H1 2026 banking-malware campaign via compromised corporate mailboxes
Campaign
Summary
Hide ▲
Show ▼
A banking-malware campaign used compromised corporate mailboxes to reach users in Czechia, Slovakia, Poland and Lithuania, pushing the attack into victims' banking sessions. The messages looked like routine shipment, invoice and scanned-document emails, which helped the lure blend into normal business traffic. The attachment launched JavaScript, then PowerShell, then shellcode, before the malware altered proxy settings and installed a browser add-on. The chain showed how a trusted account can deliver the first stage of an operation while later steps reshape the browser session used for banking.
Timeline
-
07.08.2026 17:00 2 articles · 2h ago
Compromised corporate mailboxes delivered banking malware to users in Czechia, Slovakia, Poland and Lithuania
Initial DisclosureGen Threat Labs described a banking-malware campaign that used compromised corporate mailboxes to deliver shipment, invoice and scanned-document lures to users in Czechia, Slovakia, Poland and Lithuania. Opening the attachment launched JavaScript, then PowerShell and shellcode, before the malware modified proxy settings and installed a browser add-on close to the victim's banking session.
Show sources
- Real emails, hijacked payments: Two H1 2026 attack chains — www.bleepingcomputer.com — 07.08.2026 17:00
- Real emails, hijacked payments: Two H1 2026 attack chains — www.bleepingcomputer.com — 07.08.2026 17:00