Threats Tagged 'cryptocurrency payments'
View all threats tagged with 'cryptocurrency payments'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cryptocurrency payments'
Click on any threat for detailed analysis and mitigation recommendations
Balonx Sistema is a sophisticated Phishing-as-a-Service (PhaaS) platform originating from Mexico that targets over 20 financial institutions. It uses real-time WebSocket session hijacking to bypass multi-factor authentication and distributes a Spyroid-based Android Remote Access Trojan (RAT) via fake security alerts. Since October 2025, it has harvested credentials from more than 1,100 victims. The platform includes CallFlow, an AI-driven vishing module leveraging GPT-4o-mini, ElevenLabs synthetic voice, and OpenAI Whisper to automate telephone fraud without human operators. It employs continuous domain rotation across more than 350 domains since 2019 and maintains centralized PostgreSQL infrastructure. The service is openly promoted on Facebook groups and generates approximately $99,000 USD weekly through subscription fees. Indicators such as IP 196.251.84.11 and multiple domains are associated with this threat. The platform primarily targets Mexican financial institutions. Join the discussion | AlienVault OTX General | 08/19/2026, 15:40:17 UTC Added: 08/20/2026, 08:22:26 UTC |
Iran's Ministry of Intelligence has broadened its Handala brand beyond cyber operations to include physical threats and influence campaigns targeting US and Israeli interests. The expansion encompasses multiple personas: Handala Popular Resistance Front claiming physical attacks inside Israel, VIPEmployment recruiting proxies globally for espionage and sabotage, and MOISIRAN conducting surveillance operations. These entities engage in coordinated amplification across platforms, soliciting individuals to conduct attacks for financial rewards. The consolidation creates a multi-domain threat combining hacktivist activities with physical operations, espionage recruitment, and influence campaigns. This approach leverages Handala Hack Team's recognition to amplify recruitment efforts while increasing risks to law enforcement, military, intelligence personnel, and critical infrastructure across targeted regions. Join the discussion | AlienVault OTX General | 06/02/2026, 14:38:53 UTC Added: 06/03/2026, 09:33:37 UTC |
Showing 1 to 2 of 2 results