Bharat Threat FeedGlobal threats, decoded for Indian defenders
Government & Defence Sector Edition · August 2026

Government & Defence Sector Edition — August 2026

Two things changed for Indian financial institutions this month, and they pull in opposite directions. The Reserve Bank rewrote the rulebook on 31 July, consolidating cybersecurity and technology risk into a single set of Directions that name the CISO's reporting line and put a six-hour clock on incident reporting. In the same window an Android banker rebuilt itself around device takeover rather than credential theft, a maximum-severity Oracle flaw reached the exploited list, and a perimeter authentication bypass landed on NetScaler. This edition covers what is being exploited now, what the new Directions actually ask for, and which dates are already behind schedule.

1. Sector snapshot

Finance is being attacked on two paths, and the vendor path is the one most Indian institutions measure least well. Black Kite recorded a 76 percent year-on-year rise in direct ransomware attacks on financial institutions in the first quarter of 2026, and counted 48 distinct threat groups targeting the sector in 2025, up from 37 in 2023. Across the 140 finance-concentrated third-party vendors it studied, 54 percent carried a vulnerability listed in CISA's known exploited catalogue and 78 percent showed critical-level patch-management failures. CYFIRMA's Q2 2026 finance report placed the sector in 14 of 23 observed APT campaigns and ranked India third among reported victim countries. Mobile is the other growth line: Zimperium tracked 34 active banking malware families through 2025 against more than 1,200 financial applications in 90 countries, with Android malware-driven fraudulent transactions up 67 percent year on year.

Source (with date): Black Kite (3 Jun 2026); CYFIRMA (18 May 2026); Zimperium (19 Mar 2026).

2. Threats targeting BFSI

1

ToxicPanda 2.0 does not phish the customer, it operates the phone

Zimperium's zLabs team published its analysis on 19 August 2026. The trojan now carries 167 remote commands and performs overlay-based credential theft against 349 banking, financial, e-wallet and cryptocurrency applications, against 16 in the first version; a separate module harvests the device lock credential across 140 apps. It abuses Android Accessibility Services to turn on Wireless Debugging, then drives the ADB daemon for shell-level command execution without root. It requests VPN service permission to create a local interface and block traffic to Google Play and Play Services, suppressing Play Protect checks and app updates, and covers activity with fake system-update screens. Delivery is from AWS-hosted buckets, with persistent WebSocket command and control. Zimperium reports 16 affected countries; Infosecurity Magazine's coverage names Pakistan, South Africa, Mexico, Nigeria and India among them. For Indian retail banking the consequence is direct: SMS and OTP verification is not a control on a device the malware already operates.

SourceZimperium zLabs (19 Aug 2026); Infosecurity Magazine (20 Aug 2026); BleepingComputer (23 Aug 2026).
2

One mailbox at a public-sector bank, and the reason mailboxes matter

Bank of Baroda confirmed a cyber incident on 28 July 2026 after an employee email account was compromised, giving unauthorised access to certain data. The bank stated it detected and contained the incident and that core banking systems were not accessed. An actor operating under an alias advertised allegedly stolen material on a darknet marketplace; the bank did not confirm exfiltration and the claim was not independently verified by the reporting outlet. We are not reproducing or characterising the claimed data. The lesson for other institutions is structural. A relationship manager's or credit officer's mailbox accumulates loan files, KYC attachments, sanction letters and audit correspondence in full fidelity, and usually sits outside the controls, retention limits and monitoring applied to the core banking platform.

SourceThe Record (28 Jul 2026).
3

Income Tax Department impersonation, delivering an Android banker and a Windows infostealer

CloudSEK documented a campaign running through the filing season. The lures are administrative rather than technical: WhatsApp office memoranda citing sections 271(1)(c) and 276C with fabricated reference numbers and a 72-hour deadline, refund messages by SMS and email, cloned e-Filing portals harvesting credentials and PAN, and fake e-PAN files. An Android package distributed as ITD.zip intercepts SMS and one-time passwords, harvests contacts, captures keystrokes and overlays fake banking screens. A Windows executable named ITD_Tax_Notice.exe is a packed infostealer masquerading as svchost.exe that pulls a second stage from cloud storage. Infrastructure is disposable, on .lol, .xin, .ink and .autos domains. This belongs to fraud teams as much as to the SOC, because the OTP-interception path lands on retail banking and UPI.

SourceCloudSEK (30 Jul 2026).

3. Sector tech & exposures

Citrix NetScaler ADC and Gateway, CVE-2026-19490. Authentication bypass at CVSS v4.0 9.3, remote and unauthenticated, published alongside CVE-2026-19489, a memory overflow at 8.8. Affected builds are 14.1 before 14.1-73.32 and 13.1 before 13.1-63.21, plus the FIPS and NDcPP variants. The flaw depends on configuration rather than on the appliance being present, and Rapid7 points teams at NetScaler configurations holding a SAML action and authentication or VPN vserver entries as the check to run. Rapid7 had not observed exploitation as of 19 August 2026. Treat that as a scheduling window, not as reassurance.

