Fake invoices and swapped wallet addresses: inside two 2026 attack chains

Gen's latest threat report tracks criminals who hijacked real business email threads to spread banking malware, and a separate crew quietly rewriting crypto wallet addresses as victims copied them.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 4 min read
A business email thread on a computer screen with invoice attachments and cryptocurrency wallet addresses being subtly edited by unseen hands overlaid with malw
Share

Key points

  • Gen's H1 2026 Threat Report details two separate criminal campaigns hitting inboxes and cryptocurrency wallets in the first half of 2026.
  • The first campaign hijacked real business email conversations to deliver banking malware, software designed to steal online banking logins.
  • The second used clipboard hijackers, small programs that silently swap a copied crypto wallet address for the attacker's own before pasting.
  • Both chains rely on victims trusting what they see on screen, not on any exotic software flaw.
  • Gen recommends stricter payment verification and clipboard-aware wallet checks for anyone moving money online.

Two criminal campaigns dominate the first half of 2026, according to a new threat report from Gen, the security company behind Norton and Avast. Neither relied on a clever new software bug. Both worked because the victim trusted what was in front of them.

The report, first covered by BleepingComputer, pulls apart the mechanics of each.

How did the email attack actually work?

Criminals broke into real business email accounts and replied inside genuine, ongoing conversations with malware attached. Because the message came from a known contact in a thread the victim had already been part of, the usual warning signs weren't there.

From compromised inboxes, attackers sent booby-trapped attachments that quietly installed banking malware once opened. The malware then manipulated the victim's web browser directly. When the person logged into online banking, criminals could harvest credentials and in some cases alter what the victim saw on screen. A payment the user thought they were sending to a supplier could be redirected without any obvious tell.

This technique is nasty precisely because the address bar and padlock icon still look correct. Readers who follow fraud targeting bank customers may recall our 8 July story on REF6045, a campaign that also used paste-based manipulation to compromise Mexican bank users: the delivery method differs here, but the browser-layer deception is the same.

What is a clipboard hijacker?

A clipboard hijacker is a small piece of malware that watches what you copy. When it spots something that looks like a cryptocurrency wallet address, a long string of letters and numbers, it silently swaps it for one belonging to the attacker before you paste.

Crypto wallet addresses are long and unmemorable. Almost nobody types them by hand. That copy-paste habit is the whole attack.

Gen's researchers found campaigns targeting Bitcoin and Ethereum holders, among others. The victim copies their intended recipient's address, pastes it into the send field, confirms, and the money goes to the criminal. By the time anyone notices, the transaction is on the blockchain and can't be reversed.

Who is affected and what should people do?

Both campaigns target ordinary users and small businesses rather than large enterprises with dedicated security teams. Finance staff at small firms are especially exposed to the email campaign, and anyone active in crypto is a candidate for the clipboard swap.

Campaign Method Target Payoff
Email thread hijack Malware attached to real replies Online banking users Stolen logins, redirected payments
Clipboard hijacker Swaps copied wallet addresses Crypto holders Diverted transfers

Before paying any invoice arriving by email, even from a known contact, phone the sender on a number you already have and confirm the bank details out loud. Don't trust changes to payment details sent in writing.

When sending cryptocurrency, always check the first six and last six characters of the pasted address against the original. If they don't match, your clipboard has been tampered with and the device needs a full malware scan.

Keep endpoint security on and updated. Both campaigns rely on the initial malware getting a foothold, and mainstream antivirus catches most known variants.

Gen has not attributed either campaign to a named group. The honest read on this report is that neither technique is new: what's worth watching is how casually they're being combined and scaled against targets who still have no idea that a browser or a clipboard can lie to them.

© 2026 Threat Vectr