Skip to content
Tech News
← Back to articles

Real emails, hijacked payments: Two H1 2026 attack chains

read original more articles

Gen Threat Labs followed two H1 2026 campaigns where attackers used legitimate accounts, browser settings and blockchain data as part of the attack path.

The Gen Threat Report is a twice-yearly examination of the biggest cyber threats shaping the digital landscape, offering an in-depth look at the trends affecting consumers around the world. Gen's H1 2026 Threat Report has its share of headline numbers.

Scams accounted for almost 46% of Gen threat detections in the first half of the year. Malvertising represented almost another 30%. Gen blocked 114.2 million e-shop scam attacks and 20.3 million tech support scam attacks during the same period.

Those figures are useful, but they compress very different attacks into a handful of categories. A detection count does not show how the first lure became script execution, how the script became a browser or proxy change, or how a wallet address was replaced before the victim signed a transaction.

Two H1 investigations are worth looking at in detail. In the first, a banking-malware campaign started with compromised corporate mailboxes and ended with proxy and browser manipulation.

In the second, a cryptocurrency campaign used a Rust-based clipper and retrieved command-and-control infrastructure pointers from Binance Smart Chain.

The payloads were different, but neither campaign depended on breaking the trusted system in front of the user. The banking campaign used a legitimate account to deliver the lure. The clipper let the blockchain record a valid transaction after changing the destination address locally.

The business email really came from a business

The banking campaign targeted users in Czechia, Slovakia, Poland and Lithuania. The lures looked like normal business emails: shipment notices, invoice-related messages and scanned document notifications. One simply told the recipient that a scanned copy of a shipment was attached.

In several cases, the messages were sent from compromised corporate mailboxes. The email was not made to look like it came from a legitimate company. It came from a legitimate account that attackers had already taken over.

... continue reading