Source (with date): Citrix security bulletin CTX696939; Rapid7 (19 Aug 2026); Help Net Security (21 Aug 2026).

Oracle HTTP Server and WebLogic Server Proxy Plug-in, CVE-2026-21962. Improper access control at CVSS 10.0, letting an unauthenticated attacker with HTTP access reach or modify critical data. Oracle shipped the fix in its January 2026 update. CISA added the flaw to the known exploited catalogue on 24 August 2026 with a federal remediation date of 27 August, and reporting on that addition attributes the earliest observed attacks to January, first flagged by CloudSEK. This is the item to escalate in Indian BFSI: Oracle HTTP Server and WebLogic sit beneath a considerable amount of core banking, net-banking and insurance middleware, often owned by an application vendor rather than by infrastructure, and therefore often off the patch calendar.

Source (with date): CISA KEV (24 Aug 2026); The Hacker News (25 Aug 2026); SecurityWeek (24 Aug 2026).

The CISA batch of 18 August 2026, four flaws, all confirmed exploited. CVE-2026-33824, a double free in the Windows IKE Service Extensions leading to remote code execution, CVSS 9.8. CVE-2026-55040, weak authentication in SharePoint Server permitting a security-feature bypass, CVSS 9.1. CVE-2026-59310, path traversal in Broadcom VMware vCenter allowing code execution by an attacker with network access to vCenter, CVSS 9.8. CVE-2026-65400, improper authentication in macOS Screen Sharing, CVSS 9.8. The federal remediation date was 21 August. In a bank data centre the vCenter entry deserves separate escalation, because it is a management plane above the whole virtual estate rather than one more server.

Source (with date): CISA KEV (18 Aug 2026); The Hacker News (19 Aug 2026).

Palo Alto Networks PAN-OS GlobalProtect, CVE-2026-0257. An authentication bypass on the GlobalProtect portal and gateway, exploitable where authentication override cookies are enabled with particular certificate configurations, letting an unauthenticated attacker establish a VPN session without credentials. Palo Alto issued the fix on 13 May 2026 and revised the severity upward after Rapid7 confirmed exploitation; CISA listed it on 29 May 2026. Arctic Wolf Labs later investigated June 2026 intrusions in which this vulnerability was the consistent initial access vector, with operators moving from perimeter compromise to domain-wide ransomware encryption.

Source (with date): Unit 42 (9 Jun 2026); Arctic Wolf Labs; CISA KEV (29 May 2026).

4. Regulatory & compliance watch

RBI's Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions, 2026. Issued on 31 July 2026 and effective on issue, as parallel Directions covering each class of regulated entity, including commercial banks, small finance banks, payments banks, urban co-operative banks, all-India financial institutions, NBFCs and credit information companies. They repeal and consolidate the earlier cybersecurity and IT governance framework. The governance change is the part that cannot be answered with a tool purchase: the CISO reports to the Executive Director overseeing risk management and presents quarterly reviews to the board and its committees. Alongside that sit a cyber security operations centre for continuous monitoring, multi-factor authentication for privileged users, DMARC, vulnerability assessment every six months on critical systems, annual penetration testing on critical customer-facing systems, disaster-recovery drills every six months with full switchover, and named contractual controls on ATM switch and core banking service providers. Cyber incidents must be reported to RBI through the DAKSH platform within six hours of detection, alongside CERT-In reporting where applicable.

Source (with date): RBI Directions of 31 Jul 2026, as summarised by TaxGuru and Risk Awareness (26 Aug 2026).

SEBI CSCRF: the live date is the Action Taken Report. For the covered participant categories the preliminary cyber-audit report was due on 30 June 2026 and the corrective Action Taken Report is due on 30 September 2026. Audit scope is 100 percent of critical systems plus a documented 25 percent sample of non-critical systems, with the sampling rationale stated in the report. Group entities holding a broking or depository-participant licence alongside a banking or NBFC entity sit inside both this cycle and the RBI Directions above, audited by different parties.

Source (with date): NSE and NSDL cyber-audit circulars under SEBI CSCRF, as summarised by GovPing (22 Apr 2026).

CERT-In's patching guidance read against this week's list. The May 2026 blueprint recommends, using the phrase where feasible, that known exploited vulnerabilities on internet-facing systems be patched within 12 hours, critical externally exposed flaws within one day and high-severity flaws within five days on a risk basis. It is guidance with indicative timelines, not a binding mandate, and it sits beside the April 2022 directions requiring incident reporting within six hours. Read against section 3, an internet-facing Oracle HTTP Server or an unpatched NetScaler carried into this week is well outside the recommended window, and once an incident is detected the DAKSH clock now runs in parallel with the CERT-In one.

Source (with date): CERT-In; The Hacker News (26 May 2026).

5. Actor in focus — Qilin

Qilin is a ransomware-as-a-service operation, criminal rather than state-directed, and currently the crew with the most consistent presence in financial-sector victim data. Black Kite links it to 59 finance-sector incidents and names it alongside Akira and Kill Security as the groups leading targeting of the sector; CYFIRMA's Q2 2026 finance report records it with the highest victim count for the sector that quarter.

