ZeroHour

Search: “fraud”

976 stories

China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud

China-linked Jewelbug runs government espionage and crypto fraud from a single XG-Web browser-based control framework.

Broadcom's Symantec and Carbon Black detail Jewelbug, a China-based hackers-for-hire group conducting espionage against governments and militaries in the Middle East, Southeast Asia, and South Asia, plus crypto fraud against Chinese-speaking victims. Operations center on XG-Web, a browser-centric remote-access and infostealing framework, with implants spanning browsers, Windows, Linux, and network devices. The group overlaps with CL-STA-0049, Ink Dragon, Earth Alux, and REF7707, and compromised a Middle Eastern government's webmail across 15 tenants.

The Hacker News · Aug 15, 2026Threat actor in the wild

Hackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection

GoldFactory-linked Gigabud and Vwork malware clone banking apps into hidden Android work profiles to evade fraud detection across 11+ countries.

Group-IB links Vwork, a modified version of the open-source Shelter app cloner, to the GoldFactory group and its Gigabud Android RAT, which clones victim banking apps into an isolated work profile so fraud sessions look clean to banks. From February through July 2026, researchers observed about 1,469 compromised devices and 1,281 potentially compromised logins in Indonesia, with estimated losses near $960,939. Targets span Brazil, Colombia, Egypt, Indonesia, Mexico, Morocco, the Philippines, Thailand, Türkiye, Laos, and a GCC state; delivery uses fake airline, tax, government, and banking apps pushed via phishing sites, messaging apps, and social media.

Cyber Security News · 7d agoMalware in the wild1

WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud

Group-IB details WindRelay, a new Android NFC relay malware paired with SpyNote RAT to relay card data live for contactless payment fraud and loans.

Group-IB identified WindRelay, a previously unseen Android near-field-communication relay malware first seen in the wild in late August 2025, deployed alongside the SpyNote RAT in a contactless payment fraud scheme. Victims are lured via personalized phishing, smishing, or vishing into sideloading an app; SpyNote's Accessibility access silently installs WindRelay, whose reader component captures live EMV APDU card data over NFC and relays it via WebSocket C2 to an emulator component at a payment terminal. The scheme enables dual monetization: RAT-driven remote access to take out digital loans and NFC relay for physical card-present cashouts, known as Ghost Tap. Twenty-three WindRelay samples uploaded to VirusTotal between November 2025 and July 2026 impersonate financial institutions in Czechia, Slovakia, and Slovenia, with the technique also spreading to Brazil and Poland.

The Hacker News · Aug 15, 2026Malware in the wild

Gigabud Uses Android App Cloning to Evade Fraud Detection

Group-IB reports the Gigabud Android banking trojan clones bank apps into isolated work profiles via the Vwork tool to evade fraud detection, with roughly $960,000 in losses in Indonesia.

Group-IB found Gigabud now ships dedicated code to work with Vwork, a weaponized fork of the open-source Android cloning app Shelter it attributes to GoldFactory, exposing cloning functions so any installed app can call them. After installing via phishing sites and messengers posing as airline, tax and government apps, operators request accessibility and overlay permissions, then clone the victim's banking app into a new work profile where it is invisible to signature-based detection in the personal profile. Fake login screens and overlays capture credentials while cloned-app transactions appear to banks as coming from an unrecognized, malware-free device. Between February and July 2026 in Indonesia, Group-IB observed about 1,469 compromised devices, 1,281 potentially compromised logins and estimated losses of roughly $960,939, with Vwork-enabled samples targeting 11 countries including Brazil, Mexico, Egypt and Thailand.

Infosecurity Magazine · 7d agoMalware in the wild

Week in review: Records allegedly stolen from Azure tenants, Medusa ransomware hits 500+ orgs

Week in review: Medusa ransomware hit 500+ orgs per CISA, millions of Azure tenant records allegedly stolen, SafePal and French tax authority breaches disclosed.

Help Net Security's weekly roundup covers the FBI, CISA, and HHS joint advisory update reporting Medusa ransomware has breached more than 500 organizations since June 2021, and threat actor TheHatman's claim of millions of employee records stolen from Azure tenants of Fortune 500 firms including McDonald's, Vodafone, Kyndryl, and Tata Consultancy Services, per Hudson Rock. It also covers the SafePal breach affecting 39,798 customers, France's DGFiP breach exposing data on 678,000 individuals, and UT San delaying its fall semester after a cyberattack. Security items include critical unauthenticated GitLab flaw CVE-2026-19478, an actively exploited patched macOS Screen Sharing flaw deploying a cryptominer, US charges against 17 Mabna Institute Iranian hackers over 31TB of stolen academic data, and Google Mandiant's AI agents finding 100+ high-severity vulnerabilities.

Help Net Security · 25d agoData breach in the wildCVE-2026-19478

Threat Actor Generates 1M Personalized Fraud Emails in 3 Days

Cybercriminals used AI to generate 1 million personalized fraud emails in three days, eliminating the traditional volume-versus-credibility tradeoff.

Dark Reading reports that a threat actor used AI to generate approximately 1 million personalized fraudulent emails within three days. The article highlights that AI now lets malicious email campaigns combine high volume with high credibility, removing a historic constraint on phishing operations. No specific gang, victim list, or tooling is named in the available text.

Dark Reading · 5d agoPhishing & fraud in the wild