The Gen Threat Report is a twice-a-year analysis of the largest cyber threats impacting the digital threat landscape, providing a detailed insight into the trends impacting customers globally. The H1 report has provided some key insights.
“The strongest pattern in the first half of 2026 was the way different threats converged around trust. Scams, account takeovers, malicious packages and AI agents all moved closer to the systems, workflows and permissions people already rely on,” said the report.
46% of Gen threat findings were scams, whereas malvertising amounted for 30%. Gen stopped 114.2 million e-commerce scams and 20.3 million tech support scams.
These numbers are important, but they fit different kinds of scams into a few categories. A discovery does not reveal how the first trap became script execution, or how the script turned into a proxy change or browser, or how a wallet address was changed before the target verified a transaction.
Two important H1 findings
Two H1 investigations should be looked at in-depth. The first is a banking-malware campaign initiated with hacked corporate mailboxes and finished with browser manipulation and proxy.
In the second finding, a cryptocurrency campaign deployed a Rust-based clipper and got C2 infrastructure pointers from Binance Smart Chain.
The payloads are distinct, but none of the campaigns relied on breaking the genuine system at user end. The banking malware used a genuine account to set the trap whereas the clipper allowed the blockchain record an authentic transaction after modifying the local destination address.
Where did the business email come from
The banking campaign attacked users in Lithuania, Poland, Slovakia, and Czechia. The lures appeared to be genuine business emails such as invoice messages, scanned document verifications, and shipment notices.
In various incidents, the texts were sent from hacked corporate mailboxes. The email was not designed to appear as if it came from an authentic organization. The emails were sent from an authentic account that threat actors had already hacked.
DKIM and SPF can still sail through when a message is sent via genuine infrastructure, whereas reputation systems may spot a sender with an authentic history.
The attachment deployed a JavaScript dropper, and then the chain travelled via PowerShell stages before reaching banking functionality and shellcode. The available signs indicate at GepyS.
The malware changed proxy settings and deployed a browser add-on, positioning itself nearby to the target’s banking session.
Read the original article: