Threats Tagged 'banking'
View all threats tagged with 'banking'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'banking'
Click on any threat for detailed analysis and mitigation recommendations
A new Android trojan, named NFCShare, has been discovered targeting Deutsche Bank customers through a phishing campaign. The malware, disguised as a banking app update, prompts users to perform a fake card verification process. It exploits NFC technology to steal card data and PINs, which are then exfiltrated to a remote WebSocket endpoint. The trojan's distribution, user flow, and technical analysis are detailed, including its NFC reading capabilities and string obfuscation techniques. The malware shows links to Chinese-linked tooling and similarities to other NFC-based threats. IOCs include hashes, package details, and network indicators. Join the discussion | AlienVault OTX General | 01/30/2026, 08:18:00 UTC Added: 01/30/2026, 08:43:08 UTC |
Fantasy Hub is a newly identified Android Remote Access Trojan (RAT) offered as Malware-as-a-Service (MaaS) on Russian-language platforms. It provides extensive espionage capabilities including SMS exfiltration, contact and call log theft, and bulk media extraction. The malware can intercept, reply to, and delete incoming notifications, and uses fake Google Play pages to evade detection. It specifically targets financial institutions by deploying fake windows to steal banking credentials. The MaaS model includes comprehensive documentation and a bot-driven subscription system, lowering the barrier for novice attackers. Although no known exploits in the wild have been reported yet, the threat poses a medium severity risk due to its broad capabilities and ease of use. European organizations, especially financial institutions, are at risk due to the malware’s targeting profile and Android’s widespread use. Mitigation requires targeted detection of fake app pages, enhanced mobile security hygiene, and user awareness focused on banking credential phishing. Countries with large financial sectors and high Android adoption, such as Germany, France, and the UK, are most likely to be affected. Join the discussion | AlienVault OTX General | 11/10/2025, 11:34:25 UTC Added: 11/10/2025, 11:50:41 UTC |
Recent versions of Zloader, a Zeus-based modular trojan, have introduced significant enhancements to its functionality. These updates include improved obfuscation techniques, anti-analysis strategies, and network communication methods. The malware now supports WebSockets and has modified its DNS tunneling protocol, replacing TLS encryption with a custom algorithm. New LDAP functions have been added to improve network discovery and lateral movement capabilities. Zloader continues to evolve its evasion tactics, including checks for process integrity levels to avoid detection in sandbox environments. The malware has also removed its Domain Generation Algorithm and made changes to its static configuration format. These updates demonstrate Zloader's ongoing development as a sophisticated tool for initial access and potential ransomware deployment. Join the discussion | AlienVault OTX General | 09/22/2025, 19:40:07 UTC Added: 09/22/2025, 21:11:04 UTC |
A large-scale Malware-as-a-Service operation, orchestrated by Chinese-speaking threat actors, has infected over 11,000 Android devices globally with the PlayPraetor Remote Access Trojan. The campaign primarily targets Europe, with significant presence in Portugal, Spain, and France, but also affects Africa, Latin America, and Asia. The botnet is expanding rapidly, with over 2,000 new infections weekly, focusing on Spanish and French speakers. The operation is managed through a sophisticated Chinese-language Command and Control panel, supporting multiple affiliates. PlayPraetor abuses Android's Accessibility Services to gain real-time control over compromised devices, targeting nearly 200 banking apps and cryptocurrency wallets worldwide. Join the discussion | AlienVault OTX General | 08/07/2025, 11:20:26 UTC Added: 08/07/2025, 15:17:45 UTC |
This report analyzes a sophisticated Android malware targeting Indian banking apps. The malware uses a dropper and main payload structure, leveraging permissions like SMS access and silent installation to steal credentials, intercept messages, and perform unauthorized financial activities. It employs Firebase for command and control, phishing pages to mimic banking interfaces, and techniques like call forwarding abuse. The malware's modular architecture, evasion tactics, and persistence mechanisms pose significant threats to mobile banking security. Distribution methods include smishing, fake websites, and malvertising. The report provides detailed static and dynamic analysis, highlighting the malware's capabilities in data exfiltration, debit card harvesting, and remote command execution. Join the discussion | AlienVault OTX General | 07/25/2025, 10:29:03 UTC Added: 07/25/2025, 12:33:10 UTC |
A new Android malware campaign has been discovered, disguising itself as a banking app to covertly mine cryptocurrency on locked devices. The malware, distributed through a phishing website impersonating Axis Bank, downloads and executes a modified version of XMRig, a popular cryptocurrency mining software. It monitors the device's lock state and battery level, initiating mining operations when the device is locked and stopping when unlocked. This stealthy approach allows for persistent mining, leading to excessive heat generation, battery drain, and potential hardware damage. The malware uses multiple hosting platforms to distribute its payload and connects to specific mining pools. Its impact on devices includes high CPU and memory usage, significant temperature increases, and overall performance degradation. Join the discussion | AlienVault OTX General | 07/18/2025, 13:03:31 UTC Added: 07/18/2025, 20:30:58 UTC |
A malicious campaign targeting primarily Brazilian residents has been discovered, with attacks detected since early 2025. The attackers employed phishing emails, some sent from compromised company servers, to distribute malware. Two attack chains were identified: one using a malicious browser extension for Google Chrome, Microsoft Edge, and Brave, and another utilizing Mesh Agent or PDQ Connect Agent. The campaign aimed to steal authentication data from victims' bank accounts, particularly targeting Banco do Brasil customers. Over 700 downloads of the malicious extension were recorded, affecting users in Brazil, Colombia, Czech Republic, Mexico, Russia, Vietnam, and other countries. The attackers used sophisticated techniques, including virtualization checks, UAC bypass, and file deletion to evade detection. Join the discussion | AlienVault OTX General | 06/05/2025, 16:53:44 UTC Added: 06/05/2025, 17:28:45 UTC |
Showing 1 to 7 of 7 results