Two Malware Campaigns Target Banks and Cryptocurrency Payments
Gen Threat Labs reports two malware campaigns: one steals banking sessions, the other hijacks cryptocurrency payments via clipboard manipulation.
Illustrative image generated with AI
Scams and malvertising dominate detections
An analysis by Gen Threat Labs, published on August 7, 2026, describes two campaigns observed during the first half of the year: one targeting banking sessions and the other cryptocurrency payments.
Scams accounted for nearly 46% of Gen’s threat detections, while malvertising approached 30%. The company also blocked 114.2 million attacks involving fake online stores and 20.3 million fake technical-support campaigns.
Convincing emails and banking-session compromise
The first campaign targeted victims in Czechia, Slovakia, Poland, and Lithuania. The messages used familiar themes such as shipping notifications, invoices, and scanned documents. In some cases, they were sent from already compromised corporate mailboxes.
An apparently legitimate attachment contained a JavaScript dropper. Execution continued through PowerShell, which loaded shellcode and subsequently modified proxy settings. The malware also installed a browser extension, bringing the attacker closer to the victim’s banking session.
The indicators link this activity to GepyS, a threat with banking capabilities and the ability to manipulate proxies and browsers. The risks include credential theft and the alteration of transactions during an already authenticated session.
The attack chain included techniques designed to hinder analysis: a 32-bit position-independent loader, MMX and SSE junk instructions, jumps into the middle of instructions, and LFSR- and XOR-based decryption. These techniques are not new, but they can slow down automated static analysis.
The use of legitimate corporate accounts makes phishing harder to identify. SPF and DKIM may still validate when a message is sent through the authorized infrastructure of a compromised mailbox; the sender’s reputation may also appear normal.
In Italy, emails containing fraudulent invoice PDFs, including references to Booking.com, redirected victims to scripts hosted on Vercel. The JavaScript obfuscation was customized for each victim, while the PowerShell stages were hosted on Blogspot and delivered XWorm. In Poland, invoice-themed campaigns instead used a steganography-based .NET loader to install Remcos RAT.
A Rust clipper replaces wallet addresses
The second campaign used a final payload written in Rust and designed to hijack the clipboard. The malware monitored copied addresses for 21 blockchain types, including BTC, ETH, and LTC.
When it recognized a supported address, it locally replaced it with one controlled by the attacker. The victim could then paste the modified address into a wallet or exchange and authorize what appeared to be a routine transaction.
Neither the blockchain nor the wallet’s cryptography was compromised. The transaction remained valid, but its destination had been altered before signing, creating the risk of irreversible loss.
The malware retrieved references to its command-and-control infrastructure from the Binance Smart Chain. No hashes, domains, IP addresses, or complete wallet addresses were disclosed.
How to reduce the risk
No affected software versions, specific patches, or dedicated workarounds have been published. Gen’s full report is cited as the source for telemetry, case studies, and guidance.
Users should treat unexpected attachments with caution, even when they come from seemingly trustworthy corporate senders. SPF, DKIM, and domain reputation are not sufficient to prove that a mailbox has not been compromised.
Before confirming a cryptocurrency payment, verify the address directly in the wallet or signing interface, rather than relying solely on the copied text. If suspicious attachments or browser anomalies are detected, stop accessing banking services and have the device inspected; however, complete technical indicators are not available for targeted threat hunting.
Sources
This article is an original reworking based on the sources below.




