operator claims to have continuously exfiltrated data for over a year from an alleged breach at a major Louisian…

identity verification company based in Louisiana1 Sep · 20:40 UTC
Breeze Comet Targets Brazilian Financial Sector for Payment Fraudhighperson_alertThreat Actor
person_alertThreat Actor

Breeze Comet Targets Brazilian Financial Sector for Payment Fraud

Breeze Comet (formerly UNC5669, overlaps with Plump Spider and SHADOW-AETHER-064) is a financially motivated threat actor operating out of Brazil since September 2023.

The Hacker News1 Sep · 15:19 UTC
Venezuelan ATM Jackpotting Group Targets U.S. Financial Infrastructurehighperson_alertThreat Actor
person_alertThreat Actor

Venezuelan ATM Jackpotting Group Targets U.S. Financial Infrastructure

This threat actor is a coordinated group of Venezuelan nationals conducting ATM jackpotting operations targeting financial institutions in the United States.

BleepingComputer1 Sep · 07:15 UTC
19 malicious Chrome/Edge extensions drain crypto wallets via auto-updateshighbug_reportVulnerability
bug_reportVulnerability

19 malicious Chrome/Edge extensions drain crypto wallets via auto-updates

19 browser extensions (18 Chrome, 1 Edge) published since February 2024, with "Enable Right Click & Copy — Smart Unlock + OCR" having 80,000 installs. Extensions either created by threat actor or purchased from legitimate owners.

Google28 Aug · 13:27 UTC
INTERPOL Operation Jackal IV Targets Black Axe and West African Crimehighperson_alertThreat Actor
person_alertThreat Actor

INTERPOL Operation Jackal IV Targets Black Axe and West African Crime

Black Axe and associated West African organized crime groups are transnational criminal networks responsible for a significant share of global cyber-enabled financial fraud.

The Hacker News26 Aug · 05:54 UTC
Zombie Card attack revives expired Visa contactless cards via NFC relayhighbug_reportVulnerability
bug_reportVulnerability

Zombie Card attack revives expired Visa contactless cards via NFC relay

Visa contactless credit cards using Kernel 3 specification. Attack requires physical card access or sustained NFC proximity, plus relay device between card and terminal. Five major US banks tested; three confirmed vulnerable with varying policies.

Visa20 Aug · 10:01 UTC
€30M Bank Fraud via Service Provider Exploit Targets Commerzbankhighperson_alertThreat Actor
person_alertThreat Actor

€30M Bank Fraud via Service Provider Exploit Targets Commerzbank

An unknown cybercriminal group, financially motivated, conducted a coordinated bank fraud operation targeting Commerzbank customers. The group operated across multiple jurisdictions, with four members arrested in Brazil and three charged in Europe.

Commerzbank14 Aug · 16:04 UTC
WindRelay NFC relay malware + SpyNote RAT steal cards, take loanshighbug_reportVulnerability
bug_reportVulnerability

WindRelay NFC relay malware + SpyNote RAT steal cards, take loans

Android devices in Czechia, Slovakia, and Slovenia. WindRelay NFC relay malware deployed alongside SpyNote RAT (and variants SpyMax, CypherRAT). 24 WindRelay samples identified on VirusTotal from November 2025 to July 2026.

BleepingComputer12 Aug · 20:22 UTC
UNC6671 Conducts Vishing Attacks to Steal SaaS Credentialshighperson_alertThreat Actor
person_alertThreat Actor

UNC6671 Conducts Vishing Attacks to Steal SaaS Credentials

UNC6671 is a financially motivated data extortion group that emerged in early January 2026. The actor operates multiple extortion brands including Redact, Pink (CL-CRI-1147), Helix, and Falcon (CL-CRI-1182), and previously operated under the BlackFil…

The Hacker News7 Aug · 16:16 UTC
UNC6671 extortion group targets financial sector via vishing attackshighperson_alertThreat Actor
person_alertThreat Actor

UNC6671 extortion group targets financial sector via vishing attacks

UNC6671 is a financially motivated extortion group tracked by Google Threat Intelligence Group (GTIG) that operates under multiple public brands including BlackFile, Redact, Pink, Helix, and Falcon.

