Visualização de leitura

Ransom & Dark Web Issues Week 1, September 2026

ASEC Blog publishes Ransom & Dark Web Issues Week 1, September 2026           ZaWoo Data Extortion Attacks Against Multiple Organizations Worldwide Black X Ransomware Attack on a South Korean Automotive Parts Manufacturer Internal Data of a South Korean Asset Management and Investment Firm Offered for Sale

Hackers Expose Data of 1.2 Million Heights Finance Customers

A Heights Finance breach exposed personal and financial data of over 1.2 million people after hackers compromised a third-party cloud platform.

Heights Finance is a U.S. consumer finance company that provides personal loans and related lending services, mainly to customers who may have limited access to traditional bank credit. It is part of Heights Finance Holdings Co.

Heights Finance Holdings is notifying more than 1.2 million people that on May 7, 2026, Heights Finance discovered unauthorized access to a third-party cloud platform storing customer data. The company launched an investigation with external cybersecurity experts and notified federal law enforcement.

“On May 7, 2026, Heights discovered that an unauthorized actor gained access to a cloud-based platform hosted by a third party that we use to store certain customer data. This activity was limited to the cloud-based platform only—it did not affect any of our loan management systems or other computer systems or networks. We immediately activated our incident response protocols, brought in outside cybersecurity specialists to investigate, and reported the incident to federal law enforcement.” reads the notice of data breach.

“We have since confirmed that the cloud-based platform is secure and that there is no ongoing security threat. Our operations were not impacted by this incident and have continued safely and securely.”

Heights said its internal systems and operations were not affected, the platform has been secured, and there is no ongoing threat.

The compromised customer information included contact details, financial and bank account data, government IDs and dates of birth. The affected data varies by person and may involve Heights Finance customers, loan applicants, people who inquired about its products, or former borrowers of Curo Management and related brands.

Heights Finance is offering affected individuals 24 months of free credit monitoring and identity protection. The company said dark web monitoring has found no evidence that the stolen data has been published.

No threat actor has claimed responsibility, and no known ransomware or extortion group has been linked to the breach so far.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Heights Finance)

Heights Finance data breach: What customers need to know

Heights Finance Holdings’ online data breach notification says an unauthorized party accessed a third-party cloud platform containing customer data, potentially exposing highly sensitive personal, banking, and identity information.

Heights Finance is a consumer lender that offers personal installment loans. Reportedly, the company filed a report with Texas regulators mentioning 734,828 affected people, though that figure should not automatically be read as a confirmed nationwide total, since Heights Finance operates dozens of personal loan companies across Alabama, Tennessee, Georgia, Texas, and South Carolina. 

The company is associated with the former CURO Management business and related brands. The breach notice covers not only some Heights Finance customers, but potentially people connected to certain current or former CURO-related brands.

On May 7, Heights Finance discovered that an unauthorized party had gained access to a cloud-based platform run by a third party and used to store certain customer information. The company says its investigation found that the intruder may have viewed or copied information in that environment.

Heights says affected people may include:

  • People who received a loan through Heights Finance.
  • People who inquired about or applied for a loan product, including through a third party.
  • Some customers of former parent company CURO Management and its present or former related brands.

What makes the incident especially concerning is the nature of the potentially exposed records, which can include the combination of information criminals need to impersonate someone, target their bank accounts, or create highly convincing phishing attempts.


Breaches happen every day. Don’t be the last to know.


Potentially exposed data includes:

  • Contact information: Name, home address, phone number, and email address.
  • Financial information: Account details, bank name, bank account number, routing number, and related financial information.
  • Government identifiers: Social Security number (SSN), tax identification number, driver’s license number, or state ID number.
  • Other personal data: Date of birth and personal circumstances voluntarily disclosed during customer service interactions.

The combination of a Social Security number, date of birth, address, and bank account details can create a much more serious risk than a breach exposing only email addresses. It can support identity fraud, financial fraud, account takeover attempts, and tailored social engineering scams.

The personal circumstances customers may have shared with support staff could also make scams more persuasive or potentially more harmful, particularly for people who discussed financial distress, repayment problems, or other sensitive subjects.

