Gen Threat Labs followed two H1 2026 campaigns where attackers used legitimate accounts, browser settings and blockchain data as part of the attack path.
The Gen Threat Report is a twice-yearly examination of the biggest cyber threats shaping the digital landscape, offering an in-depth look at the trends affecting consumers around the world. Gen's H1 2026 Threat Report has its share of headline numbers.
Scams accounted for almost 46% of Gen threat detections in the first half of the year. Malvertising represented almost another 30%. Gen blocked 114.2 million e-shop scam attacks and 20.3 million tech support scam attacks during the same period.
Those figures are useful, but they compress very different attacks into a handful of categories. A detection count does not show how the first lure became script execution, how the script became a browser or proxy change, or how a wallet address was replaced before the victim signed a transaction.
Two H1 investigations are worth looking at in detail. In the first, a banking-malware campaign started with compromised corporate mailboxes and ended with proxy and browser manipulation.
In the second, a cryptocurrency campaign used a Rust-based clipper and retrieved command-and-control infrastructure pointers from Binance Smart Chain.
The payloads were different, but neither campaign depended on breaking the trusted system in front of the user. The banking campaign used a legitimate account to deliver the lure. The clipper let the blockchain record a valid transaction after changing the destination address locally.
The business email really came from a business
The banking campaign targeted users in Czechia, Slovakia, Poland and Lithuania. The lures looked like normal business emails: shipment notices, invoice-related messages and scanned document notifications. One simply told the recipient that a scanned copy of a shipment was attached.
In several cases, the messages were sent from compromised corporate mailboxes. The email was not made to look like it came from a legitimate company. It came from a legitimate account that attackers had already taken over.
... continue reading