BleepingComputer6 Aug · 18:07 UTC
Poipet Scam Network Leveraged ChatGPT for Multi-Scheme Fraud Operationshighperson_alertThreat Actor
person_alertThreat Actor

Poipet Scam Network Leveraged ChatGPT for Multi-Scheme Fraud Operations

The Poipet scam network is a Cambodia-based organized criminal operation originating from Poipet, a city with extensive ties to scam compounds and human trafficking.

OpenAI5 Aug · 16:33 UTC
COLDCARD wallet RNG flaw exploited to steal $88.6M in Bitcoincriticalbug_reportVulnerability
bug_reportVulnerability

COLDCARD wallet RNG flaw exploited to steal $88.6M in Bitcoin

COLDCARD hardware wallets: Mk2/Mk3 firmware 4.0.1-4.1.9, Mk4/Mk5 before 5.6.0 (standard) or 6.6.0X (Edge), Q devices before 1.5.0Q (standard) or 6.6.0QX (Edge). Seeds generated using the flawed RNG are compromised.

COLDCARD2 Aug · 19:14 UTC
Coldcard wallet PRNG flaw enabled $70M Bitcoin theft in 41 minutescriticalbug_reportVulnerability
bug_reportVulnerability

Coldcard wallet PRNG flaw enabled $70M Bitcoin theft in 41 minutes

Coldcard hardware wallets (Coinkite): Mk2 and Mk3 firmware 4.0.0–4.1.9 (fixed in 4.2.0); Mk4 and Mk5 before 5.6.0; Q model before 1.5.0Q; Edge builds before 6.6.0X (Mk4/Mk5) and 6.6.0QX (Q).

Coinkite1 Aug · 15:17 UTC
Fraudulent Sparrow Wallet App on Apple App Store Steals $1.8M in Bitcoinhighperson_alertThreat Actor
person_alertThreat Actor

Fraudulent Sparrow Wallet App on Apple App Store Steals $1.8M in Bitcoin

The threat actor behind this campaign remains unidentified. The operation involved publishing fraudulent cryptocurrency wallet applications on Apple's App Store that impersonated the legitimate Sparrow Wallet.

Apple27 Jul · 15:29 UTC
SourTrade Campaign Delivers Malware via Browser-Assembled Executableshighperson_alertThreat Actor
person_alertThreat Actor

SourTrade Campaign Delivers Malware via Browser-Assembled Executables

SourTrade is a malvertising campaign (not a named threat actor group) operating since late 2024. The campaign impersonates legitimate trading platforms—TradingView, Solana, and Luno—to distribute malware to retail traders and cryptocurrency investors…

Bun25 Jul · 16:48 UTC
Malvertising campaign targets crypto users with in-memory malware assemblyhighbug_reportVulnerability
bug_reportVulnerability

Malvertising campaign targets crypto users with in-memory malware assembly

Users of Solana, Luno, and TradingView platforms targeted via malicious advertisements. Campaign uses fake webpages that deliver JavaScript-based malware assembled directly in browser memory, affecting users across all platforms and browsers.

Solana25 Jul · 13:21 UTC
Insurance phishing evolves to real-time account hijacking via OTP relayhighbug_reportVulnerability
bug_reportVulnerability

Insurance phishing evolves to real-time account hijacking via OTP relay

Insurance providers globally, with primary focus on Saudi Arabia; additional activity in Europe, US, and India. Affects customers of multiple insurance brands using online portals for policy management, claims, and payments.

The Hacker News25 Jul · 08:14 UTC
Malicious npm and PyPI packages impersonate Paysafe payment SDKshighbug_reportVulnerability
bug_reportVulnerability

Malicious npm and PyPI packages impersonate Paysafe payment SDKs

Developers using npm and PyPI repositories who may have installed counterfeit packages impersonating Paysafe, Skrill, and Neteller payment SDKs. Affects development environments and potentially downstream applications integrating these malicious pack…

Paysafe8 Jul · 17:54 UTC
RedWing Android MaaS enables bank fraud via credential thefthighbug_reportVulnerability
bug_reportVulnerability

RedWing Android MaaS enables bank fraud via credential theft

Android devices targeted by RedWing malware, distributed as Malware-as-a-Service on Telegram. Variant of Oblivion MaaS. Primarily affects banking applications and users with compromised devices.

