NEW: Group Profiler — instant APT intel lookup. Try it →

Finance — threat intelligence

Recent advisories whose title or summary heuristically matches the Finance sector. Derived in-browser/at-edge from a keyword catalog — treat tags as a hint and open each source for ground truth. Counts and contents update hourly.

28 recent Finance advisories

  1. INFO malwarebytes-labs · 1d ago

    StreamRat Android malware spreads through Meta and TikTok ads

    Social media ads for a free streaming service exposed roughly 570,000 people to StreamRat, a banking Trojan that can take control of infected phones.

    android
  2. INFO the-record · 2d ago

    Hackers expose donor data from Russian fundraisers for Ukrainians, political prisoners

    Hackers reportedly gained access to payment accounts used by two Russian fundraising projects supporting Ukrainians and political prisoners, exposing donor email addresses and limited payment card information.

  3. INFO thehackernews · 2d ago

    Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control

    Cybersecurity researchers have disclosed details of a new Android banking trojan called StreamRat that was promoted to Spanish-speaking users through a fake television-streaming campaign on Meta and can give operators near-complete control …

    android ES
  4. INFO thehackernews · 2d ago

    Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems

    Brazilian financial services, retail, and e-commerce organizations have become the target of a financially motivated threat actor dubbed Breeze Comet (formerly UNC5669) since 2024. Google Threat Intelligence Group (GTIG) and Mandiant teams …

    mandiant BR
  5. INFO mandiant-blog · 3d ago

    Financially Motivated Threat Actor BREEZE COMET Targets Brazil

    Introduction Beginning in 2024 Mandiant investigated a string of compromises affecting Brazilian financial services, retail, and eCommerce organizations. Google Threat Intelligence Group (GTIG) tracks this activity as BREEZE COMET (formerly…

    mandiant BR
  6. INFO the-record · 3d ago

    Iranian cyber spies target aviation, fintech developers with new malware

    In a report published Tuesday, Kaspersky said it first discovered NodeRabbit on a system in Afghanistan and later identified variants on systems in Egypt and Ethiopia.

    kaspersky AFEGET
  7. INFO the-record · 3d ago

    Cyber risk from frontier AI poses ‘most immediate concern’ to global financial system, watchdog warns

    Andrew Bailey, chair of the Financial Stability Board, called on financial institutions and technology providers to “prepare for more severe scenarios involving simultaneous disruption across multiple firms or shared technology dependencies…

  8. INFO securelist · 3d ago

    Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set

    Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.

    kasperskynodejs
  9. INFO thehackernews · 4d ago

    ⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More

    The boring parts caused most of the trouble. A router shipped ready to listen. A fake check turned the user into the installer. Trusted systems collected traffic and passwords, then cleaned the logs. Old bugs formed new attack chains. Even …

  10. INFO EXPLOITED securityweek · 7d ago

    In Other News: Log4j RCE Scare, Minimus Shutdown, Iranian Hacker Sanctions

    Noteworthy stories that might have slipped under the radar: Manchester Airports Group cyberattack, Carhartt breach data was partly fake, U.S. Bank responds to ransomware gang’s claims. The post In Other News: Log4j RCE Scare, Minimus Shutdo…

    apache-foundation
  11. INFO qualys-blog · 7d ago

    PCI DSS 4.0.1: Application Requirements You’re Being Assessed On in 2026

    Key Takeaways Since March 31, 2025, all 51 former “best practice” requirements in PCI DSS 4.0 have been fully scored. Every 2026 assessment covers them. A large share of the new weight sits in the PCI DSS 4.0.1 application requirements, con…

  12. INFO rapid7-blog · 8d ago

    Identity-as-a-Service: Uncovering Dark Web Marketplaces Trading Executive SSNs

    IntroductionDespite modern verification controls, identity theft remains one of the most pervasive threats to both individuals and enterprise organizations. U.S. Federal Trade Commission statistics show over 1 million identity theft reports…

