Real emails, hijacked payments: Two H1 2026 attack chains

Real emails, hijacked payments: Two H1 2026 attack chains
Gen Threat Labs examined two H1 2026 campaigns that abused trusted systems, including compromised mailboxes, browser and proxy manipulation, clipboard hijacking, and blockchain-based C2 resolution. The report highlights how these attacks bypassed normal trust signals while targeting banking sessions in Europe and cryptocurrency payments through a Rust-based clipper and Binance Smart Chain pointers. #GepyS #XWorm #RemcosRAT #BinanceSmartChain

Keypoints

  • Compromised corporate mailboxes delivered banking-malware lures that looked like ordinary business emails.
  • The banking chain used JavaScript, PowerShell, shellcode, and browser or proxy changes to reach the victim’s session.
  • A Rust-based clipper replaced copied cryptocurrency wallet addresses before the victim signed the transaction.
  • The crypto campaign used Binance Smart Chain and EtherHiding to retrieve C2 infrastructure pointers from smart-contract data.
  • Defenders should correlate delivery, execution, and post-delivery changes instead of treating each event separately.

Read More: https://www.bleepingcomputer.com/news/security/real-emails-hijacked-payments-two-h1-2026-attack-chains/