Home
Elezar
Sol Threat Intelligence

June 2026
Finance, Bank and Payment
Regional Sector Brief

Download PDF
1 Jun to 30 Jun 20263 regionsPrepared by Kaartheeswaran Ravichandran
A futuristic financial cyber-vault under digital attack
Americas
Executive Summary
Ransomware concentration, browser credential theft and trusted-cloud delivery

The Americas finance, banking and payment sector was exposed to a ransomware-dominated threat environment during June 2026. The United States was the most targeted country globally in all four tracked weeks, ranging from 32.10 percent to 45.59 percent of global ransomware victims. Canada reached 7.35 percent in the first tracked week. The source set also identified DragonForce, Securotrop, 3AM ransomware and GoldenGh0stLoader as high-relevance threats to financial infrastructure and developer environments.

Key Insights
1
The United States led global ransomware victimization during every tracked June week, with a range of 32.10 to 45.59 percent.
2
DragonForce targeted organizations with annual revenue of at least USD 15 million and used vulnerable drivers to disable endpoint protection.
3
Securotrop, a Qilin affiliate, deployed Chrome credential harvesting through Group Policy to all domain-joined systems.
4
3AM ransomware achieved full domain compromise through email bombing, IT vishing, Quick Assist and QEMU-based EDR evasion.
5
GoldenGh0stLoader used fake TurboVPN and WhatsApp installers, Google Cloud Storage, Amazon S3 and encrypted WebSocket traffic.
6
SocGholish and XWorm remained relevant as access and credential-theft tooling in the tracked period.
Attack chains, vulnerabilities and indicators
CVEProductImpactJune context
CVE-2021-44228Apache Log4jRemote code execution, CVSS 10.0Actively exploited by DragonForce
CVE-2024-57726 / 57727 / 57728SimpleHelp RMMAuthentication bypass, traversal and privilege escalationActively exploited by DragonForce
CVE-2026-20253Splunk EnterpriseUnauthenticated RCE, CVSS 9.8Risk to SIEM infrastructure
CVE-2026-0257Palo Alto PAN-OSAuthentication bypass, CVSS 9.1Perimeter risk
Attack Chain 1: DragonForce
Attack PathELEZAR
01
Log4Shell, SimpleHelp exploitation or spearphishing
T1190 · T1566.001
02
Cobalt Strike and SystemBC
03
Mimikatz and domain discovery
T1003.001
04
Truesight.sys or RentDrv.sys BYOVD
T1562.001
05
Kernel-level EDR termination
06
PsExec lateral movement
T1021.002
07
Cross-platform encryption
T1486 · T1490
08
Data analysis and double extortion
T1657
Attack Chain 2: Securotrop
Attack PathELEZAR
01
VPN, RDP, phishing or public-facing application access
T1078
02
Domain controller compromise
03
Group Policy deploys Chrome credential harvesting script
T1484.001 · T1555.003
04
DPAPI decryption of passwords and cookies
05
LSASS credential theft
T1003.001
06
PsExec and RDP lateral movement
T1021.001 · T1021.002
07
C:\temp\w.exe detonation
08
VSS deletion and event log clearing
T1490 · T1070.001
09
Qilin encryption
T1486
Attack Chain 3: 3AM ransomware
Attack PathELEZAR
01
Email bombing
T1598
02
Spoofed IT support call
03
Quick Assist access
T1219
04
QEMU VM and QDoor backdoor
T1610
05
Duo and EDR impairment
T1562.001
06
RDP and WMIC lateral movement
T1021.001 · T1047
07
GoodSync exfiltration to Backblaze
T1567.002
08
WindowsSensor15 persistence
T1053.005
09
.threeamtime encryption
T1486
Attack Chain 4: GoldenGh0stLoader
Attack PathELEZAR
01
Fake TurboVPN or WhatsApp installer
T1189
02
GoldenGh0stLoader execution
T1204.002
03
Encrypted payload retrieved from Google Cloud Storage or Amazon S3
T1105 · T1102
04
Encrypted WebSocket command and control over TCP 443
T1071.001
05
Secondary payload delivery and persistent access

