Tag: banking
-
AI-Powered RatHat Android Trojan Steals Bank Credentials, PINs and MFA Codes
Researchers have identified a new Android banking Trojan called RatHat that utilizes artificial intelligence to automate device compromise and steal financial credentials, PINs, and one-time passcodes. Zimperium’s zLabs researchers analyzed this malware, which represents a significant evolution in Android threats. AI-Powered RatHat Android Trojan Unlike traditional malware that relies on fixed scripts, RatHat offers a…
-
ISMG Editors: Even Valid Email Addresses Can’t Be Trusted
Also: States Inherit America’s Cyber Burden, AI Agents Reshape the MSSP Market. In this week’s panel, four ISMG editors discuss an unusual breach at U.K. digital banking platform Revolut, the growing role of U.S. state governments in protecting local critical infrastructure and what a new cybersecurity acquisition tells us about the AI-powered SOC. First seen…
-
CISOs to Watch in Charlotte: From Theme Parks to Financial Services
Charlotte’s reputation runs on banking, but the security leaders in this piece protect a far wider slice of American consumer life: aircraft engines and building controls, a lending marketplace, packaging for half the products on a grocery shelf, payroll software,… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/cisos-to-watch-in-charlotte-from-theme-parks-to-financial-services/
-
RatHat Abuses Android Wireless Debugging to Gain Shell Access and Steal Banking PINs
RatHat, a newly identified Android banking malware family that combines Accessibility abuse, local Android Debug Bridge (ADB) pairing, native shell-level components, and generative-AI-assisted interface automation. The operation appears linked to China-based threat actors and is primarily designed to steal banking credentials, payment PINs, one-time passwords, device-unlock secrets, and other high-value data from infected Android devices.…
-
Malware bypasses browser checks to force install Chrome, Edge extensions
A banking malware operation active since mid-2025 has been using a toolkit named KREMLIN to install malicious Chrome and Edge extensions that steal credentials, session tokens, and sensitive data. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/malware-bypasses-browser-checks-to-force-install-chrome-edge-extensions/
-
Malware bypasses browser checks to force install Chrome, Edge extensions
A banking malware operation active since mid-2025 has been using a toolkit named KREMLIN to install malicious Chrome and Edge extensions that steal credentials, session tokens, and sensitive data. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/malware-bypasses-browser-checks-to-force-install-chrome-edge-extensions/
-
Smishing Triad Hackers Use JWR Phishing Kit to Steal Cards, OTPs and Bank Credentials
A large-scale SMS phishing campaign linked to the Smishing Triad is using a sophisticated phishing kit dubbed JWR to harvest payment-card data, one-time passwords, online-banking credentials, identity information, and digital-wallet logins. Group-IB attributed the activity to an operator sub-cluster tracked as Outsider, which appears to operate as a customer within the wider phishing-as-a-service ecosystem rather…
-
KREMLIN Banking Malware Bypasses Chrome Security to Steal Banking Sessions
A Brazilian banking malware operation, dubbed KREMLIN, that can silently implant malicious extensions in Google Chrome and Microsoft Edge, bypassing Chromium’s built-in integrity protections to steal credentials, cookies, and active banking sessions. Despite its name, the KREMLIN toolkit shows no apparent Russian connection. The campaign relies on Portuguese-language artifacts, lures impersonating 12 Brazilian banks, and…
-
KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
Tags: banking, browser, chrome, credentials, cybersecurity, finance, google, malicious, malware, threatCybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN.Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google…
-
Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users
A Casbaneiro banking Trojan campaign targeting users across Latin America, using phishing lures, geofenced delivery infrastructure, and distributed command-and-control (C2) servers to obscure malicious activity. The operation, observed in August 2026, primarily targets victims in Argentina, Peru, Colombia, and Mexico through fake invoice and legal-notice emails carrying links to malicious PDF files. The campaign demonstrates…
-
Casbaneiro Banking Trojan Uses Distributed C2 Servers to Evade Detection and Target Bank Users
A Casbaneiro banking Trojan campaign targeting users across Latin America, using phishing lures, geofenced delivery infrastructure, and distributed command-and-control (C2) servers to obscure malicious activity. The operation, observed in August 2026, primarily targets victims in Argentina, Peru, Colombia, and Mexico through fake invoice and legal-notice emails carrying links to malicious PDF files. The campaign demonstrates…
-
Toronto’s CISOs to Watch: Leaders Across Industry
Toronto anchors Canada’s financial, retail, and technology sectors, with a cybersecurity leadership community shaped by the demands of banking regulation, critical infrastructure protection, and large-scale digital transformation. The CISOs below bring experience spanning transit systems, national retail, enterprise software, professional… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/torontos-cisos-to-watch-leaders-across-industry/
-
CISOs to Watch in New York’s Fintech Industry
New York’s fintech sector spans digital banking platforms, trading infrastructure, financial technology providers, and payments companies operating at the intersection of financial services and rapid technological innovation. CISOs in this space must protect complex digital ecosystems while navigating stringent regulatory… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/cisos-to-watch-in-new-yorks-fintech-industry/
-
Indonesia Hit by Android Banking App-Cloning Campaign
The GoldFactory threat group exploits the Android Work Profile feature to deliver the Gigabud Trojan, while Mantax Otax spreads separately. First seen on darkreading.com Jump to article: www.darkreading.com/mobile-security/indonesia-android-banking-app-cloning-campaign