The Hacker News7 Jul · 15:10 UTC
Ousaban banking trojan targets Spain and Portugal via phishinghighbug_reportVulnerability
bug_reportVulnerability

Ousaban banking trojan targets Spain and Portugal via phishing

Windows users in Spain and Portugal. Ousaban banking trojan campaign using fake PDF lures with geolocation filtering and steganography techniques. No specific product vulnerability; threat actor campaign identified by Fortinet FortiGuard Labs in May…

Fortinet1 Jul · 13:26 UTC
Silent Swap Campaign Targets Cryptocurrency via Malicious Browser Extensionshighperson_alertThreat Actor
person_alertThreat Actor

Silent Swap Campaign Targets Cryptocurrency via Malicious Browser Extensions

Silent Swap is an active cybercrime campaign leveraging malicious browser extensions to conduct cryptocurrency theft. The operation distributes unsigned installers written in both .NET and Golang variants, masquerading as a legitimate Google Notes br…

Google30 Jun · 13:40 UTC
Pre-Planned Fraud Campaign Targets FIFA World Cup 2026 Across Sectorshighperson_alertThreat Actor
person_alertThreat Actor

Pre-Planned Fraud Campaign Targets FIFA World Cup 2026 Across Sectors

The threat actor behind this campaign remains unattributed. Motivation appears financially driven, leveraging the global interest in FIFA World Cup 2026 to conduct fraud operations.

The Hacker News30 Jun · 09:30 UTC
236K+ malicious sites use DCloud Uni-App templates for crypto scamshighbug_reportVulnerability
bug_reportVulnerability

236K+ malicious sites use DCloud Uni-App templates for crypto scams

Organizations and users interacting with websites built using DCloud Uni-App framework templates. Over 236,000 malicious sites identified conducting cryptocurrency scams, phishing, wallet draining, pig-butchering schemes, and fake gambling platforms.

DCloud29 Jun · 09:57 UTC
Polymarket frontend compromised via third-party vendor; $3M stolenhighbug_reportVulnerability
bug_reportVulnerability

Polymarket frontend compromised via third-party vendor; $3M stolen

Polymarket platform users. Attack vector: malicious JavaScript injected into frontend via compromised third-party vendor. Approximately $3 million in customer funds stolen. No CVE assigned.

Polymarket26 Jun · 16:04 UTC
Clipboard-stealing malware spreads via USB, targets crypto walletshighbug_reportVulnerability
bug_reportVulnerability

Clipboard-stealing malware spreads via USB, targets crypto wallets

Windows systems with USB connectivity. Targets cryptocurrency wallet users. No specific vendor or product vulnerability; relies on user interaction with malicious Windows shortcut (.lnk) files on removable media.

BleepingComputer18 Jun · 14:20 UTC
Windows cryptocurrency clipper campaign uses USB worms and Tor C2highbug_reportVulnerability
bug_reportVulnerability

Windows cryptocurrency clipper campaign uses USB worms and Tor C2

Windows systems with Windows Script Host and ActiveX enabled. Campaign active since February 2026 targeting cryptocurrency users via USB-based LNK worm propagation.

Microsoft18 Jun · 12:30 UTC
Cryptocurrency clipper malware with worm propagation targets Windowshighbug_reportVulnerability
bug_reportVulnerability

Cryptocurrency clipper malware with worm propagation targets Windows

Windows systems globally. No specific product vulnerability; threat relies on social engineering, malicious downloads, or lateral movement. All cryptocurrency wallet users on Windows are potential targets.

Microsoft17 Jun · 21:11 UTC
Rokarolla Android banking trojan targets 217 banking and crypto appshighbug_reportVulnerability
bug_reportVulnerability

Rokarolla Android banking trojan targets 217 banking and crypto apps

Android devices with 217 targeted banking and cryptocurrency applications. Malware features 137 commands for comprehensive device control and data exfiltration. Specific app list and Android version scope not disclosed.

BleepingComputer16 Jun · 18:04 UTC
FBI disrupts Outsider Enterprise Chinese phishing-as-a-service platformhighperson_alertThreat Actor
person_alertThreat Actor

FBI disrupts Outsider Enterprise Chinese phishing-as-a-service platform

Outsider Enterprise is a Chinese phishing-as-a-service (PhaaS) operation disrupted by the FBI in coordination with Google and Black Lotus Labs. The actor operated thousands of phishing websites designed to harvest credit card data and passwords from…

BleepingComputer14 Jun · 12:36 UTC