FS-ISAC CYBER THREAT INTELLIGENCE BRIEF

DATE August 25, 2026
SHARE

90-Day Telemetry Summary — Financial Sector Threat Landscape

TLP: AMBER — For FS-ISAC Member Distribution Only

Date: Monday, August 24, 2026  |  Source: Dataminr Cyber Threat Intelligence  |  Reference Period: 270-Day Historical Dataset (90-day rolling view)

Executive Summary

Over the past 90 days, the financial sector’s threat profile has shifted decisively toward phishing-led, identity-based attacks and away from the malware-heavy environment that characterized late 2025. Threat-actor attribution has become more precise even as raw malware volume has fallen sharply. Dark web extortion activity, after nine months of decline, is rising again in August — the earliest signal of a possible new threat cycle. This brief summarizes threat-actor activity, active malware families, and strategic trends, with recommended member actions highlighted throughout.

Active Threat Actor Roster (90-Day) — with Recommended Actions

Scroll horizontally to view more
Actor
Type
Trend
Recommended Action

NoName05716

Hacktivist / DDoS

↑ Growing

Last seen: Aug 12

Confirm DDoS mitigation/scrubbing capacity is current; review public-facing service resilience runbooks.

Infrastructure Destruction Squad

Hacktivist + OT

Active

Last seen: Aug 23

If you operate or depend on OT/ICS systems, verify network segmentation between IT and OT environments.

Dark Storm Team

Hacktivist

↑ Growing (+60%)

Last seen: Aug 14

Same as above: validate DDoS response plans and rate-limiting on customer-facing infrastructure.

Exchange Markets

Financially motivated

↑ Surging (+150%)

Last seen: Aug 18

Fastest-growing actor this period — review recent alerts/advisories tied to this group and brief SOC analysts on its TTPs.

ShinyHunters

Extortion

Active

Last seen: Aug 22

Audit third-party SaaS/Okta/SSO access; this group’s primary vector is credential and OAuth-token abuse, not encryption malware.

Inc Ransom

Ransomware

Active

Last seen: Aug 18

Patch internet-facing remote-access appliances (VPN/SMA gateways) — this is this group’s primary entry point.

The Gentlemen

Ransomware

Stable (9-mo persistent)

Last seen: Aug 21

Long-running presence — confirm this actor is already covered in existing IR playbooks and threat-hunting rules.

Void Blizzard

Nation-state

Precision burst (Jul 29–30)

Last seen: Jul 30

Nation-state actor with a short, targeted burst — review logs from that window for any related indicators.

Kazu Ransomware Group

Ransomware

↑ Active dark web

Last seen: Aug 22

Monitor dark web leak sites for your organization’s name; prepare breach-notification workflows in advance.

 

Ransomware (emerging)

Chatter spike

Last seen: Aug 23

Newly emerging group — no established TTP profile yet. Add to watchlist rather than acting on it directly.

Malware Intelligence (90-Day, Financial Sector) — with Recommended Actions

Scroll horizontally to view more
Malware
Category
Trend
Recommended Actions

Apocalypse

Ransomware/Dropper

Surging

Ensure EDR signatures are current; this is the fastest-growing ransomware dropper in the current dataset.

Shark

Banking malware

Persistent, slowly declining

Maintain existing banking-trojan detection rules; threat is easing but not gone.

Domino

FIN7-linked backdoor

Growing, dubbed

Review email/attachment filtering — FIN7-linked backdoors typically arrive via phishing lures.

Money Message

Ransomware

Active Dark Web campaign

Prepare incident response plans now; dark-web activity suggests this campaign is in an active extortion phase.

OWAReaper

Exchange Webshell

Financial sector targeting

Audit Outlook Web Access (OWA) servers for unauthorized webshells; patch Exchange to current levels.

Grandoreiro

Banking Trojan

Recurring (Brazil-linked)

Relevant primarily for organizations with Latin American operations or customers.

BankGhost

Finance-specific RAT

Targeted

Confirm endpoint detection covers finance-specific remote access trojans, not just generic malware families.

Malware Ecosystem Shift

The dominant banking malware of late 2025 — the Kraken/Exodus/x4 ecosystem — has completely disappeared as of May 2026. A new cohort has emerged in its place, centered on Apocalypse, Domino/FIN7, and Money Message. The transition suggests either a law enforcement action, infrastructure takedown, or coordinated group retirement.

  • Retire detection rules tuned narrowly to Kraken/Exodus/x4 signatures and reallocate that effort to Apocalypse, Domino, and Money Message coverage.

Strategic Trend Analysis (9-Month View) — with Recommended Actions

The 270-day dataset shows three distinct threat eras for the financial sector:

  • Era 1 — “The Malware Flood” (Nov 2025–Feb 2026): Large-scale Kraken/Exodus banking-trojan activity, heavy PLATINUM nation-state presence, elevated dark web exposure. Highest volume; lowest signal quality.
  • Era 2 — “The Transition” (Feb–May 2026): Banking malware collapsed; PLATINUM faded. Russian and Iranian actors appeared briefly. Phishing share grew substantially. A new ransomware cohort began establishing presence.
  • Era 3 — “Phishing Consolidation” (May–Aug 2026, current): Nearly pure phishing environment. Malware ecosystem fully replaced. Nation-state APTs largely absent except for isolated bursts.
Scroll horizontally to view more
Metric
Direction
Recommended Action

Threat actor rate

Rising sharply

Alerts are increasingly attributable to named actors — treat attributed alerts as higher-priority for investigation.

Malware rate

Falling sharply

Malware-based detection alone is less effective now; shift SOC emphasis toward identity and phishing signals.

Dark Web rate

Recovering after a decline

Increase dark-web/leak-site monitoring cadence — this is the early indicator of the next threat cycle.

Phishing rate

Now the dominant vector (91% of alerts)

Prioritize phishing-resistant MFA, email security controls, and user awareness training over malware-signature tuning.

Strategic Assessment

The convergence of rising dark web extortion claims, a new ransomware actor cohort with multi-sector financial targeting, and the return of nation-state activity suggests FS-ISAC members should expect elevated threat pressure in Q4 2026 — potentially similar in character to the Nov–Feb era, but with more sophisticated phishing and identity-based attack chains as the primary vectors, reflecting attackers’ adaptation to the financial sector’s improved malware defenses.

Priority action for Q4 planning: Shift security investment and staffing emphasis from malware/signature defense toward identity protection (phishing-resistant MFA, SSO hardening, vendor access audits) and dark-web monitoring capacity, ahead of the anticipated increase in threat pressure.

Aug 25, 2026

SHARE