Description

A comprehensive analysis of 46 deep-web hacker forums and over 26,000 discussion threads has revealed alarming trends in cyberattacks targeting financial institutions. Conducted throughout 2024, this study offers rare insights into the evolving tactics used by cybercriminals against the financial sector. One of the most notable findings is the rise of an underground market for information-stealing malware. Known as "infostealer-as-a-service," these tools were referenced 3–4 times daily across monitored forums, highlighting their growing prevalence. These malware services cater to both individual hackers and advanced persistent threat (APT) groups, offering user-friendly interfaces, technical support, and customized features for credential theft. Tools such as Mystic Stealer, which specializes in extracting passwords from applications like Outlook, demonstrate a clear focus on financial organizations. This decentralization of cybercrime lowers the barrier to entry, enabling even those with limited technical expertise to launch complex attacks, making law enforcement and attribution more challenging. Additionally, the increasing use of One-Time Password (OTP) bots has introduced new challenges in cybersecurity. These automated social engineering tools, often operated via Telegram, are designed to bypass two-factor authentication (2FA). By leveraging previously leaked credentials and impersonating legitimate organizations through AI-generated voice calls or messages, these bots deceive victims into revealing their 2FA codes. Once compromised, attackers seize control of accounts, modifying passwords and phone numbers to lock out the rightful users. In 2024 alone, researchers identified at least 38 active OTP bot services, with mentions rising 31% compared to the previous year, emphasizing a significant shift in cybercriminal methodologies. These developments compel financial institutions to rethink their cybersecurity strategies, shifting from traditional defense mechanisms to proactive threat intelligence that includes monitoring deep and dark web activities for early detection of emerging threats.