Its relevance to Indian BFSI is the access route rather than any claimed Indian victim. Arctic Wolf Labs documented June 2026 intrusions in which affiliates exploited the PAN-OS GlobalProtect bypass described in section 3 to obtain a VPN session, then moved to domain-wide encryption. Behaviour after entry varied between rapid encryption-only operations and full double extortion, consistent with several affiliates working under the same platform. That variation matters for detection, because there is no single dwell-time assumption to plan against. The second pattern is fourth-party concentration: Black Kite attributes a September 2025 campaign against one South Korean managed service provider that cascaded into 32 financial institutions and more than 2TB of stolen data, and that MSP-dependency shape is common across Indian bank and NBFC vendor ecosystems. Stated plainly, no Indian BFSI victim is attributed to Qilin in the sources reviewed for this issue; the exposure is the initial-access pattern, which is vendor-agnostic and already present in Indian estates.

Source (with date): Black Kite (3 Jun 2026); CYFIRMA (18 May 2026); Arctic Wolf Labs (Jun 2026).

6. IOC pack

Every indicator below is already public in the named source and is reproduced with attribution. These are not Nirad observations.

IndicatorTypeContextSource
cctvv2[.]com/panelC2 panelToxicPanda 2.0Zimperium zLabs
www.v17001[.]com/panelC2 panelToxicPanda 2.0Zimperium zLabs
www.w17907[.]com/panelC2 panelToxicPanda 2.0Zimperium zLabs
g8688808[.]comC2 domainToxicPanda 2.0Zimperium zLabs
ITD.zipFilename (Android dropper archive)Income Tax Department impersonationCloudSEK
ITD_Tax_Notice.exeFilename (Windows infostealer)Masquerades as svchost.exeCloudSEK
667b37eafb9ec5131ed4f017ed429a47dca3adf626b2fc85fc6424b1e17ff6e1SHA-256Windows infostealer sampleCloudSEK
vss2.oss-cn-hongkong[.]aliyuncs[.]comCloud bucketSecond-stage payload stagingCloudSEK
apeal[.]lol, tarif[.]lol, bcgovtop[.]lol, fsyahsxd[.]xinPhishing domainsTax-themed impersonationCloudSEK
CVE-2026-19490 / CVE-2026-19489CVENetScaler authentication bypass and memory overflowCitrix; Rapid7
CVE-2026-21962CVEOracle HTTP Server / WebLogic Proxy Plug-in, exploitedCISA KEV
CVE-2026-59310CVEVMware vCenter path traversal RCE, exploitedCISA KEV
CVE-2026-55040CVESharePoint Server weak authentication, exploitedCISA KEV
CVE-2026-33824CVEWindows IKE Service Extensions double free, exploitedCISA KEV
CVE-2026-65400CVEmacOS Screen Sharing improper authentication, exploitedCISA KEV
CVE-2026-0257CVEPAN-OS GlobalProtect bypass, Qilin initial accessUnit 42; Arctic Wolf Labs

7. Tiered actions

Board. Ask for three things in writing against the RBI Directions: the CISO's current reporting line, the quarterly board review schedule, and the status of the named contractual controls on ATM switch and core banking service providers. Where a group entity holds a SEBI licence, ask for the position on the 30 September 2026 Action Taken Report. Ask whether the six-hour DAKSH path has been tested end to end, including out of hours, rather than only documented.

CISO. Patch on an emergency basis across Oracle HTTP Server and WebLogic, VMware vCenter, NetScaler, SharePoint, Windows IKE and PAN-OS GlobalProtect, starting with the Oracle and vCenter entries because both are confirmed exploited and both sit under shared services. On NetScaler and GlobalProtect, terminate and re-issue active sessions after patching; a patch does not invalidate session material already taken. Establish which internet-facing middleware is owned by an application vendor rather than by infrastructure and put those assets on your own patch clock. Run a fourth-party and MSP privileged-access review against the pattern in section 5. Review mailbox-level controls, attachment retention and export monitoring for relationship, credit and audit functions. At the MDM or EMM layer, block sideloaded packages and alert on Accessibility Service grants and Wireless Debugging enablement.

SOC. Hunt the indicators in section 6. On managed devices, alert on an Accessibility Service grant followed by ADB activation, and on applications requesting VPN service permission without a business reason. On the perimeter, alert on GlobalProtect sessions from unfamiliar hostnames, monitor NetScaler SAML action and VPN vserver configuration changes, and baseline vCenter administrative access before you need it. Feed the tax-themed lure paths and the OTP-interception behaviour into fraud telemetry, not only into email security, and agree with the fraud team which function owns the alert.

8. Source index

Arctic Wolf Labs · BleepingComputer · Black Kite · CERT-In · CISA KEV · Citrix · CloudSEK · CYFIRMA · GovPing · Help Net Security · Infosecurity Magazine · NSDL · NSE · Rapid7 · Reserve Bank of India · Risk Awareness · SecurityWeek · TaxGuru · The Hacker News · The Record · Unit 42 (Palo Alto Networks) · Zimperium zLabs

9. Byline

4

Nirad Threat Research

NBTF — BFSI Sector Edition | 26 August 2026