Skip to main content

【イベント】TrendAI™ Spark 2026 開催

AIセキュリティの最前線を探るグローバルイベント「Spark 2026」を全国5都市で開催します。

Return to research homepage
AI and emerging technologies Cyber Crime

Modern Bank Heists 2026: The Machine-Speed War for Financial Control

How agentic AI, nation-state actors, and cybercrime-as-a-service are outpacing financial sector defenses, and how defenders can respond at machine speed

Financial services Cyber Crime AI Research Features

In June 2026, TrendAI™ surveyed 46 chief information security officers (CISOs) across the financial sector. The key finding: 67% of institutions experienced counter-incident response—attackers actively working to undermine defenders during live engagements. When threat actors shift from stealing data to actively degrading the defenders' ability to respond, the conflict has changed. It is no longer a fight over data but over control of the response itself.

Simultaneously, an 89% year-over-year increase in AI-enabled attacks confirms that attacks are now happening at machine speed. Campaigns that once required skilled operators running manual tradecraft can now run on their own, with phishing, fraud, and exploitation running in parallel and continuously in the background.

A sector under siege

In the past year, 41% of the surveyed organizations suffered a destructive cyberattack, signaling a deliberate shift from exfiltration toward damage. API surfaces are expanding, with 55% reporting increased API-based attacks. Nearly half (46%) reported intrusions targeting nonpublic market information or investment strategies. Threat actors are stealing market strategies as aggressively as they do funds.

Fraud vectors have evolved in step. Account takeover ranks as the most concerning threat (37%), followed by business email compromise (BEC) and reverse business email compromise (RBEC) schemes augmented by deepfakes (28%), and AI-enabled spear phishing and smishing (26%). Generative AI has reduced the cost of a convincing social engineering attack to near zero. Island-hopping, where attackers compromise an organization’s infrastructure to pivot against its customers, was confirmed by 37% of respondents. Customer-facing risk now flows directly from enterprise breaches.

A lack of resources compounds the threat: 54% of organizations saw no budget increase despite this environment. Security leadership remains structurally subordinated, with 57% of security functions still reporting to the chief information officer (CIO) rather than holding independent executive authority. Investment, when it occurs, skews toward technology (70%), while managed detection and response (20%) and people (10%) are under-resourced. Meanwhile, 35% are evaluating whether to replace their XDR platform, and 27% are considering sovereign cloud, both signs that institutions are actively rethinking their security architectures.

The dark passenger: Steganography

Cybercriminals are embedding attack infrastructure inside ordinary images, hiding commands within image pixels that malware then retrieves from compromised social media and hosting sites.

Backdoors such as Daserf use steganographic algorithms, such as RC4 combined with base64 encoding, to establish covert command-and-control (C&C) channels that bypass traditional traffic inspection. State-sponsored actors, including Pawn Storm, pair steganography with legitimate cloud services to evade endpoint monitoring entirely. Attackers have also exploited compromised cloud storage buckets to distribute malicious scripts concealed inside image files. The emerging frontier is invisible prompt injection, a threat vector that did not exist two years ago. In it, attacker-controlled instructions embedded in images are silently processed and acted on by AI systems.

The RAT plague

Five remote access trojans (RATs) define the threat to financial institutions, ranging from commodity tools repurposed for surveillance to purpose-built malware-as-a-service (MaaS) platforms that cover the entire fraud lifecycle from a single implant. Each has confirmed campaigns against banks or crypto exchanges, and together they illustrate how accessible and financially damaging RAT-based intrusions have become.

  • Remcos, originally marketed as a legitimate tool, has evolved into a real-time surveillance platform capable of live webcam streaming and instant keystroke transmission.
  • AsyncRAT is free, open-source, and the most prolific by volume, fueling an ecosystem of more than 40 GitHub forks. Known financial attacks include the Winnti-linked GodRAT campaign via Skype.
  • XenoRATwas forked by North Korea's Kimsuky advanced persistent threat (APT) group into a variant called MoonPeak. It has documented campaigns against South Korean financial and government entities, with the billion-dollar impact detailed in the next section.
  • BananaRAT combines screen streaming, overlay injection, QR-code-based Pix transaction manipulation, and continuous keylogging into a single fraud and surveillance platform. Deployed by SHADOW-WATER-063, an elite Brazilian threat actor, it successfully targeted 16 financial institutions and crypto exchanges in Brazil.
  • XWorm is the most sophisticated of the group, a commercial MaaS RAT available for a US$500 lifetime license. Its modular architecture spans ransomware, distributed denial-of-service (DDoS), hidden virtual network computing (HVNC), USB lateral movement, and crypto clipboard hijacking. It is the only tool in this class that covers every major financial attack vector from a single implant. Documented campaigns include fake Bradesco bank receipt lures across Brazil and Latin America and business-themed payment phishing globally.