Selected indicators

TypeIndicatorAssociation
SHA256410db536a57c511b0ccac2639e0eb3320f303fc5c90242379ab43364c51ef321DragonForce Truesight.sys
FileTruesight.sys / RentDrv.sysDragonForce BYOVD drivers
FileC:\temp\w.exeSecurotrop staging
TaskWindowsSensor153AM persistence
FileUpdate_excic.acow23AM QEMU disk image
Processqemu-system-* / wexe.exe3AM EDR bypass
Prioritized defensive guidance
Immediate: act within 72 hours
1. Patch remaining Log4j exposure
Scan Java-based portals, middleware and payment systems for CVE-2021-44228 and isolate systems that cannot be patched.
2. Patch and restrict SimpleHelp
Apply fixes for CVE-2024-57726, CVE-2024-57727 and CVE-2024-57728. Restrict management access and verify MSP patch status.
3. Block vulnerable driver execution
Add Truesight.sys and RentDrv.sys to WDAC deny rules and enable the Microsoft Vulnerable Driver Blocklist.
Urgent: act within 1 to 2 weeks
4. Detect GPO-based Chrome credential theft
Alert on Group Policy login script changes and PowerShell access to Chrome Login Data or Cookies.
5. Harden helpdesk processes
Restrict Quick Assist, implement callback verification and alert on more than 10 emails delivered to one mailbox within 60 seconds.
6. Enforce phishing-resistant MFA
Apply FIDO2, WebAuthn or certificate-based MFA to VPN, RDP and remote administration.
7. Detect trusted cloud payload delivery
Alert on WebSocket traffic and binary downloads from unapproved Google Cloud Storage and Amazon S3 buckets.
Investigate and strengthen
8. Detect QEMU-based EDR evasion
Block or alert on qemu-system, wexe.exe and .acow2 or .qcow2 files outside approved IT use.
9. Protect immutable backups
Use offline or immutable storage that domain administrators cannot modify. Test clean recovery regularly.
10. Patch Splunk and PAN-OS
Prioritize CVE-2026-20253 and CVE-2026-0257 because compromise would remove security visibility or bypass the perimeter.
June source reports: Threat Intelligence Report ending 1 Jun 2026 · Threat Intelligence Reports for Jun 2 to 8, Jun 9 to 15, Jun 16 to 22 and Jun 23 to 29 2026
EMEA
Executive Summary
Credential theft, ransomware and regulatory extortion pressure

EMEA finance, banking and payment organizations faced a criminally driven threat environment in June 2026. The source set highlighted mass credential-stealer distribution, ransomware with GDPR and PDPL pressure tactics, and the temporary disruption of Amadey and StealC through Operation Endgame. Germany accounted for 5.15 percent of global ransomware victims during the week of 2 to 8 June. June report volume reached 455, up from 164 in May.

Key Insights
1
Operation Endgame disrupted 47 domains and 182 command-and-control IPs associated with Amadey and StealC on 24 June.
2
StealC v2 targeted Chromium and Firefox credentials, saved payment card data and Chrome App-Bound Encryption through APC injection.
3
Brain Cipher used double extortion and explicit GDPR notification threats against organizations exposed through RDP, VPN, phishing and initial access brokers.
4
AiLock introduced ChaCha20 plus NTRUEncrypt256 and laundering through Wasabi, FixedFloat and Monero.
5
3AM ransomware combined email bombing, IT vishing, Quick Assist abuse, a QEMU-hosted QDoor backdoor, 868 GB exfiltration and WindowsSensor15 persistence.
6
RevStealer used Polygon blockchain state to retrieve command-and-control configuration, reducing the value of static domain and IP blocklists.
Attack chains, vulnerabilities and indicators
CVEProductImpactJune context
CVE-2023-28252Windows CLFS driverPrivilege escalationActively used by Brain Cipher
CVE-2026-20253Splunk EnterpriseUnauthenticated RCE, CVSS 9.8Risk to SIEM infrastructure
CVE-2026-0257Palo Alto PAN-OSAuthentication bypass, CVSS 9.1Risk to network perimeter
CVE-2026-48907Joomla Widget FactoryRCE, CVSS 9.8Customer-facing portal risk
CVE-2026-35273Oracle PeopleSoftZero-day RCE, CVSS 9.8Enterprise HR and finance risk
Attack Chain 1: Amadey to StealC
Attack PathELEZAR
01
Phishing, malvertising or cracked software
T1566 · T1189
02
Amadey installation and scheduled task
T1053.005
03
RC4-encrypted host fingerprint
T1082
04
StealC download or injection
T1105
05
Browser, Outlook, WinSCP, FileZilla and wallet theft
T1555.003
06
APC injection bypasses Chrome App-Bound Encryption
T1055.004
07
RC4-encrypted HTTP POST exfiltration
T1041
Source: Amadey and StealC: Malware-as-a-Service Unavailable; StealC and Amadey technical analysis
Attack Chain 2: Brain Cipher
Attack PathELEZAR
01
Exposed RDP or VPN, phishing or public-facing exploit
T1133 · T1078
02
CVE-2023-28252 privilege escalation
T1068
03
LSASS and domain credential theft
T1003
04
Defender and service impairment
T1562.001
05
GPO and PsExec lateral movement
T1484.001 · T1021
06
Shadow copy deletion
T1490
07
Salsa20 and RSA encryption
T1486
08
GDPR-focused double extortion
Attack Chain 3: 3AM ransomware
Attack PathELEZAR
01
Email subscription bombing
02
Spoofed IT helpdesk VoIP call
T1566.004
03
Microsoft Quick Assist access
T1219
04
QEMU Windows 7 VM launched
T1610
05
QDoor backdoor outside host EDR
06
Duo uninstall attempts and EDR impairment
T1562.001
07
RDP and WMIC lateral movement
T1021.001 · T1047
08
868 GB exfiltration to Backblaze
T1567.002
09
.threeamtime encryption
T1486

