Tag: banking
-
Cybercriminals Target Turkish Banks With 8,400 Phishing Domains and 6,600 Scam Ads
Cybercriminals are operating an industrial-scale fraud ecosystem targeting Turkey’s financial sector, using more than 8,400 phishing domains, thousands of social media advertisements, fake loan offers, illicit gambling services, and money-mule recruitment to steal credentials. Group-IB’s investigation links these operations into five interconnected schemes targeting dozens of Turkish banking brands. Group-IB recorded more than 6,600 scam…
-
Fake Bank Apps Let Scammers Control Android Phones in Southeast Asia
RedHook malware uses fake banking and government apps to steal data and control Android phones, with attacks confirmed in Vietnam and Indonesia so far. The post Fake Bank Apps Let Scammers Control Android Phones in Southeast Asia appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-android-malware-apac-southeast-asia/
-
RedWing Android Spyware Sold as a Service on Telegram
Zimperium found RedWing, an Android spyware sold as a service via Telegram to target banking apps First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/redwing-android-spyware-maas/
-
SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users
A new banking fraudulent operation is targeting customers of Mexican banks, fintech, payment processors, and cryptocurrency exchanges using ClickFix lures.The activity cluster, tracked by Elastic Security Labs under the moniker REF6045, involves infecting victims through fake CAPTCHA verification pages that deceive them into running a malicious command that installs a PowerShell toolkit dubbed First seen…
-
Telegram-Hosted RedWing Malware Lets Anyone Rent Android Spyware Tools
RedWing: The Android Banking Trojan You Can Rent on Telegram for Less Than a Coffee Subscription Zimperium’s zLabs team has uncovered RedWing, an Android spyware operation sold as a subscription service through Telegram, with links to Russian threat actors and apparent roots in the Oblivion malware family. It comes with documentation, tutorial videos, a referral…
-
How to implement a continuous offensive security testing program
The hard part was never finding the exposure. It was deciding what to do about it: whether to patch, mitigate, monitor, or accept, and banking that that decision would still … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/08/picus-continuous-offensive-security-testing-program/
-
RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service
A new Android malware operation called RedWing is being rented out on Telegram as a ready-made bank-fraud service. It lets even low-skill criminals take over a victim’s phone, steal their banking logins, and capture the one-time codes that protect their accounts.Zimperium’s zLabs, which found the operation, says it looks like a new variant of Oblivion,…
-
Hackers Use Server-Side Geofencing to Deliver Ousaban Banking Trojan in Spain and Portugal
A targeted campaign that delivers the Ousaban banking Trojan to users in Spain and Portugal using sophisticated server-side geofencing and multi-stage delivery. The adversary begins with a socially engineered phishing PDF that impersonates a corrupted document and coerces victims into visiting a malicious webpage through an “Atualizar” (Update) prompt. The PDF’s JavaScript is hex-escaped to…
-
Hackers Use Geofenced Webpages to Deliver Ousaban Banking Trojan in Spain and Portugal
A targeted phishing campaign delivering the Ousaban banking Trojan to users in Spain and Portugal, notable for its use of geofenced webpages, layered evasion techniques, and a modular delivery chain. The threat actor repurposes a playbook seen previously in Brazil but has refined access controls and server-side checks to ensure malware reaches only the intended…
-
Aflac Data Breach: Over 4M Customers in Japan May Be at Risk
Aflac says a data breach in Japan may affect 4.38 million customers and agents, exposing personal, policy, and some banking information. The post Aflac Data Breach: Over 4M Customers in Japan May Be at Risk appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-aflac-japan-data-breach-insurance-records/
-
Ousaban Banking Trojan Targets Iberian Bank Users with Fake PDF Lures
A Brazilian banking trojan called Ousaban is going after Windows users who bank in Spain and Portugal. Fortinet’s FortiGuard Labs identified the campaign in May 2026.It opens with a phishing PDF disguised as a corrupted file, checks that the visitor is really in Spain or Portugal, and hides its real payload inside an image.The goal…
-
Brazilian Banking Trojan Ousaban Targets Spain and Portugal
FortiGuard says the Brazilian banking trojan Ousaban is targeting Spain and Portugal via phishing First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ousaban-banking-trojan-spain/
-
Insurance Giant Aflac Discloses Data Breach Impacting Millions
Aflac Japan has notified regulators that policy details and personal and banking information have been compromised First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/insurance-giant-aflac-data-breach/
-
Rokarolla Uses Fake Google Play Protect App to Target Banking and Cryptocurrency Users
Rokarolla, a sophisticated Android banking trojan distributed via malicious websites that masquerade as trusted applications such as TikTok, Google Chrome and even Google Play Protect. Unlike simple credential stealers, Rokarolla is a multi-functional fraud platform that targets at least 217 banking and cryptocurrency apps and combines Accessibility Service abuse, phishing overlays, SMS interception, keylogging, screenshot…
-
CISA Urges OT Resilience in Dark Remarks About Cyberattacks