What affected customers should do

People who receive a letter from Heights Finance should follow the company’s instructions and enroll in the offered protection service. Exact instructions can be found on Heights Finance’s website.

Since people who were not actual customers could also be affected, there may be some uncertainty about whether someone’s information was included in the data breach. If you believe you fall into one of the listed groups but do not receive a notice, use contact details published by Heights Finance for inquiries. Do not use a number provided in an unexpected email, text, phone call, or even sponsored search result to ask whether your information was involved.

More general advice on what to do is available in our article Involved in a data breach? Here’s what you need to know.


What do cybercriminals know about you?

Use Malwarebytes’ free Digital Footprint scan to see whether your personal information has been exposed online.

July 2026 Dark Web Threat Actor Trend Report

Note The July 2026 Dark Web Threat Actor Trend Report focuses on trends among threat actors—including hacktivists—active on the deep web and dark web. It is explicitly noted that the factual accuracy of some content could not be verified. Major Issues Handala claimed to have compromised the core infrastructure of an Internet service provider in […]

UK Cybercrime Journal: H1 2026 Social Media Fraud Trends

What Happened

HMRC Issues Warning to TikTok Users

  • On 4 June 2026, HM Revenue and Customs (HMRC) uncovered a suspected £153 million tax fraud scam involving TikTok.
  • The scheme allegedly involved individuals posting advertisements on the TikTok, enticing users to hand over sensitive tax information, including business VAT registration details or personal self-assessment credentials for a financial reward.
  • Using the stolen tax details, the fraudsters could file bogus repayment requests with HMRC.
  • The warning comes after two Romanian men, aged 22 and 25, were apprehended by HMRC officers in east London on 23 April 2026 in connection with the alleged fraud.

Lloyds Bank found Two Thirds of Fraud Cases Started on Meta 

  • On 6 June 2026, Liz Ziegler, the Lloyds fraud prevention director disclosed that 68% of fraud reports from their customers started on a Meta platform, including Facebook, Instagram, and WhatsApp.
  • The average claim value submitted to Lloyds Bank is now above £500, an increase of about £100 from last year. Plus, victims were sending up to £66 million a year to fraudsters after falling victim to a scam advert via Meta, up from £27 million in 2023.
  • The most common scams involve fake tickets for concerts, festivals and sporting events. Meta’s Facebook Marketplace is also plagued by fake adverts for cars, bikes, campervans and mobility vehicles.
  • Other categories of fraud on Meta platforms, collected by Lloyds between March 2025 and 2026, include: wedding photobooths, tattoo deposits, vapes, wigs, Moncler jackets, football shirts, Dyson products and Amazon Alexas. Fraudulent transactions for deposits for flats, mobile phones, household furniture and gym equipment have also been observed.

UK Finance Recorded £221.5m Lost to Investment Scams

  • In June 2026, UK Finance's Annual Fraud Report recorded the highest loss total ever recorded and the highest total number of cases ever reported at 14,893, which was 26% higher than 2025.
  • Up to £221.5m was lost to scams in which victims were persuaded to transfer funds to a fake investment or fictitious fund. This figure also marked a 40% rise more than 2025.
  • The primary observed tactics involved in investment scams include traditional cold calling to pressurise victims into acting quickly to claim an opportunity before it expires, as well as adverts on social media offering unrealistic rates of returns on investments, and hand-delivered letters.
  • The types of investments fraudsters used as bait in 2026 involved gold, property, carbon credits, cryptocurrencies, land banks, and wine.

Fraudsters arrested in Nigeria following NCA intelligence sharing

  • In February 2026, the National Crime Agency (NCA) announced that seven men were arrested in Nigeria after intelligence identified an online investment scam compound targeting UK victims. These arrests were the result of co-operation between the National Crime Agency, Meta and the Nigerian Police.
  • Using hundreds of fake Facebook accounts accounts to impersonate cryptocurrency traders, the Nigeria-based scammers targeted people who used legitimate investment platforms.
  • The scam compound was also allegedly recruiting and training young people in targeting victims for future investment frauds and phishing attacks. A total of 26 phones, 42 sim cards and a laptop were seized on 13 January.

