Affected Systems

Campaign 1: Users in Czechia, Slovakia, Poland, and Lithuania targeted by GepyS banking malware via compromised corporate email accounts. Campaign 2: Cryptocurrency users globally affected by Rust-based clipboard hijacker monitoring 21 blockchain types (BTC, ETH, LTC, others) using Binance Smart Chain for C2 resolution via EtherHiding.

Exploitation Status

Active exploitation confirmed. Gen Threat Labs documented both campaigns during H1 2026 with real-world detections. Banking campaign used compromised corporate mailboxes to deliver JavaScript droppers leading to GepyS malware. Cryptocurrency campaign deployed Rust clipper with smart contract-based C2 infrastructure.

Business Impact

Banking campaign bypasses email authentication (SPF/DKIM pass on compromised accounts) and deploys proxy/browser manipulation to intercept banking sessions. Cryptocurrency campaign silently redirects payments by replacing wallet addresses in clipboard before transaction signing—blockchain records valid transaction to attacker wallet. Both campaigns exploit trusted workflows rather than breaking cryptographic controls. Network IoC lists age quickly due to smart contract-based C2 pointer rotation. Related H1 campaigns in Italy (XWorm via Vercel/Blogspot) and Poland (Remcos RAT via steganographic .NET loader) show regional pattern expansion.

Urgency

🟠 Within 24 hours

Recommended Actions

  • Monitor for JavaScript and PowerShell execution chains originating from email attachments, especially .js files launching PowerShell with obfuscation or multi-stage loaders
  • Implement endpoint detection for unauthorized proxy setting changes and browser extension installations, particularly targeting banking and financial application sessions
  • Deploy clipboard monitoring to detect wallet address substitution patterns across BTC, ETH, LTC and other cryptocurrency formats; alert on clipboard modification by unsigned or unexpected processes
  • Investigate Binance Smart Chain contract interactions for C2 resolution (EtherHiding technique); track contract addresses, read methods, and resolved infrastructure as linked IoC sets rather than isolated network indicators
  • Enhance email security posture to detect compromised internal accounts through behavioral analysis—legitimate SPF/DKIM passing does not confirm account integrity; correlate attachment types with sender history and geographic targeting