Financial cyberthreats in 2025 and the outlook for 2026

2026-04-08T20:51:53Z4a133f25eb250064ff2c3ab7249a29df18cf5084e83f3a2c8f67bf356ba403a0
Android-trojanBeatBankerCVE-2023-32434CVE-2023-38606CorunaCrystalXGoPixHorabotLiteLLMMaaSPACRATbanking-trojanexploit-kitinfostealerkernel-exploitmalvertisingmalwareman-in-the-middlememory-onlymobile-malwareprankwarestealersupply-chainvulnerabilities-report

What happened

Kaspersky Securelist published a set of April 2026 analyses and reports covering the 2025 financial threat landscape and notable campaigns: CrystalX RAT (MaaS) combining spyware, stealers and prankware; a supply‑chain compromise of LiteLLM used as an AI gateway; the Coruna exploit kit updating kernel exploits (including CVE-2023-32434 and CVE-2023-38606) targeting iPhones; GoPix, a sophisticated Brazilian banking Trojan using memory‑only implants, PAC-based MITM and malvertising; BeatBanker, a dual‑mode Android banking/mining Trojan; a Horabot campaign in Mexico; plus Q4‑2025 vulnerability/exP

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
4a133f25eb250064ff2c3ab7249a29df18cf5084e83f3a2c8f67bf356ba403a0
Enrichment time
2026-04-08T20:51:53Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Financial cyberthreats in 2025 and the outlook for 2026 · Baitaphish