Fake invoices and swapped wallet addresses: inside two 2026 attack chains
Gen's latest threat report tracks criminals who hijacked real business email threads to spread banking malware, and a separate crew quietly rewriting crypto wallet addresses as victims copied them.

Key points
- Gen's H1 2026 Threat Report details two separate criminal campaigns hitting inboxes and cryptocurrency wallets in the first half of 2026.
- The first campaign hijacked real business email conversations to deliver banking malware, software designed to steal online banking logins.
- The second used clipboard hijackers, small programs that silently swap a copied crypto wallet address for the attacker's address at the moment of pasting.
- Both chains rely on victims trusting what they see on screen, not on any exotic software flaw.
- Gen recommends stricter payment verification and clipboard-aware wallet checks for anyone moving money online.
Two criminal campaigns dominate the first half of 2026, according to a new threat report from Gen, the security company behind Norton and Avast. Neither relied on some clever new software bug. Both worked because the victim trusted what was on the screen.
The report, first covered by BleepingComputer, pulls apart the mechanics of each.
How did the email attack actually work?
Criminals broke into real business email accounts and replied inside genuine, ongoing conversations with malware attached. Because the message came from a known contact, in a thread the victim had already been part of, the usual warning signs were absent.
The attackers used compromised business inboxes as their launch pad. From there they sent booby-trapped attachments that, once opened, quietly installed banking malware on the recipient's computer.
The malware then went a step further. It manipulated the victim's web browser directly, so that when the person logged into their online banking, the criminals could see the session, harvest credentials, and in some cases alter what the victim saw on the page. A payment the user thought they were sending to a supplier could be redirected without any obvious sign on screen.
This technique, sometimes called a browser-in-the-browser attack, is nasty precisely because the address bar and padlock icon still look correct.
What is a clipboard hijacker?
A clipboard hijacker is a small piece of malware that watches what you copy. When it spots something that looks like a cryptocurrency wallet address, a long string of letters and numbers, it silently swaps it for one belonging to the attacker before you paste.
Crypto wallet addresses are long and unmemorable. Almost nobody types them by hand. People copy and paste. That habit is the whole attack.
Gen's researchers found campaigns aimed at Bitcoin, Ethereum and several other major coins. The victim copies their intended recipient's address, pastes it into the send field, hits confirm, and the money goes to the criminal. By the time anyone notices, the transaction is on the blockchain and effectively unreversible.
Who is affected and what should people do?
Both campaigns target ordinary users and small businesses rather than large enterprises with dedicated security teams. Finance staff at small firms are especially exposed to the email campaign, and anyone dabbling in crypto is a candidate for the clipboard swap.
| Campaign | Method | Target | Payoff |
|---|---|---|---|
| Email thread hijack | Malware attached to real replies | Online banking users | Stolen logins, redirected payments |
| Clipboard hijacker | Swaps copied wallet addresses | Crypto holders | Diverted transfers |
Practical steps for readers:
Before paying any invoice arriving by email, even from a known contact, phone the sender on a number you already have and confirm the bank details out loud. Do not trust changes to payment details sent in writing.
When sending cryptocurrency, always check the first six and last six characters of the pasted address against the original. If they do not match, your clipboard has been tampered with and the device needs a full malware scan.
Keep endpoint security on and updated. Both campaigns rely on the initial malware getting a foothold, and mainstream antivirus catches most known variants.
Gen has not attributed either campaign to a named group. Jurisdiction for any enforcement action would likely fall to national cybercrime units and, for the banking side, financial regulators in the affected countries.



