threat-intel Fake Bahrain Alert App Deploys Android Surveillance Malware A malicious Android application, dubbed ‘BH Alert,’ is being distributed through fake Google Play sites mimicking Bahraini government entities to deliver a four-stage surveillance platform. The app leverages users' trust… Dark Reading · Jul 22, 2026 High BHKUandroidspywaremalware
threat-intel ISC Stormcast For Monday, July 20th, 2026 https://isc.sans.edu/podcastdetail/10014, (Mon, Jul 20th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions, leveraging sophisticated phishing techniques and exploiting vulnerabilities in legacy systems. The threa… SANS Internet Storm Center · Jul 20, 2026 High phishingshadowratvulnerability
threat-intel 20+ Hijacked Government Websites Became an Attack Channel A sophisticated campaign, dubbed PhantomEnigma, has hijacked over 20 Brazilian government websites to deliver malware and conduct attacks against banks and public agencies. Attackers leveraged compromised .gov.br infrast… The Hacker News · Jul 16, 2026 High BRgovernmentphishingmalware
threat-intel New Ghost Phishing Wave Is Breaking Traditional Email Security A new phishing technique called ‘ghost phishing’ is emerging, where malicious links appear harmless during initial email inspection but execute a more damaging attack within the victim’s browser. The EvilTokens campaign,… The Hacker News · Jul 8, 2026 High USEUphishingghost phishingmicrosoft 365
threat-intel SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users A new banking fraud operation, tracked as REF6045, is targeting Mexican banks, fintech companies, and cryptocurrency exchanges using a malware toolset called SCMBANKER. The operation leverages fake CAPTCHA verification p… The Hacker News · Jul 8, 2026 High MXbankingmalwarephishing
threat-intel RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service A new Android malware operation, RedWing, is being sold on Telegram as a ready-made bank fraud service. Developed by a Russian threat actor group, RedWing allows even unskilled criminals to steal banking logins and one-t… The Hacker News · Jul 7, 2026 High RUandroidmalwarefraud
threat-intel ⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More This week’s security recap highlighted several concerning trends, including a disruption of the NetNut residential proxy network used for botnet operations, a fake Proof-of-Concept (PoC) malware targeting vulnerability r… The Hacker News · Jul 6, 2026 High CVE-2026-48276CVE-2026-48283CVE-2026-48277USESSPbotnetproxymalware
malware Ousaban Banking Trojan Targets Iberian Bank Users with Fake PDF Lures The Ousaban banking trojan, originating in Brazil and previously tracked as Javali, is targeting Windows users in Spain and Portugal with a phishing campaign utilizing fake PDF lures. The trojan, which has evolved over t… The Hacker News · Jul 1, 2026 High PTESbanking trojanphishinggeofencing
threat-intel SocGholish Takedown Highlights Malicious TDS Threats A coordinated international law enforcement operation, part of Operation Endgame, successfully disrupted SocGholish, a decade-old malware framework used as an initial-access broker by cybercriminal groups like Evil Corp.… Dark Reading · Jun 23, 2026 High NLtdssmalwareaffiliate
ransomware New Prinz Eugen ransomware prioritizes recent files for encryption A new ransomware variant, Prinz Eugen, is targeting organizations with a focus on encrypting recently modified files to maximize disruption. The group employs a hands-on-keyboard approach, utilizing legitimate RMM tools… BleepingComputer · Jun 20, 2026 High GBransomwarerdpencryption
malware Fileless Phantom Stealer Targets Browser Credentials A new fileless malware, Phantom Stealer, is being deployed through targeted phishing campaigns against banks and high-value organizations. The malware focuses on stealing browser credentials and session cookies, utilizin… Dark Reading · Jun 16, 2026 High GBDEFRcredential theftbrowser securityfileless malware
malware New Rokarolla Android malware targets 217 banking, crypto apps A new Android banking trojan, Rokarolla, is targeting 217 banking and cryptocurrency applications through deceptive app distribution and sophisticated data theft techniques. The malware leverages Accessibility permission… BleepingComputer · Jun 16, 2026 High androidbanking trojandata theft
malware New Rokarolla Android Malware Steals PINs, SMS Codes, and Crypto Wallet Funds A new Android banking trojan, Rokarolla, has been identified by Zimperium, targeting over 200 banking and cryptocurrency apps. The malware utilizes techniques like fake login pages and Accessibility abuse to steal sensit… The Hacker News · Jun 16, 2026 High androidbanking trojanpin theft
other Cyberattack on Russian tech firm Astral disrupts business, government services for week A cyberattack disrupted the operations of Russian tech firm Kaluga Astral for approximately a week, impacting its customers who rely on its software for various business and government services. The company is undergoing… The Record · Jun 15, 2026 Medium RUcyberattackdisruptionrussian
malware NFCShare Android malware spreads via fake banking app updates on GitHub A new variant of the NFCShare Android malware is spreading through fake updates for banking apps hosted on GitHub, targeting financial institutions across Europe. The malware leverages NFC technology to steal payment car… BleepingComputer · Jun 8, 2026 High ITSPGEnfcandroidbanking
threat-intel Russia upgrades rules for its digital spy system to better track citizens online Russia has updated its SORM (System for Operative Investigative Activities) digital surveillance system to enhance its capabilities for tracking citizens online. The updated regulations expand the data accessible through… The Record · Jun 8, 2026 High RUsurveillancedigital privacyinternet monitoring
threat-intel What 345 Days of Untested Exposure Looks Like at a Bank This article details a significant security vulnerability stemming from a bank’s reliance on an annual penetration testing schedule, highlighting the risks associated with infrequent assessments. A VPN vulnerability, exp… BleepingComputer · Jun 3, 2026 High USvulnerabilityapitenant_id
threat-intel Asia's Cyber Insurance Market Shows Signs of Life The Asian cyber insurance market has historically lagged behind other regions due to low penetration rates, particularly among larger organizations and small businesses. However, a recent report indicates a potential shi… Dark Reading · May 29, 2026 High CHJASIcyberinsuranceransomwareapac
supply-chain Malicious Sicoob NuGet Steals Banking Credentials as npm Packages Target Cloud Secrets A malicious NuGet package, 'Sicoob.Sdk,' disguised as a C# SDK for Sicoob, Brazil's largest cooperative financial system, was discovered to be stealing client IDs and PFX certificates. This allowed unauthorized access to… The Hacker News · May 29, 2026 High BRsupply-chaincredentialsbanking
malware Grandoreiro Malware and BTMOB RAT Campaigns Target Windows and Android Users Two separate malware campaigns are targeting Windows and Android users across Latin America and Europe, primarily focusing on banking trojans. The first campaign utilizes the Grandoreiro malware, an actively evolving ban… The Hacker News · May 27, 2026 High PTBRESbanking trojanandroid malwaredll side-loading