Selected indicators

TypeIndicatorAssociation
IP185[.]215[.]113[.]206Amadey and StealC C2
IP185[.]215[.]113[.]17Amadey and StealC C2
IP62[.]204[.]41[.]151Shared C2 infrastructure
FileC:\Users\<user>\e079729711\nudwee.exeAmadey persistence
IP88[.]118[.]167[.]239:4433AM QDoor C2
TaskWindowsSensor153AM persistence
Prioritized defensive guidance
Immediate: act within 72 hours
1. Block and hunt Amadey and StealC infrastructure
Block 185[.]215[.]113[.]206, 185[.]215[.]113[.]17 and 62[.]204[.]41[.]151. Hunt for nudwee.exe in user and temporary paths.
2. Detect the StealC APC injection sequence
Alert on CREATE_SUSPENDED followed by VirtualAllocEx, WriteProcessMemory, QueueUserAPC and ResumeThread from non-browser processes.
3. Patch CVE-2023-28252 and CVE-2026-20253
Prioritize Windows hosts and Splunk systems connected to financial operations.
Urgent: act within 1 to 2 weeks
4. Harden IT support against Quick Assist abuse
Restrict Quick Assist, require out-of-band callback verification and alert on sudden mailbox flooding.
5. Detect QEMU and rogue VM execution
Alert on qemu-system processes, wexe.exe and .acow2 or .qcow2 images in C:\ProgramData.
6. Enforce phishing-resistant MFA on RDP and VPN
Use FIDO2 or certificate-based authentication for remote administration.
7. Prepare a GDPR and DORA double-extortion playbook
Pre-approve legal, compliance and incident reporting decision paths before an active ransomware event.
Investigate and strengthen
8. Monitor blockchain RPC use
Alert on Polygon RPC traffic from non-trading systems and scripts decoding blockchain-sourced payloads.
9. Protect Outlook and WinSCP credentials
Restrict registry access to Outlook profile and WinSCP session paths from unapproved processes.
10. Rotate and harden FortiGate administration
Remove internet-exposed management, enforce certificates and rotate administrative credentials in response to FortiBleed.
June source reports: Amadey and StealC: Malware-as-a-Service Unavailable · StealC and Amadey technical analysis · Threat Intelligence Reports for Jun 2 to 8, Jun 9 to 15, Jun 16 to 22 and Jun 23 to 29 2026
APAC
Executive Summary
Localized phishing, supply chain compromise and cryptocurrency targeting

The APAC finance, banking and payment sector faced elevated multi-vector activity throughout June 2026. Chinese-speaking cybercrime and espionage operations targeted East and Southeast Asian financial institutions, payroll systems and tax-processing environments. North Korean-linked operators also targeted cryptocurrency and fintech development ecosystems through supply chain compromise and developer recruitment lures. June intelligence volume rose to 455 reports from 164 in May, while adversaries increased the use of localized Japanese, Hindi and Chinese pretexts.