Analyst Comment 

H1 2026 reinforces the transition from email-centric fraud campaigns to social-media-powered fraud operations, with platforms increasingly serving as the primary source of victims for organised cybercriminal groups. Fraudsters are also adapting scams to the culture and user behaviour of individual platforms, such as generate short promotional videos on TikTok or listing fake items for sale on Facebook Marketplace. Rather than deploying identical scams everywhere, criminals tailor campaigns to the platform's intended purpose. Recommendation algorithms and advertising ecosystems provide fraudsters with scalable victim acquisition channels that were previously unavailable through traditional phishing campaigns.

Advances in artificial intelligence (AI) and large language models (LLMs) has also meant it is much easier for cybercriminals to carry out scams on a much larger scale than they were previously able to. Autonomous systems can enable them to send out messages at scale and contact users by telephone at scale. Plus the scam attempts are also more convincing as they can mimic voices and appearance of celebrities or even a target’s friends and family.

The scale of fraudulent activities across social media is so large, it requires vast resources and expertise to monitor, detect, and prevent. At the same time, the response from HMRC, banks, social media companies, the NCA, and international law enforcement suggests increasing recognition that combating social media fraud requires coordinated action.

The volume of fake accounts on social media used for scams does also validate the calls for increased verification and security checks on such platforms. The UK Government's proposal to introduce a national digital ID system, however, was met with fierce opposition. Up to 2.9 million people signed a UK parliament petition to show their disagreement with such a system.

Defensive Takeaways 

  • Reduce Public Exposure: Fraudsters increasingly use information shared on social media to personalise scams and identify potential victims. Consider making profiles private or limiting visibility to trusted contacts and if you no longer actively use a social media platform, consider deleting the account entirely.
  • Be on Guard for Scams: Sponsored advertisements should not automatically be considered legitimate. Refuse any financial rewards in exchange for your login credentials. Be cautious of investment opportunities promoted solely through social media. Assume Facebook Marketplace listings can be fraudulent.
  • Report Suspicious Activity: Reporting scams helps remove fraudulent content and supports law enforcement investigations. Useful UK reporting channels include Report Fraud and the UK NCSC's Suspicious Email Reporting Service report@phishing.gov.uk.
  • Seek Support after a Scam: Victims should not assume financial losses are unrecoverable. It can be possible to get funds returned if they contact their bank immediately, preserve screenshots and transactions records, and report the incident to Report Fraud. Further, if a victim is dissatisfied with how their bank handled their case, they can complain to the Financial Ombudsman Service.

Relevant Sources 

  1. https://www.independent.co.uk/news/uk/crime/tiktok-hmrc-tax-fraud-scam-b2989914.html
  2. https://www.thetimes.com/article/840020a8-1210-47c9-9262-e3139116b652?shareToken=771d08288cd2ac9d0ba13194f43d75a0
  3. https://www.theguardian.com/money/2026/jun/15/investment-fraud-uk-more-than-220m-lost-last-year-scams-ai
  4. https://www.ukfinance.org.uk/system/files/2026-06/UK%20Finance%20Fraud%20Report%202026.pdf
  5. https://www.nationalcrimeagency.gov.uk/news/fraudsters-arrested-in-nigeria-following-nca-intelligence-sharing 

Hermes AI Agent Used in Cyberattack Targeting Thailand Finance Ministry

Hermes AI Agent

A Hermes AI agent was used to automate parts of a cyberattack targeting Thailand's Ministry of Finance, according to research by Hunt.io and security researcher Bob Diachenko. The investigation found evidence of an operator using the agent in unattended "YOLO" mode while staging exploit code, web shells, stolen credentials and a previously unreported Hades implant on exposed infrastructure. The research team identified three open directories on a Hong Kong-hosted server between July 9 and 13, 2026. The directories contained 585 files totaling about 470 MB of attack code and stolen credentials. The material included tools targeting the ministry's internal systems, multiple known vulnerabilities and payloads for both Windows and Linux environments.

