Finance — threat intelligence
Recent advisories whose title or summary heuristically matches the Finance sector. Derived in-browser/at-edge from a keyword catalog — treat tags as a hint and open each source for ground truth. The underlying feed updates hourly; this page is a snapshot from its last build (timestamped below).
27 recent Finance advisories
Snapshot built . The live filter and the RSS feed reflect new items as they arrive.
-
SWIFT Banking & Government Middleware Enables RCE
Patch middleware vulnerabilities now to avoid hardware-based MFA exploits in ultra-sensitive environments.
-
How Financial Services Companies Can Modernize Their Software Supply Chain
Every security leader at a bank, insurer, or asset manager has had a version of this conversation: Security wants to eliminate a class of vulnerabilities. Engineering explains what it would take to upgrade the platform where they live. Some…
-
Connected Cars Are a Surveillance Platform
Researchers at Northeastern University, in collaboration with Consumer Reports, evaluated how much modern cars spy in their drivers: To determine this, CR dug through thousands of pages of automakers’ privacy policies and asked questions of…
-
Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft
Cryptocurrency exchange Bitget on Wednesday confirmed that attackers who stole $387.5 million last week exploited a zero-day flaw in third-party security products, citing ongoing investigation findings from SlowMist. "Their investigation id…
-
Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT
Unknown threat actors have been observed exploiting a newly patched security flaw in Citrix NetScaler ADC and NetScaler Gateway appliances to target organizations in North America and Europe. The activity, observed by Mandiant Consulting an…
-
Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances
Introduction In late September 2026, Mandiant Consulting and Google Threat Intelligence Group (GTIG) identified active, in-the-wild exploitation of a zero-day vulnerability (CVE-2026-88772) affecting Citrix NetScaler ADC and NetScaler Gatew…
-
Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M
The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday. The attacker exploited the flaw to obtain hi…
-
RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims
RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April 2026. It said this fi…
-
Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise
Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets. "At 18:31 UTC on September 24, 2026, Bitget's security systems identified unauthorized transfers involving a …
-
TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords
Cybersecurity researchers have disclosed details of an active TeamFiltration campaign codenamed UNK_CondorFiltration that has targeted over 5,700 accounts across 28 Microsoft 365 tenants. According to Proofpoint, the activity has primarily …
-
RemControl: AI Built the Overlays. Victims Lose their PINs
Group-IB uncovers RemControl, a new Android banking trojan targeting European, Middle Eastern and Canadian banks, whose criminal infrastructure was unknowingly built by AI.
-
New Android malware uses AI to steal bank logins and PINs
RatHat can navigate infected phones while stealing bank logins, authentication codes, and screen-lock PINs.
-
Fake parcel delivery messages steal your card and bank details
Parcel delivery phishing messages impersonate familiar couriers and use small fees or promised refunds to steal personal and financial information.
-
Revolut phishing texts appear days after data breach
Revolut customers received phishing texts only days after the digital bank acknowledged disclosing customer data to a government impostor.
-
Top 5 Fraud Prevention Platforms for Banks and Fintechs in 2026
Most fraud platforms only see a threat once it becomes a transaction. This guide compares the top 5 fraud prevention platforms for banks and fintechs in 2026, including Group-IB, Feedzai, Sift, DataVisor, and Kount, and what actually separa…
-
KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at lea…
-
Revolut handed customer data to fraudsters using government email account
British fintech Revolut confirmed disclosing sensitive customer data to fraudsters who submitted emergency data requests from a legitimate government email account.
-
Revolut gave customer IDs and financial data to a government impostor
The digital bank was tricked into releasing sensitive customer information, including IDs, to an attacker using a legitimate government email domain.
-
Android malware creates a hidden copy of your banking app
The Gigabud banking Trojan can clone a banking app into a separate work profile on an Android device to help hide fraudulent transactions.
-
Indonesia Hit by Android Banking App-Cloning Campaign
The GoldFactory threat group exploits the Android Work Profile feature to deliver the Gigabud Trojan, while Mantax Otax spreads separately.
-
The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions
Elastic Security Labs tracked this malicious browser extension across seven campaigns and 15 months, through Brazilian bank lures and the Ethereum smart contracts that hold its C2 configuration.
-
Treasury urges banks to file cyber scam reports, noting nearly $13 billion in losses since 2023
As the cyber scam industry expands globally, the U.S. government wants banks to share more information about what's happening to their customers.
-
Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks
The Gigabud banking trojan now installs a second Android app that creates a work profile on an infected phone and drops a tampered banking app inside it, security firm Group-IB said in a report published on September 9. A work profile is a …
-
More than 100,000 fake stores are out to steal your card details
DoppelCart’s fake stores copy real retailers and steal shoppers’ card details and one-time bank confirmation codes.
-
Vwork: Weaponized Open-source Software as an Addon for Gigabud
How the Gigabud Android banking trojan abuses Shelter, an open-source app cloner, and what that means for banks, users, and defenders.
-
Russian suspect in bank account takeovers is extradited to US
A Russian web developer who played a role in a multimillion-dollar bank account takeover scheme has been extradited to the U.S. to face an indictment.
-
Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution
A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026. Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster un…
Other sectors: Government ·Healthcare ·Energy ·Critical Infra ·Education ·Technology ·Telecom ·Defense ·Retail ·Transportation ·Legal Services
Threat groups reported to target Finance
MITRE ATT&CK records 17 tracked groups with reported targeting of this sector. Each links to its ATT&CK profile: techniques by tactic, aliases, tooling and the groups closest to it by technique overlap. Reported targeting is not attribution of any specific advisory above.
admin@338 ·APT-C-23 ·APT-C-36 ·APT19 ·APT41 ·APT42 ·CURIUM ·Deep Panda ·FIN4 ·GCMAN ·Molerats ·OilRig ·Patchwork ·POLONIUM ·TA505 ·Winnti Group ·Wizard Spider
Also on ThreatFilter: cross-source corroborated CVEs · threat group directory · every source we track