Real Emails, Hijacked Payments: Two H1 2026 Attack Chains Use Compromised Corporate Mailboxes to Steal Funds
What Happened — In the first half of 2026, threat actors compromised legitimate corporate email accounts and used them to deliver a JavaScript dropper that progressed through PowerShell stages to shellcode, ultimately modifying proxy settings and installing a browser add‑on to hijack banking sessions. A second campaign employed a Rust‑based cryptocurrency clipper that fetched C2 pointers from the Binance Smart Chain, altered wallet destination addresses, and completed unauthorized crypto transfers.
Why It Matters for Compliance & Audit Readiness
- The scenario is a textbook example of a credential‑compromise breach that SOC 2’s Logical Access (CC6.1) and System Operations (CC7.1) controls are designed to detect, prevent, and evidence.
- Continuous monitoring of mailbox activity and documented security‑awareness training provide the audit‑ready evidence needed to demonstrate due diligence under SOC 2.
- Leveraging Verisq’s Security Awareness capability helps embed the required training, phishing simulations, and policy enforcement into a defensible compliance program.
Who Is Affected – Financial services firms, cryptocurrency exchanges, and any organization that relies on corporate email for payment‑related communications.
Recommended Actions –
- Enforce MFA and conditional access for all mailbox accounts.
- Deploy automated mailbox activity monitoring and alerting for anomalous logins or forwarding rules.
- Conduct targeted security‑awareness training that covers business‑email‑compromise (BEC) tactics and safe handling of email attachments.
- Map the incident to SOC 2 CC6.1 and CC7.1 controls, collect logs as audit evidence, and update your incident‑response playbook.
Technical Notes – Attack vector: stolen credentials → JavaScript dropper → PowerShell → shellcode → proxy/browser manipulation (banking campaign). The crypto clipper used a Rust binary, leveraged Binance Smart Chain for C2, and performed local address substitution before signing transactions. Source: BleepingComputer