NEW: Group Profiler — instant APT intel lookup. Try it →

Finance — threat intelligence

Recent advisories whose title or summary heuristically matches the Finance sector. Derived in-browser/at-edge from a keyword catalog — treat tags as a hint and open each source for ground truth. The underlying feed updates hourly; this page is a snapshot from its last build (timestamped below).

27 recent Finance advisories

Snapshot built . The live filter and the RSS feed reflect new items as they arrive.

  1. INFO darkreading ·

    SWIFT Banking & Government Middleware Enables RCE

    Patch middleware vulnerabilities now to avoid hardware-based MFA exploits in ultra-sensitive environments.

  2. INFO thehackernews ·

    How Financial Services Companies Can Modernize Their Software Supply Chain

    Every security leader at a bank, insurer, or asset manager has had a version of this conversation: Security wants to eliminate a class of vulnerabilities. Engineering explains what it would take to upgrade the platform where they live. Some…

  3. INFO schneier ·

    Connected Cars Are a Surveillance Platform

    Researchers at Northeastern University, in collaboration with Consumer Reports, evaluated how much modern cars spy in their drivers: To determine this, CR dug through thousands of pages of automakers’ privacy policies and asked questions of…

  4. INFO EXPLOITED thehackernews ·

    Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft

    Cryptocurrency exchange Bitget on Wednesday confirmed that attackers who stole $387.5 million last week exploited a zero-day flaw in third-party security products, citing ongoing investigation findings from SlowMist. "Their investigation id…

    exchange-server
  5. INFO EXPLOITED thehackernews ·

    Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT

    Unknown threat actors have been observed exploiting a newly patched security flaw in Citrix NetScaler ADC and NetScaler Gateway appliances to target organizations in North America and Europe. The activity, observed by Mandiant Consulting an…

    citrix USEU
  6. INFO EXPLOITED mandiant-blog ·

    Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances

    Introduction In late September 2026, Mandiant Consulting and Google Threat Intelligence Group (GTIG) identified active, in-the-wild exploitation of a zero-day vulnerability (CVE-2026-88772) affecting Citrix NetScaler ADC and NetScaler Gatew…

    citrix USCAEU
  7. INFO EXPLOITED thehackernews ·

    Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M

    The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday. The attacker exploited the flaw to obtain hi…

    exchange-server
  8. INFO thehackernews ·

    RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims

    RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April 2026. It said this fi…

    android
  9. INFO thehackernews ·

    Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise

    Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets. "At 18:31 UTC on September 24, 2026, Bitget's security systems identified unauthorized transfers involving a …

    exchange-server KR
  10. INFO thehackernews ·

    TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords

    Cybersecurity researchers have disclosed details of an active TeamFiltration campaign codenamed UNK_CondorFiltration that has targeted over 5,700 accounts across 28 Microsoft 365 tenants. According to Proofpoint, the activity has primarily …

    microsoftaws CL
  11. INFO group-ib-blog ·

    RemControl: AI Built the Overlays. Victims Lose their PINs

    Group-IB uncovers RemControl, a new Android banking trojan targeting European, Middle Eastern and Canadian banks, whose criminal infrastructure was unknowingly built by AI.

    android EUCA
  12. INFO malwarebytes-labs ·

    New Android malware uses AI to steal bank logins and PINs

    RatHat can navigate infected phones while stealing bank logins, authentication codes, and screen-lock PINs.

    google
  13. INFO malwarebytes-labs ·

    Fake parcel delivery messages steal your card and bank details

    Parcel delivery phishing messages impersonate familiar couriers and use small fees or promised refunds to steal personal and financial information.

  14. INFO malwarebytes-labs ·

    Revolut phishing texts appear days after data breach

    Revolut customers received phishing texts only days after the digital bank acknowledged disclosing customer data to a government impostor.

  15. INFO group-ib-blog ·

    Top 5 Fraud Prevention Platforms for Banks and Fintechs in 2026

    Most fraud platforms only see a threat once it becomes a transaction. This guide compares the top 5 fraud prevention platforms for banks and fintechs in 2026, including Group-IB, Feedzai, Sift, DataVisor, and Kount, and what actually separa…

  16. INFO thehackernews ·

    KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

    Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at lea…

    elastic-securityelasticchromeedge BR
  17. INFO the-record ·

    Revolut handed customer data to fraudsters using government email account

    British fintech Revolut confirmed disclosing sensitive customer data to fraudsters who submitted emergency data requests from a legitimate government email account.

    UK
  18. INFO malwarebytes-labs ·

    Revolut gave customer IDs and financial data to a government impostor

    The digital bank was tricked into releasing sensitive customer information, including IDs, to an attacker using a legitimate government email domain.

  19. INFO malwarebytes-labs ·

    Android malware creates a hidden copy of your banking app

    The Gigabud banking Trojan can clone a banking app into a separate work profile on an Android device to help hide fraudulent transactions.

    google
  20. INFO darkreading ·

    Indonesia Hit by Android Banking App-Cloning Campaign

    The GoldFactory threat group exploits the Android Work Profile feature to deliver the Gigabud Trojan, while Mantax Otax spreads separately.

    android ID
  21. INFO elastic-security-labs ·

    The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions

    Elastic Security Labs tracked this malicious browser extension across seven campaigns and 15 months, through Brazilian bank lures and the Ethereum smart contracts that hold its C2 configuration.

    elastic-securityelasticchrome BR
  22. INFO the-record ·

    Treasury urges banks to file cyber scam reports, noting nearly $13 billion in losses since 2023

    As the cyber scam industry expands globally, the U.S. government wants banks to share more information about what's happening to their customers.

    US
  23. INFO thehackernews ·

    Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks

    The Gigabud banking trojan now installs a second Android app that creates a work profile on an infected phone and drops a tampered banking app inside it, security firm Group-IB said in a report published on September 9. A work profile is a …

    android
  24. INFO malwarebytes-labs ·

    More than 100,000 fake stores are out to steal your card details

    DoppelCart’s fake stores copy real retailers and steal shoppers’ card details and one-time bank confirmation codes.

  25. INFO group-ib-blog ·

    Vwork: Weaponized Open-source Software as an Addon for Gigabud

    How the Gigabud Android banking trojan abuses Shelter, an open-source app cloner, and what that means for banks, users, and defenders.

    android
  26. INFO the-record ·

    Russian suspect in bank account takeovers is extradited to US

    A Russian web developer who played a role in a multimillion-dollar bank account takeover scheme has been extradited to the U.S. to face an indictment.

    US
  27. INFO thehackernews ·

    Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution

    A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026. Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster un…

    crowdstrike BR

Other sectors: Government ·Healthcare ·Energy ·Critical Infra ·Education ·Technology ·Telecom ·Defense ·Retail ·Transportation ·Legal Services

Threat groups reported to target Finance

MITRE ATT&CK records 17 tracked groups with reported targeting of this sector. Each links to its ATT&CK profile: techniques by tactic, aliases, tooling and the groups closest to it by technique overlap. Reported targeting is not attribution of any specific advisory above.

admin@338 ·APT-C-23 ·APT-C-36 ·APT19 ·APT41 ·APT42 ·CURIUM ·Deep Panda ·FIN4 ·GCMAN ·Molerats ·OilRig ·Patchwork ·POLONIUM ·TA505 ·Winnti Group ·Wizard Spider

Also on ThreatFilter: cross-source corroborated CVEs · threat group directory · every source we track