Hermes AI Agent Ran Unattended Attack Operations

The investigation found logs showing the Hermes AI agent enumerating hosts associated with the Ministry of Finance, traversing files and collecting privilege escalation information from an adjacent system. Hermes was reportedly operated in YOLO mode, which removes prompts requiring human approval for potentially dangerous commands. Logs recovered from the exposed directories showed the agent using LinPEAS to assess privilege escalation opportunities and enumerate services, files and system information. Researchers also found evidence that the agent was instructed to search content connected to the Office of the Permanent Secretary for Finance. The material included PDF, DOC and XLS files, along with personnel records. However, the researchers said there was no evidence that these files had been exfiltrated. The investigation also identified a custom LinPEAS script configured to scan for several 2026 Linux kernel vulnerabilities, including CVE-2026-43503, CVE-2026-31431 and CVE-2026-43284/CVE-2026-43500.

Hades Implant Found in Windows and Linux Payloads

The 10 July directory contained 62 compiled binaries for Windows and Linux. Analysis of two recovered samples confirmed that they belonged to the same custom malware codebase, which the operator referred to as the Hades implant. The malware communicates over HTTPS and uses URI paths designed to resemble legitimate web traffic. Its communications are encrypted using AES-256-GCM with a hardcoded key for each build. The Windows and Linux versions also included different persistence and execution capabilities. The Windows build supported persistence through Registry Run keys and scheduled tasks, while the Linux version used cron jobs. The Windows sample also supported screenshot capture and process hollowing, while both versions included interactive shell, SOCKS proxy and file transfer capabilities. The recovered samples contained hardcoded command-and-control addresses that researchers said linked the malware to additional infrastructure identified through TLS certificate analysis.

Attackers Targeted Thailand's Ministry of Finance Infrastructure

Custom scripts found across the exposed directories referenced Thailand's Ministry of Finance systems, including an administrative web panel, Hadoop infrastructure and the Ambari management platform. Researchers identified tooling designed to target Apache HiveServer2 using hardcoded credentials and a malicious Hive user-defined function capable of executing commands. Additional scripts targeted an internal GlassFish application server and attempted to deploy web shells. The investigation also uncovered scripts testing mailbox credentials against ministry mail infrastructure, along with session material associated with an internal administration panel and document management platform. The attackers had also staged exploit code targeting several known vulnerabilities, including CVE-2021-3156, CVE-2021-4034 and CVE-2017-7269. The research noted that the tooling indicated preparation for privilege escalation and further movement within targeted systems.

Researchers Link Infrastructure to Ongoing Activity

Hunt.io identified three exposed directories hosted on 43.246.208[.]207, an IP address associated with infrastructure in Hong Kong. TLS certificate analysis connected the activity to two additional servers in Malaysia and Hong Kong. The researchers also identified a separate IP address in the Hermes configuration that appeared to have been used to connect to the staging server. According to the investigation, the activity appeared to be ongoing when the exposed directories were discovered. The combination of an autonomous AI agent, a cross-platform implant and custom tools targeting specific Ministry of Finance systems indicated significant preparation by the operator. The initial method used to gain access to the Ministry of Finance network remains unknown. Researchers said they found no evidence confirming that data had left the network. Thailand's national CERT and National Cyber Security Agency were notified on July 15, 2026, and acknowledged receipt the same day. The research was published following a standard seven-day disclosure window. The investigation assessed with low to medium confidence that the actor may be Chinese-speaking or closely familiar with the Chinese language, based on the infrastructure history and language-related indicators. Researchers said they would continue tracking the activity and associated infrastructure.

Thailand’s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged

Hunt.io uncovered a cyber-espionage attack on Thailand’s Finance Ministry using Hermes AI agent and Hades malware for reconnaissance and persistence.

Researchers at Hunt.io have uncovered an intrusion targeting Thailand’s Ministry of Finance that offers a rare look inside a live cyber-espionage operation. Instead of recovering malware after the fact, the team found exposed staging servers containing attack tools, stolen credentials, active session material, AI agent logs, and a previously undocumented implant dubbed Hades. The findings suggest the operation was still unfolding when the infrastructure was discovered.

The investigation, conducted jointly by Hunt.io and security researcher Bob Diachenko, traced the activity to three publicly accessible directories exposed between July 9 and July 13 on a Hong Kong-hosted server. Together they contained nearly 600 files, including exploit code, web shells, custom scripts, compiled implants, and credentials targeting Thailand’s Ministry of Finance (MOF). Investigators also found evidence that the operator had already established access to multiple internal systems, although the initial intrusion vector remains unknown.

