TrendAI Reasearch: Financial Threats at Machine-Speed

Share this article
Share this article
Prioritise Us on Google
The report Modern Bank Heists 2026: The Machine-Speed War for Financial Control, reveals a major shift in attacker strategy | Credit: Getty
Cybercrime has entered its industrial age, says Bharat Mistry, Field CTO at TrendAI, as AI-powered attacks on financial institutions escalate

Agentic AI, state-sponsored threat actors and cybercrime-as-a-service are outpacing financial sector defences, a TrendAI report has found. 

In its report titled Modern Bank Heists 2026: The Machine-Speed War for Financial Control, TrendAI surveyed CISOs from the financial sector and the findings reveal a major shift in attacker strategy. 

The report found a surge in counter-incident response, with 67% of institutions experiencing an attacker push back during ongoing cyber incidents, as they try to undermine the work of defenders. 

There was also a stupendous rise in AI-enabled attacks at 89% year-over-year, cementing the fact that attacks are now happening at the speed of the machine.

Campaigns that once required skilled operators, such as phishing and fraud, all now run in the background on their own thanks to AI.

“Cybercrime has entered its industrial age,” says Bharat Mistry, Field CTO at TrendAI.

Bharat Mistry, Field CTO at TrendAI

“Criminal organisations are chaining together AI agents that can conduct reconnaissance, launch phishing campaigns, evade detection and exploit vulnerabilities with minimal human intervention. 

“Financial institutions are no longer facing isolated attacks, they are confronting highly automated adversaries operating at machine speed.”

Destructive attacks dominate

Of those surveyed, 41% suffered a cyberattack that was destructive. 

TrendAI says that this is indicative of a “deliberate shift from exfiltration toward damage”. There was also a 55% increase in API-based attacks, the report finds.

As well as this, criminals are stealing market strategies, with 46% experienced attempts to steal non-public market intelligence or investment strategies. TrendAI says they do so as aggressively as they target funds. 

The most concerning threat according to 37% respondents was account takeover, followed at 28% by business email compromise (BEC) and reverse business email compromise (RBEC) schemes enhanced by deepfakes. 

Financial institutions are no longer facing isolated attacks, they are confronting highly automated adversaries operating at machine speed

Bharat Mistry, Field CTO at TrendAI

About four in 10 (37%) said that they confirmed ‘island hopping’ – when attackers not only compromise the organisation's infrastructure but also then use it to target its customers.

This all comes at a time when 54% organisations are seeing no budget increase, as security leadership remains “structurally subordinated”. 

Steganography and invisible prompt injection 

To help hide in plain sight their notorious attack infrastructure, cybercriminals are embedding commands within image pixels so they can be later accessed by malware.

One example is Daserf backdoor, which uses steganographic algorithms like RC4 along with base64 encoding. This enables it to establish covert command-and-control (C&C) channels that sink under the radar of traditional traffic inspection.

Nation state actors like Pawn Storm use steganography with legitimate cloud services to evade endpoint monitoring entirely. 

Cybercriminals are also known to exploit compromised cloud storage buckets to distribute malicious code contained in images. 

Key facts and figures
  • AI-enabled attacks rose 89% year-over-year
  • 67% of institutions experienced an attacker push back during ongoing cyber incidents
  • 54% organisations are seeing no budget increase, as security leadership remains “structurally subordinated”

A new frontier that did not exist two years ago is that of invisible prompt injection. In this sort of attack, malicious instructions embedded in images are silently processed and acted on by AI systems.

Plagued by RATs

Five particular remote access trojans (RATs), according to TrendAI, pose a major threat to financial institutions.

  1. Remcos: Once marketed as a legitimate tool, this is now a real-time surveillance platform and is capable of live webcam streaming and instant keystroke transmission
  2. AsyncRAT: A free, open source RAT which is remarked by TrendAI as “most prolific” in terms of volume is the culprit behind the Winnti-linked GodRAT campaign via Skype
  3. XenoRAT: This was forked by a nation state actor – North Korea's Kimsuky advanced persistent threat (APT) group – into a variant called MoonPeak. Deployed against South Korean financial and government entities, this boasts a billion-dollar impact
  4. BananaRAT: The malware combines screen streaming, overlay injection, QR code-based Pix transaction manipulation and continuous keylogging into a single platform designed for fraud and surveillance. Operated by an elite Brazilian cybercrime group, SHADOW-WATER-063, it was successfully used to target 16 financial institutions and cryptocurrency exchanges across Brazil.
  5. XWorm: Regarded as the most sophisticated of the group, this one is available in the form of malware-as-a-service (MaaS) with a US$500 lifetime license. “It is the only tool in this class that covers every major financial attack vector from a single implant,” TrendAI says. 
Youtube Placeholder

Each of these have been confirmed to have mounted campaigns against banks or crypto exchanges.  

The report concludes that financial institutions need to move beyond reactive cybersecurity and adopt a proactive intrusion suppression strategy. 

TrendAI recommends combining AI-powered detection with proactive threat hunting, virtual patching and managed detection and response to improve resilience against increasingly autonomous attacks.

The company also advises organisations to build AI-enabled security operations capable of responding at machine speed, strengthen protection against prompt injection, deepfake-enabled fraud and business email compromise and elevate CISOs into independent executive leadership roles with direct responsibility for cyber resilience.

Company portals

Executives