Threats

H1 2026 Attack Chains: Email Hijacking and Crypto Theft

August 8, 2026 16:07 · 12 min read
H1 2026 Attack Chains: Email Hijacking and Crypto Theft

H1 2026 Attack Chains: A Deeper Look

Gen Threat Labs followed two H1 2026 campaigns where attackers used legitimate accounts, browser settings, and blockchain data as part of the attack path. The Gen Threat Report is a twice-yearly examination of the biggest cyber threats shaping the digital landscape, offering an in-depth look at the trends affecting consumers around the world.

Scams accounted for almost 46% of Gen threat detections in the first half of the year, with malvertising representing almost another 30%. Gen blocked 114.2 million e-shop scam attacks and 20.3 million tech support scam attacks during the same period.

Banking-Malware Campaign

The first campaign started with compromised corporate mailboxes and ended with proxy and browser manipulation. The lures looked like normal business emails: shipment notices, invoice-related messages, and scanned document notifications.

The email was not made to look like it came from a legitimate company; it came from a legitimate account that attackers had already taken over. SPF and DKIM can still pass when a message is sent through authorized infrastructure, while reputation systems may see a sender with a legitimate history.

The attachment launched a JavaScript dropper, which moved through PowerShell stages before reaching shellcode and banking functionality. The available indicators pointed towards GepyS. The malware modified proxy settings and installed a browser add-on, placing itself close to the victim's banking session.

Cryptocurrency Campaign

The second campaign used a Rust-based clipper and retrieved command-and-control infrastructure pointers from Binance Smart Chain. The final payload was a Rust-compiled clipboard hijacker, which monitored copied content for wallet addresses across 21 blockchain types.

When the malware recognized a supported address, it replaced it with an attacker-controlled one. From the victim's point of view, the transaction could still look normal: copy an address, paste it into a wallet or exchange, and approve the payment.

The blockchain was not compromised, and the wallet's cryptography was not broken. The transaction itself was valid, but the destination had already been changed locally before signing.

Detection and Prevention

Detection has to follow the sequence for both campaigns. For the banking chain, sender authentication needs to be paired with post-delivery telemetry. An attachment launching JavaScript, PowerShell retrieving additional stages, shellcode execution, proxy changes, and a new browser extension should be correlated as one sequence rather than handled as unrelated events.

For the crypto campaign, defenders can monitor clipboard-modifying processes, wallet-address pattern matching, and blockchain queries from applications that have no reason to make them. The smart-contract pointer and the infrastructure it resolves should be tracked together rather than treating the current C2 domain as the complete indicator set.

Users making cryptocurrency payments should verify the full destination shown by the signing device or wallet immediately before approval. Address books or allowlists reduce repeated manual entry, while first-time or changed destinations deserve a full comparison rather than a check of only the opening and closing characters.

In both campaigns, the first trust decision could look legitimate while the surrounding workflow had already been changed. Detection and verification need to cover the steps between the authenticated email, the copied value, and the final action.

Gen's H1 2026 Threat Report covers the broader picture across scams, malware, identity exposure, privacy, and AI-driven attacks. The full report includes telemetry, case studies, and guidance on how attacks are moving through trusted workflows.


Source: BleepingComputer

Source: BleepingComputer

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free