home.social

#financial-fraud — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #financial-fraud, aggregated by home.social.

fetched live
  1. Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource Files

    This analysis examines new obfuscation techniques employed by Gremlin stealer malware to conceal malicious payloads within embedded resources. A variant protected by sophisticated commercial packing utility uses instruction virtualization, transforming code into custom bytecode executed by a private virtual machine. The malware siphons sensitive information including payment card details, browser cookies, session tokens, cryptocurrency wallet data, and FTP/VPN credentials from compromised systems. It exfiltrates data to attacker-controlled servers at hxxp[:]194.87.92[.]109 for potential publication or sale. Recent iterations incorporate expanded Discord token extraction, active financial fraud through crypto clipper functionality that replaces cryptocurrency wallet addresses in real-time, and WebSocket-based session hijacking to bypass modern cookie protections. The malware employs advanced anti-analysis techniques including XOR-encoded payloads in .NET resource sections, identifier renaming, string encryp...

    Pulse ID: 6a073a73501adf1f890b1a5e
    Pulse Link: otx.alienvault.com/pulse/6a073
    Pulse Author: AlienVault
    Created: 2026-05-15 15:23:31

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Cookies #CyberSecurity #Discord #FinancialFraud #ICS #InfoSec #Mac #Malware #NET #OTX #OpenThreatExchange #RAT #RCE #Troll #VPN #bot #cryptocurrency #AlienVault

  2. Indirect Prompt Injection in the Wild: 10 IPI Payloads Found

    X-Labs researchers discovered 10 verified Indirect Prompt Injection (IPI) payloads deployed across live web infrastructure. Unlike direct prompt injection where users send malicious input to AI models, IPI hides adversarial instructions inside ordinary web content. When AI agents crawl or summarize poisoned pages, they ingest and execute these instructions as legitimate commands. The discovered payloads span financial fraud, data destruction, API key exfiltration, and denial-of-service attacks. Attackers employ techniques including CSS invisibility, HTML comments, accessibility attribute abuse, meta namespace spoofing, and system prompt tag impersonation. The shared injection templates across multiple domains suggest organized tooling rather than isolated experimentation. Observed attack intents include unauthorized financial transactions, terminal command execution, content suppression, traffic hijacking, and sensitive information leakage, targeting AI systems that browse web pages, index content for RAG ...

    Pulse ID: 69e9e01bb389be062117de5a
    Pulse Link: otx.alienvault.com/pulse/69e9e
    Pulse Author: AlienVault
    Created: 2026-04-23 09:02:19

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #FinancialFraud #HTML #InfoSec #OTX #OpenThreatExchange #RAT #bot #AlienVault

  3. I asked over the weekend if anyone was watching trading right before the Shitstain's lies about the Strait of Hormuz and massive Iranian concessions in negotiations.

    Pleasantly, there were.

    bsky.brid.gy/r/https://bsky.ap

    There is not enough jail time in the world for these fucks.

    #uspol #uspolitics #politics #fascism #fraud #FinancialFraud #InsiderTrading

  4. Excited to share that the MITRE Fight Fraud Framework™ (F3) is now included in the default MISP galaxy and available across all MISP instances.

    F3 is a curated knowledge base of tactics and techniques used by financial fraud actors, helping analysts structure, share, and enrich fraud-related intelligence more effectively.

    A great step forward for the MISP community and for teams tracking financial fraud.

    🔗 github.com/MISP/misp-galaxy

    @misp
    @circl

    #misp #financialfraud #threatintel #threatintelligence #opensource
    #financial

  5. Times of India | Rs 1,717 crore lost to digital fraud in Delhi since 2023, only 10% recovered: Government

    Delhi lost approximately Rs 1,717 crore to digital payment fraud and online cheating between 2023 and 2025, with only 10% recovered. The Delhi Police reported a significant rise in cases, prompting enhanced measures like the '1930' helpline and a specialized financial fraud mitigation center to expedite fund recovery and raise public awareness.

    Read more: timesofindia.indiatimes.com/in

    #delhi #government #delhipolice #1930helpline #financialfraud

  6. Lock them UP. #Ivanka #FinancialFraud Hiding assets $45M. And where there’s this one, there’s more. Their fraud runs like roaches. Never just one. You see one, you know there’s a nest of them.
    #RachelMaddow Audio only

    youtu.be/5CO4leakvu4?si=nC7w_U

  7. Coimbatore lost ₹87.16 Cr to cyber fraud in 2025! Learn about surging online scams, how fraudsters trap victims, & crucial tips to protect your money. Act fast & report fraud! english.mathrubhumi.com/news/i #CyberFraud #FinancialFraud #Crime #Coimbatore #Fraud

  8. The #EU passed a new law holding #socialmedia #platforms liable for #financialfraud. The law requires platforms to compensate banks when a user is defrauded due to the platform’s failure to remove #reportedscams. This builds on existing regulations like the #DSA and #DMA, which aim to curb #illegalcontent and prevent tech giants from leveraging their dominance. mashable.com/article/social-me #tech #media #news

  9. Over $10 billion lost to cyber scams in 2024 alone—and there's a darker side involving modern slavery. How are sophisticated Southeast Asian networks striking again? Explore the surprising and devastating impact behind the numbers.

    thedefendopsdiaries.com/the-ri

    #cyberscams
    #financialfraud
    #humanrights
    #cryptocurrencyfraud
    #cybersecurity

  10. Financial fraud through AI is quickly becoming a headache for many banks and corporate finance departments. It's only a question of time till the criminal will attack individuals as well.

    bobsguide.com/ai-driven-attack

  11. ‘We Can’t Count on Trump’s SEC to Tell Us If He Is Manipulating the Market’ #Prospect. You can count on it not to! New MAGA (Making America’s Greatest Asshole) tourist pitch: only Fraudsters who bend a knee to Dictator Donald welcome? #DictatorDonald #EmperorElon #UltraFraudsters #EarthSuckered #WarOnDemocraticRepublics
    #FinancialFraud #FascistStates prospect.org/economy/2025-05-0

  12. ⚠️ Mobile security risk: New Android malware "SuperCard X" enables contactless payment fraud via NFC relay attacks 📱💳

    Here’s how it works:
    🔹 Victims are socially engineered through fake bank alerts (smishing + calls)
    🔹 Tricked into installing a rogue app posing as “security software”
    🔹 NFC data is intercepted from real debit/credit cards
    🔹 Attackers relay stolen credentials to PoS terminals and ATMs for fraudulent cashouts

    Why it matters:
    • Attackers no longer need stolen physical cards — just proximity + deception
    • Banking customers, payment providers, and card issuers are all at risk
    • Google is working on Android protections — but vigilance is key now

    🛡️ Tip: Always scrutinize app installs, verify messages before acting, and keep Google Play Protect enabled.

    #CyberSecurity #MobileSecurity #Malware #NFC #FinancialFraud #ThreatIntel #security #privacy #cloud #infosec

    thehackernews.com/2025/04/supe