Notable cybercrime groups

FIN7 (also known as Sangria Tempest or Carbon Spider), among the most prolific financially motivated actors operating today, has relentlessly evolved its toolkit. Its tools moved from Carbanak to Diceloader to Minodo and, in 2025, to a Python-based RAT called Anubis Backdoor. Each iteration is engineered for minimal footprint, since reflective loaders enable in-memory execution of additional modules and leave almost nothing on disk for defenders to find. The group uses raw TCP sockets with Advanced Encryption Standard (AES) encryption to evade Transport Layer Security (TLS) inspection controls. It has also been observed selling an endpoint detection and response (EDR)-killer utility called AuKill (AVNeutralizer), which loads Microsoft's Process Explorer driver to achieve kernel-mode execution and neutralize endpoint defenses entirely.

Void Balaur (Rockethack), a mercenary hack-for-hire service advertising on underground forums, offers bank account data, personally identifiable information (PII), and full account credentials for purchase by any willing buyer. The group deploys a custom credential stealer, ZStealer, targeting browsers, email clients, instant messaging platforms, and cryptocurrency wallets, and has extended operations to Android devices via DroidWatcher spyware. This represents the outsourcing layer of modern financial cybercrime, enabling threat actors to acquire initial access and intelligence without direct exposure.

The Lazarus Group, North Korea's financially motivated cyber arm, has pivoted decisively from SWIFT (Society for Worldwide Interbank Financial Telecommunication) terminal attacks to cryptocurrency heists, where funds can be liquidated outside traditional banking controls. It compromises developers through social engineering, infects software supply chains, and uses blockchain-based C&C resolution ("EtherHiding") to store malware stages on the Ethereum network, making takedowns structurally difficult. Using malware such as the previously mentioned XenoRAT and their custom MoonPeak fork, North Korea-linked operators stole US$2.02 billion in cryptocurrency in 2025 alone.

“The financial sector has always been a prime target for malicious actors, and what we’re seeing today represents a significant evolution in both the sophistication and scale of these attacks. At TrendAI, our research is tracking threat groups that are no longer simply exploiting technical vulnerabilities, but are systematically targeting the trust infrastructure that financial institutions depend on, from wire transfer workflows to authentication systems to insider access pathways. What concerns me most looking ahead is the convergence of AI capabilities with these already-mature attack operations. We’re moving into a period where AI-enabled attacks will allow malicious actors to automate highly targeted social engineering at scale, generate convincing deepfake communications to impersonate executives, and dramatically accelerate the reconnaissance phase before a financial breach. The modern bank heist isn’t a smash-and-grab. It’s a long, patient, AI-assisted operation, and organizations that aren’t preparing for that reality today will be caught off guard tomorrow.”

—Jon Clay, VP of Threat Intelligence, TrendAI™

The race to defend at machine speed

The financial sector has reached an inflection point. Attackers now chain specialized AI agents under a central orchestrator to run end-to-end campaigns—which include phishing, fraud, and exploitation—continuously and at machine speed. Security architectures must respond in kind, matching orchestrated, machine-speed attacks with equally automated, AI-driven detection and response rather than manual, human-paced defenses.

Institutions can defend against these intrusions by combining 10 capabilities:

  • Virtual patching against zero-day vulnerabilities, shielding vulnerable systems from exploitation before an official vendor patch is available
  • Proactive threat hunting via knowledge graph relationships, mapping connections across assets, identities, and events to surface hidden attack paths before they are exploited
  • Blast radius calculation, quantifying how far an attacker could pivot from a single compromised asset, so incidents can be contained before they spread enterprise-wide
  • Prompt injection prevention, blocking attacker-controlled instructions embedded in content processed by AI systems
  • Deepfake identification via computer vision, detecting AI-generated video and audio used in executive impersonation and social engineering
  • Pre-execution and runtime machine learning (ML) for endpoint detection, identifying malicious code both before it runs and as it executes in memory
  • Writing style analysis for BEC, flagging stylistic anomalies in emails that indicate impersonation or compromised accounts
  • Query generation assistance for analysts, translating natural-language questions into threat-hunting queries to accelerate investigations
  • Global and sector-specific threat intelligence, contextualizing alerts against active campaigns targeting financial institutions
  • Managed detection and response (MDR) services, providing continuous, expert-led monitoring and incident response coverage around the clock

Most critically, CISOs must be elevated, since security cannot credibly report to the technology function it exists to check. The 57% of institutions where security still answers to the CIO carry a structural weakness that must be corrected. Safety and resilience now depend on proactive cybersecurity at the executive level.

Cybercrime groups have industrialized, running phishing, fraud, and exploitation through orchestrated, machine-speed pipelines rather than as isolated, manually operated tools. The window to respond before they fully automate every stage of the kill chain, from initial compromise to laundering the proceeds, is closing. The defense must close that window first. Institutions that automate their detection and response now can set the terms of the fight rather than react to whatever follows.