Financial cyberthreats in 2025 and the outlook for 2026
2026-04-08T20:51:53Z•4a133f25eb250064ff2c3ab7249a29df18cf5084e83f3a2c8f67bf356ba403a0
Android-trojanBeatBankerCVE-2023-32434CVE-2023-38606CorunaCrystalXGoPixHorabotLiteLLMMaaSPACRATbanking-trojanexploit-kitinfostealerkernel-exploitmalvertisingmalwareman-in-the-middlememory-onlymobile-malwareprankwarestealersupply-chainvulnerabilities-report
What happened
Kaspersky Securelist published a set of April 2026 analyses and reports covering the 2025 financial threat landscape and notable campaigns: CrystalX RAT (MaaS) combining spyware, stealers and prankware; a supply‑chain compromise of LiteLLM used as an AI gateway; the Coruna exploit kit updating kernel exploits (including CVE-2023-32434 and CVE-2023-38606) targeting iPhones; GoPix, a sophisticated Brazilian banking Trojan using memory‑only implants, PAC-based MITM and malvertising; BeatBanker, a dual‑mode Android banking/mining Trojan; a Horabot campaign in Mexico; plus Q4‑2025 vulnerability/exP
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- 4a133f25eb250064ff2c3ab7249a29df18cf5084e83f3a2c8f67bf356ba403a0
- Enrichment time
- 2026-04-08T20:51:53Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.