One of the most interesting aspects of the operation is the use of Hermes, an open-source autonomous AI agent. Rather than acting as a chatbot, Hermes functioned as an operator assistant capable of executing commands without waiting for approval.

“The attack, targeting Thailand’s Ministry of Finance (MOF) was largely driven by Hermes, an autonomous AI agent using “YOLO” mode. Additionally, we identified an unreported Go implant the operator refers to as “Hades”.” reads the report published by Hunt.io “Active session cookie files, deployed webshells, and internal network access indicate the operator was able to compromise multiple systems within the MOF network. How initial access was obtained was not immediately evident from the reviewed documents.”

Logs recovered from the exposed directories show the framework running in its so-called YOLO mode, allowing potentially dangerous commands to execute automatically. The recovered logs reveal the agent performing privilege escalation checks, file enumeration, service discovery, and reconnaissance across ministry systems.

This isn’t science fiction anymore. It’s simply offensive automation. The only thing missing was someone forgetting to close the directory listing, which, fortunately for defenders, is exactly what happened.

The exposed infrastructure also hosted a custom Go-based malware family that researchers named Hades. Windows and Linux versions shared the same codebase and supported encrypted command-and-control communications, persistence, interactive shells, file transfers, SOCKS proxying, and, on Windows, process hollowing and screenshot capture. Runtime variables also revealed operational safeguards such as configurable working hours and kill dates designed to reduce the implant’s visibility.

The investigation paints the picture of an operator that invested considerable effort in understanding the ministry’s internal environment. Custom scripts specifically targeted Apache Hadoop infrastructure through HiveServer2, abusing default authentication behavior and malicious Hive user-defined functions to execute operating system commands.

“Purpose-built scripts target MOF Hadoop infrastructure with a HiveServer2 client using hardcoded credentials and a malicious Hive UDF issuing commands and returning output over WebHDFS.” continues the report.

Separate tooling focused on Apache Ambari management servers, GlassFish administration consoles, internal web applications, ministry mail services, and document management platforms. Researchers also recovered web shells disguised as legitimate system files together with scripts designed to validate mailbox credentials and reuse active web sessions.

Privilege escalation capabilities were already staged inside the infrastructure. The directories contained exploit code for well-known vulnerabilities, including PwnKit (CVE-2021-4034), the sudo heap overflow (CVE-2021-3156), and the long-standing IIS WebDAV vulnerability (CVE-2017-7269). The recovered payloads suggest the attackers prepared multiple options depending on the operating systems encountered after compromising the target network.

Researchers also mapped additional infrastructure by pivoting on TLS certificate characteristics and command-and-control configuration embedded in Hades. That analysis identified multiple related servers hosted in Hong Kong and Malaysia, reinforcing the conclusion that the exposed server was only one component of a broader operational infrastructure.

The Hermes logs provide perhaps the clearest evidence of how AI is beginning to reshape offensive operations. Rather than issuing every command manually, the operator delegated routine reconnaissance tasks to the agent, which executed LinPEAS, searched for privilege escalation opportunities, traversed ministry directories, and catalogued files belonging to the Office of the Permanent Secretary for Finance.

Hunt.io noted that it found no evidence those documents had been exfiltrated, but the logs show the attackers systematically expanding their visibility inside the environment.

“The agent made use of the open-source project LinPEAS (Linux Privilege Escalation Awesome Script) to further move through the network.” continues the report. “Additional logs indicate the operator instructed the agent to enumerate a content directory containing PDF, DOC, XLS files, and personnel records associated with the Office of Permanent Secretary for Finance. There is no evidence the files were exfiltrated.”

While the researchers stopped short of attributing the operation to a specific threat actor, they assessed with low-to-medium confidence that the operator is Chinese-speaking or closely familiar with the language. That assessment is based on several indicators, including the infrastructure’s historical association with ShadowPad, the presence of an active VShell command-and-control server, Hong Kong-based hosting, Chinese-language artifacts found during the investigation, and the use of FOFA, a Chinese internet reconnaissance platform.

