
APT Lures Shift to Jobs, Code Reviews, Cloud Apps
This threat trend report describes multiple real-world APT campaigns that rely on social engineering (job offers, fake recruiters, code reviews, and…
A June 2026 financial-sector threat report describes real phishing emails that used business-looking themes (e.g., money transfers, receipts, voicemail) to push victims to malicious links or HTML attachments that mimic login pages. The report also highlights cases where stolen account information was exfiltrated to attackers via the Telegram API, alongside dark-web sales of financial datasets and access credentials.
This campaign relied on business-sounding email themes such as money transfer notices, receipts, and voicemail alerts to pressure recipients into clicking a link or opening an attachment. Those links and attachments led to login pages designed to harvest credentials. A second variant used attachment filenames crafted to resemble tax and payment receipts or HR and contract documents, aiming to build trust before the recipient opened the file. Phishing was the most common initial access method observed in the financial sector, frequently followed by downloaders or infostealers in multi-stage attack chains.
The lures worked because they mimicked routine business communication that finance, accounting, treasury, and HR staff handle daily. A message about a transfer receipt or a voicemail does not stand out as unusual in these workflows, which lowers scrutiny. Attachment filenames were deliberately structured to resemble real business documents, tax and payment receipts, and HR or contract paperwork, making them look legitimate at a glance. HTML attachments made up the largest share of malicious files, and script-based extensions such as js, vbe, vbs, bat, and hta were also common, both of which can bypass casual visual inspection since they don't look like traditional executable threats.
Organizations in finance, insurance, fintech, banking, and asset management should treat money transfer, receipt, and voicemail-themed emails as high-risk until verified through a separate, trusted channel. Staff should be trained to view HTML attachments with the same caution as executables, since HTML accounted for the largest share of malicious attachments in this reporting period. Because stolen account information was reportedly exfiltrated to attackers through the Telegram API, rapid reporting of suspected phishing matters: the faster a suspicious email is flagged, the less time attackers have to move stolen credentials off-site. Techniques referenced in this campaign map to spearphishing via link (T1566.002), spearphishing attachment (T1566.001), and user execution of malicious files (T1204.001), which security awareness programs can use as a basis for targeted training scenarios.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Attackers used routine business themes like money transfer notices, receipts, and voicemail alerts to get recipients to click links or open HTML attachments leading to fake login pages.
HTML accounted for the largest share of malicious attachments, often paired with script-based extensions like js, vbe, vbs, bat, and hta, which are used to build convincing fake login pages.
Stolen account information collected through malware infections and phishing emails was leaked to attackers through the Telegram API, allowing rapid off-site exfiltration.
Finance, accounting, treasury, HR, procurement, operations, and executive assistant roles are the primary targets, particularly within financial services, insurance, fintech, banking, and asset management.
You get an email: “Subject: Money transfer receipt, please review.” Looks routine, right? The email pushes you to click a link or open an HTML “receipt.” That opens a login page that looks like your bank or finance portal, but it’s fake. Here’s the nasty part: the moment you type your ID and password, that data can be shot straight out through the Telegram API and sold on dark‑web markets within minutes. If an email about money transfers, receipts, or voicemail asks you to log in from a link or HTML file, stop, report it as phishing and verify the request through our normal finance or HR channels.

This threat trend report describes multiple real-world APT campaigns that rely on social engineering (job offers, fake recruiters, code reviews, and…

A state-sponsored campaign in South Korea used spear-phishing and hacked “trusted” local websites to infect visitors who had vulnerable AnySign4PC installed.…

Attackers are taking over hotel and conference Wi‑Fi gateways and changing DNS settings so travelers are silently redirected to fake Microsoft 365 sign-in…

Researchers report multiple real-world email phishing campaigns that used tax and government-benefit themes to trick people into downloading malware. The…

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims…

Proofpoint observed real phishing campaigns using government-themed lures to trick people into downloading ZIP files that install malware. The campaigns used a…