Tags: banking, china, cisa, cyber, cyberattack, defense, infrastructure, Internet, military, resilience, russia, serviceVital Service Providers Need a Plan to Work Through Internet Outages, CISA Says. Critical U.S. infrastructure like water, power and even banking systems will be successfully hacked by enemy cyber warriors in the event of a military confrontation with a peer adversary like Russia or China, officials from the nation’s civilian cyber defense agency said.…
-
CISA Urges OT Resilience in Dark Remarks About Cyberattacks
Tags: banking, china, cisa, cyber, cyberattack, defense, infrastructure, Internet, military, resilience, russia, serviceVital Service Providers Need a Plan to Work Through Internet Outages, CISA Says. Critical U.S. infrastructure like water, power and even banking systems will be successfully hacked by enemy cyber warriors in the event of a military confrontation with a peer adversary like Russia or China, officials from the nation’s civilian cyber defense agency said.…
-
CISA Urges OT Resilience in Dark Remarks About Cyberattacks
Tags: banking, china, cisa, cyber, cyberattack, defense, infrastructure, Internet, military, resilience, russia, serviceVital Service Providers Need a Plan to Work Through Internet Outages, CISA Says. Critical U.S. infrastructure like water, power and even banking systems will be successfully hacked by enemy cyber warriors in the event of a military confrontation with a peer adversary like Russia or China, officials from the nation’s civilian cyber defense agency said.…
-
Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline
A French-speaking attacker broke into a small French automotive business, planted a keylogger, and stole banking and email credentials.Ordinary stuff, until one move near the end.Before his command-and-control server went dark, he installed OpenSSH and Tailscale on a victim’s machine, building a way back in that did not run through the C2 at all. When…
-
Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline
A French-speaking attacker broke into a small French automotive business, planted a keylogger, and stole banking and email credentials.Ordinary stuff, until one move near the end.Before his command-and-control server went dark, he installed OpenSSH and Tailscale on a victim’s machine, building a way back in that did not run through the C2 at all. When…
-
Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline
A French-speaking attacker broke into a small French automotive business, planted a keylogger, and stole banking and email credentials.Ordinary stuff, until one move near the end.Before his command-and-control server went dark, he installed OpenSSH and Tailscale on a victim’s machine, building a way back in that did not run through the C2 at all. When…
-
Serverless Phishing Kit on GitHub Targets Mexican Banks
GitBait phishing kit abuses GitHub Pages and the SheetBest API to steal Mexican banking credentials First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/gitbait-github-pages-sheetbest/
-
FIFA WM 2026 im Visier von Cyberkriminellen – Geklonte FIFA-Seiten, Banking-Trojaner und Stealer-Logs bedrohen WM-Fans
Tags: bankingFirst seen on security-insider.de Jump to article: www.security-insider.de/wm-2026-betrug-phishing-banking-trojaner-fifa-a-c6fe1701ed6ea0db7980feb2275609d7/
-
Rokarolla Android trojan targets banking and crypto users, enables device takeover
A newly discovered Android banking trojan, dubbed Rokarolla, targets 217 banking and cryptocurrency applications and can execute 137 commands on infected devices, according to … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/17/rokarolla-android-banking-trojan-device-takeover/
-
Modular Phishing Kit Uses GitHub Pages to Steal Payment Card Details and Passwords
A sophisticated, long-running phishing operation has evolved into a serverless, modular campaign that weaponizes GitHub Pages to harvest payment card data, credentials, and customer identifiers from banking customers in Mexico. The campaign’s architecture centers on a phishing kit containing a selector panel that operators use to generate institution-specific landing pages. Those landing pages impersonate at…
-
New Rokarolla Android Trojan Targets 217 Banking and Crypto Apps
Rokarolla Android malware targets 217 banking and crypto apps, steals credentials, blocks bank calls, intercepts SMS, and disables Play Protect. Zimperium’s zLabs researchers have published a detailed analysis of Rokarolla, a new Android banking trojan named after its command-and-control infrastructure. It spreads through malicious websites masquerading as TikTok and Chrome, one confirmed distribution point being…
-
Rokarolla Android Banking Trojan Enables Device Takeover
Malware Targets Banks, Crypto Platforms and Social Media. Newly surfaced Android-based banking Trojan gives threat actors near-total control over infected devices, letting them steal user credentials for direct access to financial accounts, says researchers. Rokarolla tricks users into side-loading malicious versions of popular, high traffic apps. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/rokarolla-android-banking-trojan-enables-device-takeover-a-31996
-
New Rokarolla Android malware targets 217 banking, crypto apps
A new Android banking trojan named Rokarolla is targeting 217 banking and cryptocurrency applications using an extensive set of 137 commands. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-rokarolla-android-malware-targets-217-banking-crypto-apps/
-
Rokarolla Android Trojan Levels Up to Full Device Control, Persistence
The emerging malware, spread via fake TikTok and Chrome downloads, demonstrates an evolution by combining banking fraud with extensive device surveillance and remote control. First seen on darkreading.com Jump to article: www.darkreading.com/endpoint-security/rokarolla-android-trojan