Beyond the specific victim, this case illustrates how autonomous AI agents are becoming practical offensive tools rather than experimental projects. Hermes wasn’t writing phishing emails or generating malware samples. It was performing the repetitive work that normally consumes an operator’s time, allowing the human behind the keyboard to focus on higher-value decisions while the agent quietly mapped the target’s environment. That’s a capability defenders should expect to encounter far more often in future intrusions.

“Most of the tools here are ones we have seen before. The combination is what stands apart: an AI agent coordinating the work, a cross-platform implant holding access, and scripts written for this specific target. Together they describe an operator who invested significant preparation into penetrating a single government target. The method of initial access remains unknown.” concludes the report. “The server’s history as a ShadowPad controller, active VShell C2, Hong Kong-based infrastructure and Chinese-language indicators, point to a low-to-medium confidence assessment that the actor behind this activity is Chinese-speaking or intimately familiar with the language. “

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Hermes AI)

June 2026 Security Issues in Korean & Global Financial Sector

Statistics on Malware Distributed to the Financial Sector In the June threat analysis for the financial sector, phishing was the most prevalent attack method in Attack Stage 1, while droppers/downloaders (distribution tools that download additional malware) were the most prevalent in Attack Stage 2. Infostealers were identified in the third attack stage, indicating that multi-stage […]

June 2026 Dark Web Breach Incident Trend Report

Note The June 2026 Dark Web Breach Incident Trend Report is based on major data breach cases posted on the deep web and dark web forums. Due to the nature of some sources, it was difficult to fully verify the accuracy of certain information, so the report includes content that requires further verification. Major Issue […]

May 2026 Dark Web Threat Actor Trend Report

Notes the May 2026 Dark Web Threat Actor Trend Report summarizes the trends of threat actors and hacktivists operating on the deep web and dark web. some statements are not factually verifiable. Major Issues hacktivist activity targeting the South Korean Region was concentrated. some hacktivist groups claimed DDoS attacks against the website of the South […]

Solving the Multi-Tenancy Identity Crisis in Modern Finance

Explore how to solve multi-tenancy identity challenges in modern finance with secure IAM strategies, improving access control and compliance.

The post Solving the Multi-Tenancy Identity Crisis in Modern Finance appeared first on Security Boulevard.

U.S. Treasury Rolls Out Cybersecurity Information Sharing Initiative as Crypto Attacks Rise

digital asset cybersecurity initiative

The U.S. Department of the Treasury has unveiled a new digital asset cybersecurity initiative, aimed at strengthening defenses across the rapidly growing digital asset ecosystem. The initiative, announced by the Treasury’s Office of Cybersecurity and Critical Infrastructure Protection (OCCIP), seeks to provide timely and actionable cyber threat intelligence to eligible U.S.-based digital asset firms. The move comes amid escalating cyberattacks targeting cryptocurrency platforms and follows recommendations outlined in the federal report “Strengthening American Leadership in Digital Financial Technology.”

Understanding About Digital Asset Cybersecurity Initiative 

At its core, the digital asset cybersecurity initiative will extend high-quality threat intelligence, previously reserved for traditional financial institutions—to digital asset companies and industry organizations. This includes insights that help firms detect, prevent, and respond to cyber threats affecting their platforms, customers, and infrastructure. “Digital asset firms are an increasingly important part of the U.S. financial sector, and their resilience is critical to the health of the broader system,” said Luke Pettit, Assistant Secretary for Financial Institutions. “By extending access to the same high-quality cybersecurity information used by traditional financial institutions, Treasury is helping promote a more secure and responsible digital asset ecosystem,” he added further. Eligible firms that meet Treasury criteria will receive this information at no cost, signaling a broader push to align cybersecurity standards across financial sectors.

