Skip to main content

Threats Tagged 'financial'

View all threats tagged with 'financial'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: financial

Threats Tagged 'financial'

Click on any threat for detailed analysis and mitigation recommendations

Fantasy Hub is a newly identified Android Remote Access Trojan (RAT) offered as Malware-as-a-Service (MaaS) on Russian-language platforms. It provides extensive espionage capabilities including SMS exfiltration, contact and call log theft, and bulk media extraction. The malware can intercept, reply to, and delete incoming notifications, and uses fake Google Play pages to evade detection. It specifically targets financial institutions by deploying fake windows to steal banking credentials. The MaaS model includes comprehensive documentation and a bot-driven subscription system, lowering the barrier for novice attackers. Although no known exploits in the wild have been reported yet, the threat poses a medium severity risk due to its broad capabilities and ease of use. European organizations, especially financial institutions, are at risk due to the malware’s targeting profile and Android’s widespread use. Mitigation requires targeted detection of fake app pages, enhanced mobile security hygiene, and user awareness focused on banking credential phishing. Countries with large financial sectors and high Android adoption, such as Germany, France, and the UK, are most likely to be affected.

Join the discussion

This report analyzes three remote access trojans (RATs) used by a Lazarus subgroup targeting financial and cryptocurrency organizations. The RATs, named PondRAT, ThemeForestRAT, and RemotePE, were observed during incident response cases. PondRAT is a simple RAT used as an initial payload, while ThemeForestRAT offers more functionality and operates in-memory. RemotePE is a more advanced RAT deployed in later attack stages. The actor uses social engineering for initial access and employs various tools for network discovery. The report details the RATs' capabilities, command and control mechanisms, and similarities to previously known malware families. It highlights the actor's persistent threat and evolving tactics in targeting high-value financial targets.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: financial
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses