Real emails, hijacked payments: Two H1 2026 attack chains
Summary
Gen's H1 2026 Threat Report details two distinct attack chains observed in the first half of 2026. One involved compromised business inboxes and browser manipulation for banking malware, while the other utilized clipboard hijacking to divert cryptocurrency payments.
IFF Assessment
FOE
The article describes two attack chains that demonstrate sophisticated methods used by threat actors to compromise systems and steal funds, posing a direct threat to defenders.
Defender Context
Defenders should be aware of these evolving attack vectors, including the exploitation of legitimate business communication channels and novel methods like clipboard hijacking for financial fraud. Monitoring for unusual browser behavior and suspicious payment redirects are crucial defensive measures.