Gen Threat Labs examined two H1 2026 campaigns that abused trusted systems, including compromised mailboxes, browser and proxy manipulation, clipboard hijacking, and blockchain-based C2 resolution. The report highlights how these attacks bypassed normal trust signals while targeting banking sessions in Europe and cryptocurrency payments through a Rust-based clipper and Binance Smart Chain pointers. #GepyS #XWorm #RemcosRAT #BinanceSmartChain
Keypoints
- Compromised corporate mailboxes delivered banking-malware lures that looked like ordinary business emails.
- The banking chain used JavaScript, PowerShell, shellcode, and browser or proxy changes to reach the victimβs session.
- A Rust-based clipper replaced copied cryptocurrency wallet addresses before the victim signed the transaction.
- The crypto campaign used Binance Smart Chain and EtherHiding to retrieve C2 infrastructure pointers from smart-contract data.
- Defenders should correlate delivery, execution, and post-delivery changes instead of treating each event separately.