Cyberattacks Get More Sophisticated as Hackers Use Legitimate Accounts to Steal Payments
In a disturbing trend that highlights the evolving tactics of cyber attackers, two recent campaigns have shown how hackers are using legitimate accounts and exploiting browser settings to steal payments from unsuspecting victims. The attacks, which were identified by Gen Threat Labs, used a combination of techniques to bypass traditional security measures and directly target online banking sessions.
The first campaign targeted users in Czechia, Slovakia, Poland, and Lithuania, with attackers sending legitimate-looking business emails that included attachments containing malicious code. These emails were sent from compromised corporate mailboxes, making them appear as if they came from trusted sources. The attachment launched a JavaScript dropper, which then led to PowerShell stages before reaching shellcode and banking functionality.
The malware modified proxy settings and installed a browser add-on, placing itself close to the victim’s online banking session. This allowed hackers to intercept sensitive information and potentially gain access to the victim’s account. According to Gen Threat Labs, the available indicators pointed towards GepyS as the malware responsible for this campaign.
In contrast, the second campaign focused on cryptocurrency theft, using a Rust-based clipboard hijacker to monitor copied content for wallet addresses across 21 blockchain types. When the malware recognized a supported address, it replaced it with its own, allowing hackers to steal funds from victims’ wallets without them even realizing it. This attack was particularly insidious because it exploited a common user behavior – copying and pasting cryptocurrency addresses.
What’s most concerning about these attacks is that they didn’t rely on breaking the trusted system in front of the user. Instead, they used legitimate accounts and browser settings to bypass traditional security measures. This means that even if users have up-to-date antivirus software and are cautious when clicking on links or opening attachments, they can still fall victim to these sophisticated attacks.
The fact that these campaigns were able to evade detection highlights the need for more advanced security measures. While traditional methods such as SPF and DKIM may still pass when a message is sent through authorized infrastructure, reputation systems may not see a sender with a legitimate history. This means that even if an email appears to come from a trusted source, it’s not necessarily safe.
To stay ahead of these threats, users need to be more vigilant than ever. Here are some practical tips to keep in mind:
* Be cautious when opening attachments or clicking on links, especially if they appear to come from a legitimate source.
* Use reputable antivirus software and keep it up-to-date.
* Monitor your online banking sessions closely for any suspicious activity.
* Consider using additional security measures such as two-factor authentication.
By staying informed and taking proactive steps to secure our online activities, we can reduce the risk of falling victim to these sophisticated attacks.
Source: Bleeping Computer — 2026-08-07