Find notable cyber news and cases, enriched with sources, timelines, and signals.

H1 2026 banking-malware campaign via compromised corporate mailboxes

Campaign
First reported
Last updated
Happening score
H score 33
1 unique sources, 1 articles

Summary

Hide ▲

A banking-malware campaign used compromised corporate mailboxes to reach users in Czechia, Slovakia, Poland and Lithuania, pushing the attack into victims' banking sessions. The messages looked like routine shipment, invoice and scanned-document emails, which helped the lure blend into normal business traffic. The attachment launched JavaScript, then PowerShell, then shellcode, before the malware altered proxy settings and installed a browser add-on. The chain showed how a trusted account can deliver the first stage of an operation while later steps reshape the browser session used for banking.

Timeline

  1. 07.08.2026 17:00 2 articles · 3h ago

    Compromised corporate mailboxes delivered banking malware to users in Czechia, Slovakia, Poland and Lithuania

    Initial Disclosure

    Gen Threat Labs described a banking-malware campaign that used compromised corporate mailboxes to deliver shipment, invoice and scanned-document lures to users in Czechia, Slovakia, Poland and Lithuania. Opening the attachment launched JavaScript, then PowerShell and shellcode, before the malware modified proxy settings and installed a browser add-on close to the victim's banking session.

    Show sources