90-Day Telemetry Summary — Financial Sector Threat Landscape
TLP: AMBER — For FS-ISAC Member Distribution Only
Date: Monday, August 24, 2026 | Source: Dataminr Cyber Threat Intelligence | Reference Period: 270-Day Historical Dataset (90-day rolling view)
Executive Summary
Over the past 90 days, the financial sector’s threat profile has shifted decisively toward phishing-led, identity-based attacks and away from the malware-heavy environment that characterized late 2025. Threat-actor attribution has become more precise even as raw malware volume has fallen sharply. Dark web extortion activity, after nine months of decline, is rising again in August — the earliest signal of a possible new threat cycle. This brief summarizes threat-actor activity, active malware families, and strategic trends, with recommended member actions highlighted throughout.
Active Threat Actor Roster (90-Day) — with Recommended Actions
NoName05716
Hacktivist / DDoS
↑ Growing
Last seen: Aug 12
Confirm DDoS mitigation/scrubbing capacity is current; review public-facing service resilience runbooks.
Infrastructure Destruction Squad
Hacktivist + OT
Active
Last seen: Aug 23
If you operate or depend on OT/ICS systems, verify network segmentation between IT and OT environments.
Dark Storm Team
Hacktivist
↑ Growing (+60%)
Last seen: Aug 14
Same as above: validate DDoS response plans and rate-limiting on customer-facing infrastructure.
Exchange Markets
Financially motivated
↑ Surging (+150%)
Last seen: Aug 18
Fastest-growing actor this period — review recent alerts/advisories tied to this group and brief SOC analysts on its TTPs.
ShinyHunters
Extortion
Active
Last seen: Aug 22
Audit third-party SaaS/Okta/SSO access; this group’s primary vector is credential and OAuth-token abuse, not encryption malware.
Inc Ransom
Ransomware
Active
Last seen: Aug 18
Patch internet-facing remote-access appliances (VPN/SMA gateways) — this is this group’s primary entry point.
The Gentlemen
Ransomware
Stable (9-mo persistent)
Last seen: Aug 21
Long-running presence — confirm this actor is already covered in existing IR playbooks and threat-hunting rules.
Void Blizzard
Nation-state
Precision burst (Jul 29–30)
Last seen: Jul 30
Nation-state actor with a short, targeted burst — review logs from that window for any related indicators.
Kazu Ransomware Group
Ransomware
↑ Active dark web
Last seen: Aug 22
Monitor dark web leak sites for your organization’s name; prepare breach-notification workflows in advance.
Ransomware (emerging)
Chatter spike
Last seen: Aug 23
Newly emerging group — no established TTP profile yet. Add to watchlist rather than acting on it directly.
Malware Intelligence (90-Day, Financial Sector) — with Recommended Actions
Apocalypse
Ransomware/Dropper
Surging
Ensure EDR signatures are current; this is the fastest-growing ransomware dropper in the current dataset.
Shark
Banking malware
Persistent, slowly declining
Maintain existing banking-trojan detection rules; threat is easing but not gone.
Domino
FIN7-linked backdoor
Growing, dubbed
Review email/attachment filtering — FIN7-linked backdoors typically arrive via phishing lures.
Money Message
Ransomware
Active Dark Web campaign
Prepare incident response plans now; dark-web activity suggests this campaign is in an active extortion phase.
OWAReaper
Exchange Webshell
Financial sector targeting
Audit Outlook Web Access (OWA) servers for unauthorized webshells; patch Exchange to current levels.
Grandoreiro
Banking Trojan
Recurring (Brazil-linked)
Relevant primarily for organizations with Latin American operations or customers.
BankGhost
Finance-specific RAT
Targeted
Confirm endpoint detection covers finance-specific remote access trojans, not just generic malware families.
Malware Ecosystem Shift
The dominant banking malware of late 2025 — the Kraken/Exodus/x4 ecosystem — has completely disappeared as of May 2026. A new cohort has emerged in its place, centered on Apocalypse, Domino/FIN7, and Money Message. The transition suggests either a law enforcement action, infrastructure takedown, or coordinated group retirement.
- → Retire detection rules tuned narrowly to Kraken/Exodus/x4 signatures and reallocate that effort to Apocalypse, Domino, and Money Message coverage.
Strategic Trend Analysis (9-Month View) — with Recommended Actions
The 270-day dataset shows three distinct threat eras for the financial sector:
- Era 1 — “The Malware Flood” (Nov 2025–Feb 2026): Large-scale Kraken/Exodus banking-trojan activity, heavy PLATINUM nation-state presence, elevated dark web exposure. Highest volume; lowest signal quality.
- Era 2 — “The Transition” (Feb–May 2026): Banking malware collapsed; PLATINUM faded. Russian and Iranian actors appeared briefly. Phishing share grew substantially. A new ransomware cohort began establishing presence.
- Era 3 — “Phishing Consolidation” (May–Aug 2026, current): Nearly pure phishing environment. Malware ecosystem fully replaced. Nation-state APTs largely absent except for isolated bursts.
Threat actor rate
Rising sharply
Alerts are increasingly attributable to named actors — treat attributed alerts as higher-priority for investigation.
Malware rate
Falling sharply
Malware-based detection alone is less effective now; shift SOC emphasis toward identity and phishing signals.
Dark Web rate
Recovering after a decline
Increase dark-web/leak-site monitoring cadence — this is the early indicator of the next threat cycle.
Phishing rate
Now the dominant vector (91% of alerts)
Prioritize phishing-resistant MFA, email security controls, and user awareness training over malware-signature tuning.
Strategic Assessment
The convergence of rising dark web extortion claims, a new ransomware actor cohort with multi-sector financial targeting, and the return of nation-state activity suggests FS-ISAC members should expect elevated threat pressure in Q4 2026 — potentially similar in character to the Nov–Feb era, but with more sophisticated phishing and identity-based attack chains as the primary vectors, reflecting attackers’ adaptation to the financial sector’s improved malware defenses.
→ Priority action for Q4 planning: Shift security investment and staffing emphasis from malware/signature defense toward identity protection (phishing-resistant MFA, SSO hardening, vendor access audits) and dark-web monitoring capacity, ahead of the anticipated increase in threat pressure.