-
Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks
The Gigabud banking trojan now installs a second Android app that creates a work profile on an infected phone and drops a tampered banking app inside it, security firm Group-IB said in a report published on September 9.A work profile is a separate space that Android typically reserves for employer apps, and what’s inside it…
-
StreamRAT Abuses Android Accessibility, MediaProjection and HVNC for Full Device Takeover
StreamRAT, a newly identified Android banking trojan distributed through fake free-TV streaming advertisements on Meta and TikTok. The campaign, tracked as “Steamtv Esp.,” primarily targeted Spanish-speaking Android users and exposed an estimated 570,000 Meta users between June 11 and July 3, 2026. The operation highlights the continued effectiveness of piracy-themed social engineering. Victims who clicked…
-
Earth Berberoka-Linked Hackers Target Brazil With Linux Malware and SEO Poisoning
A Chinese-speaking cybercrime cluster linked to the Earth Berberoka threat actor has compromised Brazilian government and educational web servers to conduct large-scale SEO poisoning and online-gambling fraud. The operation has been active since mid-2025 and represents a notable shift in Brazil’s threat landscape. Rather than deploying the country’s more familiar banking malware, the attackers are…
-
Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control
Cybersecurity researchers have disclosed details of a new Android banking trojan called StreamRat that was promoted to Spanish-speaking users through a fake television-streaming campaign on Meta and can give operators near-complete control of infected devices.ThreatFabric said the campaign’s advertisement focused on Spain and reached an estimated 570,950 Meta accounts in the European Union First seen…
-
Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems
Brazilian financial services, retail, and e-commerce organizations have become the target of a financially motivated threat actor dubbed Breeze Comet (formerly UNC5669) since 2024.Google Threat Intelligence Group (GTIG) and Mandiant teams described the threat actor as “specializing in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers.” The adversary First seen on…
-
Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems
Brazilian financial services, retail, and e-commerce organizations have become the target of a financially motivated threat actor dubbed Breeze Comet (formerly UNC5669) since 2024.Google Threat Intelligence Group (GTIG) and Mandiant teams described the threat actor as “specializing in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers.” The adversary First seen on…
-
Financial Stability Board Sounds the Alarm Over Frontier AI Risks
The Financial Stability Board has warned G20 banking leaders about the cyber risks of frontier AI First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/financial-stability-board-alarm/
-
Financial Stability Board Sounds the Alarm Over Frontier AI Risks
The Financial Stability Board has warned G20 banking leaders about the cyber risks of frontier AI First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/financial-stability-board-alarm/
-
âš¡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More
The boring parts caused most of the trouble.A router shipped ready to listen. A fake check turned the user into the installer. Trusted systems collected traffic and passwords, then cleaned the logs. Old bugs formed new attack chains. Even an AI agent decided its assigned task was optional.Elsewhere, fake apps, helpful support calls, cheap banking…
-
Mobile banking trojans expand capabilities; 66% now allow full device takeover
First seen on scworld.com Jump to article: www.scworld.com/news/mobile-banking-trojans-expand-capabilites-66-now-allow-full-device-takeover
-
Mobile banking trojans expand capabilities; 66% now allow full device takeover
First seen on scworld.com Jump to article: www.scworld.com/news/mobile-banking-trojans-expand-capabilites-66-now-allow-full-device-takeover
-
Being Right Is the Easy Part
Tags: ai, banking, business, cloud, compliance, container, control, country, crypto, cryptography, data, email, encryption, endpoint, fraud, ibm, intelligence, jobs, strategy, technologyHome Blog <!– PKWARE Blog, "Being Right Is the Easy Part" – STYLES Design tokens + .pk-article class rules. Paste into a Code Block (or move the token layer to the child theme and keep only the .pk-article rules here). tags included. –> Guest Perspective Being Right Is the Easy Part The question I asked…
-
AI-Powered Balonx Sistema PhaaS Harvests Credentials From Over 1,100 Banking Users
Mexico’s financial sector is facing an industrialized phishing Balonx Sistema, a Mexico-focused Phishing-as-a-Service (PhaaS) platform that has harvested credentials and financial data from more than 1,100 banking users since at least October 2025. The service targets over 20 Mexican financial institutions and combines live phishing, Android malware, and AI-driven voice fraud in one subscription-based operation.…
-
Scammers Impersonate Microsoft to Push Fake Security Scans and Refund Fraud
A cluster of fraudulent websites impersonating Microsoft is using fake “security scans” to pressure victims into uninstalling antivirus products, disclosing personal and banking information, and granting remote access to their computers. The sites, branded as SysScan, claim to assess whether an antivirus product is functioning properly. Their conclusion is predetermined: the victim’s computer is allegedly…
-
ToxicPanda 2.0 can take over your Android phone and banking apps
A new version of the Android banking Trojan can seize control of infected phones and block access to Google Play and Google Play Services. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/toxicpanda-2-0-can-take-over-your-android-phone-and-banking-apps/
-
ToxicPanda 2.0 Targets 349 Financial Apps and Steals Android Lock Credentials
ToxicPanda 2.0 is going after Android users in 16 countries, stealing banking and unlock credentials while taking control of devices through Wireless Debugging. First seen on hackread.com Jump to article: hackread.com/toxicpanda-2-0-app-steals-android-lock-credentials/