Key Insights
1
TA4922 was the most operationally active Chinese-speaking actor in the source set, expanding tax, payroll and HR-themed phishing into Japan and Taiwan.
2
Sapphire Sleet, also tracked as BlueNoroff or UNC1069, compromised more than 140 npm packages and enumerated 166 cryptocurrency wallet browser extensions.
3
Operation TaxShadow impersonated Indian and Japanese tax authorities to deliver an obfuscated in-memory malware framework. Attribution to Chinese-speaking operators was assessed at moderate confidence.
4
UNK_DeadDrop targeted finance and cryptocurrency developers and quantitative analysts with recruitment lures, including impersonation of Ondo Finance.
5
No named APAC financial entity ransomware incident was confirmed in the ingested June reports. The period was instead dominated by phishing, credential theft, developer targeting and supply chain activity.
Attack chains, vulnerabilities and indicators
CVEProductImpactJune relevance
CVE-2026-20245Cisco Catalyst SD-WAN ManagerRoot-level backdoorEmergency patch priority for financial network infrastructure
CVE-2026-20253Splunk EnterpriseUnauthenticated RCE, CVSS 9.8Direct risk to SIEM infrastructure
CVE-2026-0257Palo Alto PAN-OSAuthentication bypass, CVSS 9.1Direct risk to perimeter access
Attack Chain 1: TA4922 localized phishing to Atlas RAT
Attack PathELEZAR
01
Localized tax, HR or payroll spearphish
T1566.001
02
ZIP archive from GoFile, LimeWire or MediaFire
03
User executes legitimate-looking binary
T1204.002
04
DLL sideloading using vulkan-1.dll or libcef.dll
T1574.001
05
RomulusLoader injects into svchost.exe or dllhost.exe
T1055.002
06
AnyDesk or SyncFuture persistence
T1219
07
Atlas RAT injects into WeChat.exe
08
Keylogging, screen capture, clipboard and file exfiltration
T1056.001 · T1113
Attack Chain 2: Operation TaxShadow
Attack PathELEZAR
01
India or Japan tax impersonation
T1566.002
02
ZIP archive containing tax-themed executable
03
DLL search order hijacking loads SbieDll.dll
T1574.001
04
Reflective PE loader maps payload in memory
T1620
05
Token duplication and impersonation
T1134
06
HTTP to WebSocket upgrade through enterprise proxy
T1071.001 · T1090
07
Persistent C2 to 43[.]128[.]54[.]184:1234
Attack Chain 3: Sapphire Sleet npm supply chain
Attack PathELEZAR
01
Compromised npm maintainer account
T1195.002
02
Poisoned 140+ Mastra packages
03
easy-day-js dependency resolved automatically
04
postinstall runs node setup.cjs
T1059.007
05
Cross-platform persistence
T1547.001 · T1543.002
06
Enumerates 166 wallet extensions
T1217
07
Credential and browser data exfiltration
T1041
08
PowerShell second stage and reflective .NET injection
T1059.001

Selected indicators

TypeIndicatorAssociation
IP43[.]128[.]54[.]184:1234TaxShadow C2
IP206[.]238[.]115[.]58Atlas RAT C2
IP154[.]211[.]86[.]110Atlas RAT C2
IP23[.]254[.]164[.]92Sapphire Sleet stage two
Domainteams[.]onweblive[.]orgSapphire Sleet PowerShell C2
Domainws[.]ztts88[.]cyouSilentRunLoader C2 and exfiltration
RegistryHKCU\Software\Microsoft\Windows\CurrentVersion\Run\NvmProtocalSapphire Sleet persistence
Prioritized defensive guidance
Immediate: act within 72 hours
1. Block confirmed June C2 infrastructure
Add 43[.]128[.]54[.]184, 23[.]254[.]164[.]92, teams[.]onweblive[.]org, ws[.]ztts88[.]cyou and related indicators to perimeter blocklists and SIEM watchlists.
2. Audit npm and CI/CD integrity
Search package-lock files and SBOMs for easy-day-js versions 1.11.21 and later. Hunt for the NvmProtocal Run key and com.nvm.protocal.plist.
3. Hunt Atlas RAT execution patterns
Alert on user-space processes spawning svchost.exe or dllhost.exe, non-system loading of vulkan-1.dll or libcef.dll, outbound TCP 886 and injection into WeChat.exe.
Urgent: act within 1 to 2 weeks
4. Control RMM use
Allowlist approved RMM tools and alert on AnyDesk or SyncFuture installs without a valid service ticket.
5. Tune phishing controls for localized lures
Flag Japanese salary or tax ZIP attachments, Hindi tax impersonation and links to GoFile, LimeWire, MediaFire and srt.tw.
6. Protect browser sessions
Use phishing-resistant MFA and managed browser profiles. Hunt for Chrome_Live_Backup_*.zip and C:\WSBF_ALL.
7. Patch June-exploited infrastructure
Prioritize CVE-2026-20245, CVE-2026-20253 and CVE-2026-0257.
Investigate and tune detections
8. Validate fileless malware coverage
Confirm behavioral detection for reflective assembly loading, unusual ZwAllocateVirtualMemory use and unexpected WebSocket upgrades.
9. Review proxy-aware C2 visibility
Alert on HTTP 101 Switching Protocols responses to unapproved destinations and inspect HTTP CONNECT tunnelling.
10. Treat developer workstations as privileged assets
Apply least privilege to CI/CD credentials, audit package installation events and monitor VS Code or Cursor extension installation.
June source reports: TA4922: The Suspected Chinese Crime Group is Going Global · From package to postinstall payload: Inside the Mastra npm supply chain compromise by Sapphire Sleet · Operation TaxShadow: Multi-Region Tax Phishing and In-Memory Malware Campaign · Don’t Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency · Threat Intelligence Report Jun 2 to Jun 8 2026