Rising Threats Drive Urgency for Digital Asset Cybersecurity

The digital asset cybersecurity initiative comes at a time when cyber threats against cryptocurrency platforms are intensifying in both scale and complexity. Treasury officials emphasized that the initiative directly responds to this evolving threat landscape. “Cyber threats targeting digital asset platforms are growing in frequency and sophistication,” said Cory Wilson, Deputy Assistant Secretary for Cybersecurity. “This initiative expands access to actionable threat information that helps firms strengthen defenses, reduce risk, and respond more effectively to incidents.” Recent incidents emphasize the urgency. Alleged North Korean hackers reportedly stole $280 million from crypto platform Drift using a complex attack. Industry-wide losses exceeded $3.4 billion last year, with billions more lost annually over the past five years. In another case, Bitcoin ATM operator Bitcoin Depot disclosed a cyberattack on March 23 that resulted in losses exceeding $3.6 million. Additional breaches this year have reported losses of $26 million and $40 million, highlighting persistent vulnerabilities across the sector.

Government Push Amid Ongoing Crypto Crime

Despite increased enforcement efforts, cybercriminals and nation-state actors continue to exploit weaknesses in the digital asset ecosystem. U.S. authorities, including the Justice Department, have ramped up prosecutions and issued repeated warnings about infiltration attempts, particularly by North Korean threat groups. However, these measures have had limited success in curbing attacks. Threat actors continue to exploit coding flaws, social engineering tactics, and employee vulnerabilities to gain access to crypto platforms. The digital asset cybersecurity initiative is designed to complement these efforts by shifting focus toward proactive defense and real-time intelligence sharing rather than reactive enforcement alone.

Strengthening the Future of Digital Finance

Treasury officials also framed the digital asset cybersecurity initiative as a foundational step for the future of digital finance. As digital assets become more integrated into mainstream financial systems, cybersecurity is emerging as a critical pillar for sustainable growth. “This initiative reflects the principles of the GENIUS Act by promoting responsible innovation grounded in strong cybersecurity and operational resilience,” said Tyler Williams, Counselor to the Secretary for Digital Assets. “As digital assets become more integrated into the financial system, access to timely and actionable cyber threat information is essential to protecting consumers and safeguarding the stability of U.S. financial markets,” Williams added. The broader federal strategy emphasizes balancing innovation with security. The Treasury’s report highlights the need for regulatory clarity, risk mitigation, and public-private collaboration to support the long-term growth of digital assets while addressing illicit finance and cyber risks.

A Step Toward Industry-Wide Cyber Resilience

With cyberattacks continuing to disrupt the crypto ecosystem, the digital asset cybersecurity initiative represents a significant step toward improving industry-wide resilience. By bridging the gap between traditional financial cybersecurity frameworks and emerging digital asset platforms, the initiative aims to create a more secure and stable environment for innovation. As digital assets evolve from niche technology to a core component of global finance, initiatives like this may play a key role in shaping how the industry manages risk, and whether it can keep pace with increasing cyber threats.

Black Friday chaos: The return of Gozi malware

On November 29th, 2024, Black Friday, shoppers flooded online stores to grab the best deals of the year. But while consumers were busy filling their carts, cyber criminals were also seizing the opportunity to exploit the shopping frenzy. Our system detected a significant surge in Gozi malware activity, targeting financial institutions across North America.

The Black Friday connection

Black Friday creates an ideal environment for cyber criminals to thrive. The combination of skyrocketing transaction volumes, a surge in online activity and often lax security awareness among users provides fertile ground for launching attacks. Gozi malware, a well-known banking Trojan, exploits this seasonal chaos to target unsuspecting users and financial institutions alike.

This year’s Black Friday activity was particularly concerning, with a notable increase in web-inject attacks. These sophisticated techniques compromised online banking sessions, enabling the theft of credentials, financial information and other sensitive data.

The campaign is not expected to stop there. With the subsequent year-end shopping rush, Gozi malware is poised to continue its onslaught. Cyber criminals are likely to capitalize on the desperation of last-minute shoppers seeking the best holiday deals, amplifying the malware’s reach and impact.

These ongoing attacks emphasize the need for vigilance and proactive security measures. Whether you’re a consumer enjoying the convenience of online shopping or a business managing increased transaction volumes, understanding the evolving tactics of cyber criminals is critical to staying ahead of the threat.

What is Gozi malware?

Gozi, also known as Ursnif and ISFB, is a modular banking Trojan that has been active since the mid-2000s. It is infamous for its ability to steal banking credentials, monitor user activity and execute advanced web-injects during online banking sessions. Over the years, it has evolved to include features like anti-debugging mechanisms and encrypted communication and is also used for targeted attacks on specific regions and financial institutions.

Observations from our system

During Black Friday, our telemetry revealed the following trends:

  • Targeted campaigns: Gozi operators appeared to focus on North American banks, aligning their campaigns with the peak shopping hours.
  • Increase in attack volume: The malware’s web-inject functionality was heavily used, indicating a rise in compromised banking sessions.

Why the surge?

The Black Friday spike in Gozi activity can be attributed to:

  • Volume of transactions: The sheer number of financial transactions increases the probability of successful attacks.
  • Weakened defenses: Many businesses prioritize frictionless user experience, uptime and sales during Black Friday, potentially delaying or weakening their security measures.
  • Human behavior: Consumers are more likely to overlook suspicious activity when rushing to grab deals.

What we found

The provided script demonstrates a sophisticated web injection attack used to compromise online banking sessions. It dynamically injects malicious code into the legitimate banking page, allowing attackers to manipulate the session without the victim’s knowledge. The malicious script operates in the background to steal sensitive data, such as credentials, and is designed to evade detection by immediately removing itself from the page after execution. By blending with the legitimate page and erasing evidence, the attack becomes nearly invisible to both users and traditional security measures. This highlights the growing sophistication of web-inject attacks and underscores the need for advanced monitoring systems and robust security measures to detect and prevent such threats.

Figure 1: Sample of Gozi injection

From the screenshot below, it appears that the attacker left minimal evidence, likely attempting to test the mechanism and ensure everything is functioning correctly:

Figure 2: Attacker preparation

We believe the web-inject is still a work in progress, with potential future updates and enhancements to the code likely.

If you’d like to learn more about Gozi malware, you can find additional information here.

Final thoughts

As cyber criminals continue to exploit global events like Black Friday, staying vigilant is more crucial than ever. The resurgence of Gozi malware activity highlights the importance of proactive security measures for both businesses and individuals. While the current attacks are predominantly targeting North America, we suspect this campaign will soon expand to Europe, leveraging the holiday shopping season to further its impact.

While we enjoy the convenience of online shopping, it’s vital to stay aware of the ever-present cyber threats lurking in the digital landscape. By adopting robust security practices and remaining cautious, we can reduce the risks and protect ourselves against these sophisticated attacks. Cybersecurity is not just a technical challenge—it’s a shared responsibility.

How to avoid Gozi malware

Here are some recommendations to avoid Gozi malware and protect yourself from similar threats:

  • Be wary of email links. Exercise caution when opening email attachments or clicking on links, especially if they come from unknown or suspicious sources. Be particularly vigilant for phishing emails that may attempt to trick you into downloading malware.
  • Increase your password security. Create strong and unique passwords for all your online accounts, including cryptocurrency exchanges and wallets. Avoid using easily guessable information and consider using a reliable password manager to securely store and manage your passwords.
  • Remain vigilant online. Pay attention to any unusual behavior or unexpected requests when accessing websites, especially financial or cryptocurrency-related platforms. If you encounter unexpected pop-ups, requests for additional personal information or changes in website appearance, it could be a sign of a web-inject attempting to deceive you.
  • Stay informed about the latest cybersecurity threats and best practices. Familiarize yourself with common techniques used by cyber criminals, such as phishing scams and social engineering, to avoid falling victim to their tactics.

One of the best tools to detect Gozi malware and protect your organization is IBM Security Trusteer Pinpoint Detect. The tool uses artificial intelligence and machine learning to protect digital channels against account takeover and fraudulent transactions and detect user devices infected with high-risk malware. Learn more here.

IOC

/usbank/inj[.]php

/in/sella/sella[.]php

/in/paypal/p[.]php

/in/ebay/ebay[.]php

/in/poste/po[.]php

/in/ubibanca/ub[.]php

/in/amazon/a[.]php

/in/clienti.chebanca/ch[.]php

/in/credem/cr[.]php

frcorporateonline/inj[.]php

hsbcnet/inj[.]php

/lancher/in

The post Black Friday chaos: The return of Gozi malware appeared first on Security Intelligence.

❌