Phishing and Ransomware in Italy: Data Breach Affects Government Agencies and Cryptowallet Providers; Chinese APT Campaigns

Weekly Threats hor Telsy

Italy: phishing and ransomware campaigns

Over the past week, several phishing campaigns have been detected involving fraudulent websites mimicking those of major financial and government organizations.

A clone portal of Wise, a global money transfer service, was designed to carry out phishing activities with various consequences for Italian users. The first screen displayed to potential victims steals their account login credentials and the phone number linked to the account; a subsequent screen asks for the PIN received via text message, a detail that suggests real-time interaction with an attacker. This is followed by a prompt to link the Wise profile to an email account—requiring the user’s email credentials—and then a request for a selfie while showing an ID document. In addition to enabling account takeover, the operation appears to be aimed at identity theft as well.

Fake websites that mimic the design and logos of the Italian Electronic Health Record (FSE), Ministry of Health, Department for Digital Transformation, and Ministry of Economy and Finance aim to steal users’ personal data and payment card details. The bait is an alleged refund of €20.73 for the purchase of medications at a pharmacy. The fraudulent process begins with a CAPTCHA verification to rule out automated bots and continues with a refund notification, a request for complete personal and contact information, and a request for payment card details. The stolen information can be used directly to carry out fraudulent transactions or other social engineering attacks, or it can be resold.

As for claims of ransomware attacks, among the organizations targeted by Qilin Team are two long-established publishing houses: Zanichelli Editore S.p.A. in Bologna and Loescher Editore (a division of Zanichelli), based in Turin. The attacker set the deadline for ransom negotiations for September 1st, the day on which it threatens to release the stolen data.

 

Data breach: the Direction générale des Finances publiques (DGFiP), Land Berlin, the Ukrainian government agency ARMA, and SafePal have been targeted

On August 14, 2026, the Direction générale des Finances publiques (DGFiP), the French tax and accounting administration, announced that an attacker had claimed to have gained unauthorized access to its information system in June and July 2026 by impersonating a DGFiP agent and an authorized third party. Analyses reportedly confirmed that data pertaining to 678,000 private individuals and professionals had been accessed and exfiltrated, including: taxable income, family allowance coefficient, withholding tax rate, company name and SIREN number, addresses, and property sizes. The DGFiP notified the Commission nationale de l’informatique et des libertés (CNIL) and announced that it would contact the affected individuals directly and file a complaint.

On August 17, 2026, Land Berlin, the federal state of Berlin, announced that it had detected a breach of the State network (Landesnetz). The incident caused disruptions to government operations and certain public services: the email systems of the affected agencies were taken offline, online applications for mail-in voting were limited, and difficulties were encountered in managing the Wohngeld, the housing allowance provided to over 50,000 households. According to the Senate Chancellery, no sensitive data was compromised in the attack. Preliminary investigations indicate that only publicly accessible data from the urban development administration was affected.

The systems of Ukraine’s Asset Recovery and Management Agency (ARMA)—the agency responsible for recovering and managing assets seized from criminals and sanctioned individuals—suffered a cyberattack. The incident occurred just a few days before the deadline for submitting bids in the competition to select the asset manager for IDS Ukraine, a bottled mineral water producer. The company is controlled by Russian oligarch Mikhail Fridman, who is subject to sanctions. According to Yaroslava Maksymenko, ARMA’s interim director, the agency had already detected signs of interference as early as last spring, including unauthorized access to the registry of officials. The National Anti-Corruption Bureau of Ukraine (NABU) has launched an investigation into these incidents, while the circumstances of the cyberattack are being investigated by the Security Service of Ukraine (SBU), which will determine whether a coordinated campaign took place aimed at obstructing the Agency’s activities and compromising or discrediting the selection process.

On August 16, 2026, SafePal, provider of hardware wallets and non-custodial wallet suites for cryptocurrencies, announced that it had suffered a security incident involving unauthorized access to order data for approximately 39,000 customers. The incident reportedly affected names, email and shipping addresses, phone numbers, and purchase information. The breach was traced to a flaw in the order-tracking function of a plug-in associated with customer order information. The security issue has been resolved, and all customers have been notified. The company states that it cannot verify the authenticity of claims regarding the attack or offers to sell the data that have reportedly been circulating in recent days.

 

State-Sponsored Campaigns: Operations of Two Chinese APTs Tracked

Among the state-sponsored threat actors recently tracked, two Chinese APTs stand out for having conducted sophisticated operations.

Mustang Panda carried out cyberespionage activities in Pakistan, Mongolia, Myanmar, and Russia, targeting organizations—including government agencies—that align with known victimology. The arsenal exploited includes the PlugX backdoor and an updated variant of the COOLCLIENT backdoor. The latter incorporates a signed kernel-mode driver, named msagent.sys, which functions as a Windows rootkit. The driver enhances the ability to conceal malicious processes, files, registry entries, and network information related to C2 servers, significantly increasing its ability to evade detection.

Earth Alux conducted a large-scale campaign that combined cyberespionage operations against governments and military entities in the Middle East, Southeast Asia, and South Asia with for-profit cryptocurrency scams targeting Chinese-speaking users. Both malicious activities are managed through the same infrastructure and a single custom control panel. The latter, called XG-Web, is a browser-centric framework for remote access and information theft built as a React dashboard on a Node.js backend and a MySQL database. XG-Web is described by its developers as a penetration-testing platform, but it is used to carry out browser hijacking, data theft, and man-in-the-middle attacks. In one of the most significant attacks, the group compromised the shared hosting platform of a state-owned telecommunications provider in the Middle East by inserting a script into a common webmail template, simultaneously targeting more than fifteen government tenants.

 


Weekly Threats Report is Telsy’s weekly update featuring the main developments on cyber attacks and threat actors worldwide, produced by our Threat Intelligence & Response team.

The team is composed of analysts and security researchers with technical and investigative skills and internationally recognized experience.

Through continuous monitoring of cyber threats and geopolitical events, it produces and provides organizations with useful information to anticipate attacks and understand their scope, with the support of a trusted partner in the event of a cyber incident.

Learn more about our Cyber Threat Intelligence solution.