The report describes confirmed phishing activity targeting the financial sector, where victims were tricked into fake login pages via emails, links, or HTML attachments. The credentials entered were then exfiltrated to attackers through Telegram using APIs. The same report also highlights ongoing dark web data-sale claims and hacktivist DDoS activity, but the most simulation-ready detail is the phishing-to-credential-theft workflow.
Key findings
- Phishing was the top initial access method observed for attacks against the financial sector, and multi-stage chains starting with phishing were described as common.
- Victims were lured to login pages via phishing emails, malicious links, or HTML attachments; entered IDs/passwords were leaked to Telegram using APIs.
- Phishing campaigns used keywords including “money transfer,” “receipt,” and “voicemail.”
- Korean-language attachment filenames commonly masqueraded as business documents, tax/payment receipts, HR documents, and contract documents.
- The report also summarizes dark web data-sale claims involving major financial brands and mentions hacktivist DDoS activity, though not all claims were verified.
Who’s being targeted
- Commonly targeted roles: All employees in financial services, Finance and payments teams, Back-office operations, Helpdesk/service desk (credential reset requests may follow phishing).
- Affected industries: Banking, Financial services, Insurance.
- Attack channels: email.
- Impersonated: Internal business operations or a payments/receipts sender (generic business document source), Voicemail/telephony service (generic).
Awareness takeaways
- Treat HTML attachments as high-risk, do not open them from unsolicited financial emails (receipts, tax, HR, contracts).
- If an email leads you to a login page (especially after clicking a link or opening an attachment), stop and verify via a trusted channel before entering credentials.
- Be extra cautious with common ‘urgent action’ lures like money transfers, receipts, and voicemail notifications, these keywords are actively used in phishing.
Red flags to watch for
- An HTML attachment is used for a “document/receipt,” which is unusual
- The page asks for credentials after opening an attachment
- Urgent finance-themed wording like “receipt” or “payment” used to prompt quick action
- Generic “voicemail” lure that routes to a login page
- Unexpected login prompt reached via email link
- Credential capture is the goal (ID/password requested)
Read the video transcript
You get an email: subject line just says, “Receipt.” There’s an HTML file attached and it looks like a payment document. You open it, and a login page pops up asking for your bank or email ID and password to view the receipt. The moment you type them, those credentials are shot straight to a Telegram chat via an API. Same trick with “Voicemail” emails: you click a link, land on a login page, and your ID and password are quietly relayed to Telegram. The common pattern? Email about money, receipts, or voicemail that suddenly demands a login. Your move: if an email or HTML attachment sends you to a login page, stop. Don’t type anything, go to the site yourself from your browser and log in there instead.