    US
  13. INFO group-ib-blog · 8d ago

    One Adversary, Two Outcomes: The 0.027% Proof

    One malware campaign, 11,000 compromised devices, two banks with very different outcomes. At the bank with fused defence, fraud succeeded on just 0.027% of compromised devices; nine times less than the market average. Regulators are taking …

  14. INFO darkreading · 11d ago

    ToxicPanda Banking Trojan Matures into Enterprise Threat

    The latest version of the Android malware has new features that expand its global reach and put more than users' financial applications at risk.

    android
  15. INFO malwarebytes-labs · 11d ago

    ToxicPanda 2.0 can take over your Android phone and banking apps

    A new version of the Android banking Trojan can seize control of infected phones and block access to Google Play and Google Play Services.

    google
  16. INFO securityweek · 13d ago

    Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight

    The spyware-equipped Manic, a persistent Grandoreiro campaign in Latin America and Europe, and an expanded ToxicPanda 2.0 malware. The post Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight appeared first on SecurityWeek.

    USEU
  17. INFO the-record · 14d ago

    U.S. Bank says breach claims related to fourth-party incident

    The bank said there is no evidence that its own systems, networks or data repositories were compromised.

    US
  18. INFO malwarebytes-labs · 14d ago

    Medical records, SSNs, and bank details exposed in CareCloud data breach

    Healthcare technology provider CareCloud confirmed that 3.75 million people were affected by a March data breach.

  19. INFO darkreading · 15d ago

    'Grandoreiro' Malware Resurfaces With Mexico Campaign

    The banking Trojan, post-law enforcement takedown, is sprucing itself up with features that make detection and analysis harder.

    MX
  20. INFO thehackernews · 15d ago

    Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices

    A new Android threat codenamed Manic has been observed actively targeting Ukrainian banks, government and identity services, and messaging applications, as well as Russian and European financial institutions, global fintech and cryptocurren…

    android UARUEU
  21. INFO thehackernews · 15d ago

    ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud

    Cybersecurity researchers have shed light on an updated version of ToxicPanda (aka TgToxic) that comes with "significant enhancements," including a set of 167 remote commands and expands its targeting footprint globally. Zimperium zLabs, in…

    android
  22. INFO group-ib-blog · 16d ago

    Balonx Sistema: The Face Behind the PhaaS Affecting Mexican Banking

    Group-IB exposes a Mexican PhaaS operation targeting over 20 financial institutions with live phishing, AI vishing, and mobile RAT capabilities.

    MX
  23. INFO malwarebytes-labs · 17d ago

    Heights Finance data breach: What customers need to know

    Leaked personal and financial data of around 750,000 US citizens, including SSNs and bank details, could put victims at risk of identity theft and phishing.

    US
  24. INFO the-record · 20d ago

    Investigation of banking hack leads to arrests in Germany, Brazil

    Germany’s federal police agency, the BKA, said three suspects were picked up in Europe and charged with fraud, and Brazil’s federal police said four others were arrested on similar charges.

    EUBR
  25. INFO darkreading · 20d ago

    Mission-Driven Security: Inside a Global Bank's Defense

    In this video interview, Standard Chartered's group CISO shares insights on transitioning from technical roles to strategic leadership, the importance of business-savvy security executives, and how AI is reshaping both defensive capabilitie…

  26. INFO malwarebytes-labs · 22d ago

    New Android malware lets criminals use your bank card in real time

    Social engineering, a Remote Access Trojan (RAT), and NFC relay malware walk up to an ATM. It's no joke. Together, they can empty your bank account.

    android
  27. INFO thehackernews · 24d ago

    Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers

    Security researchers invented a cryptocurrency startup, advertised developer jobs, and hired three people they believe were North Korean operatives. Every virtual machine the company issued was recording. The onboarding paperwork is the par…

    KR
  28. INFO EXPLOITED thehackernews · 24d ago

    Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks

    Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world. Targets of these attacks include healthcare and public he…

    fortinetschneider-electric KR

Other sectors: Government ·Healthcare ·Energy ·Critical Infra ·Education ·Technology ·Telecom ·Defense ·Retail ·Transportation ·Legal Services

Also on ThreatFilter: cross-source corroborated CVEs · threat group directory · every source we track