Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
1inch

1inch Vendor Cyber Rating & Cyber Score

1inch.com

1inch is the DeFi ecosystem building the future of finance. A community of engineers, designers and problem solvers who believe in the power of Web3 to transform the way the world works - and to offer fair and universal access to finance, for everyone.


1inch A.I CyberSecurity Scoring

1inch
Company Information
Website:https://1inch.com/
Employees number:169
Number of followers:54,604
NAICS:5112
Industry Type:Software Development
Homepage:1inch.com
1inch Risk Score (AI oriented)
Between 700 and 749
logo
1inchSoftware Development
Updated:
27/03/2026
741/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
1inch Global Score (TPRM)
xxxx
logo
1inchSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

1inch
1inchModerate
Current Score
741Ba (MODERATE)
01000
1 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
743Before Incident
AUGUST 2026
743Before Incident
JULY 2026
742Before Incident
JUNE 2026
742Before Incident
MAY 2026
741Before Incident
APRIL 2026
741Before Incident
MARCH 2026
741Before Incident
FEBRUARY 2026
740Before Incident
JANUARY 2026
740Before Incident
DECEMBER 2025
739Before Incident
NOVEMBER 2025
739Before Incident
OCTOBER 2025
738Before Incident
JUNE 2025
754Before Incident
Cyber Attack
02 Jun 20251inch
1inch: Cyberattack On Web3 Support Staff Uses Fake Screenshots For Malware Delivery

Sophisticated Malware Campaign Targets Web3 Support Teams via Fake Screenshots

736After Incident
CRITICAL-18
1IN1774607100
Sophisticated Malware Campaign Targets Web3 Support Teams via Fake Screenshots A highly targeted malware campaign is exploiting customer support channels of Web3 platforms, with decentralized exchange 1inch recently identifying a persistent threat aimed at its staff. Attackers masquerade as frustrated users seeking transaction assistance, sharing links disguised as innocuous screenshots. Instead, these links trigger a multi-stage infection chain designed to compromise workstations and establish persistent backdoor access. This shift marks a tactical evolution for threat actors, moving from passive watering-hole attacks to direct social engineering against customer-facing employees. Security researchers have attributed the activity with moderate confidence to APT-Q-27 (GoldenEyeDog), a financially motivated Chinese-nexus group active since at least 2022. The group has a documented history of targeting the global cryptocurrency and gambling sectors. ### Attack Anatomy The malware employs a custom runtime encryption scheme to conceal strings, preventing plaintext URLs or file paths from being stored on disk. Upon execution, the initial loader performs anti-debugging and sandbox-evasion checks before retrieving a payload manifest from an AWS S3 dead drop. The malware then downloads a six-file package into a hidden staging directory, impersonating the Windows Update cache (with a unique @27 tag) to evade detection. The attack leverages DLL sideloading, using a legitimately signed executable (updat.exe) from the YY platform. Since Windows prioritizes local directory dependencies, the malicious vcruntime140.dll and msvcp140.dll files are loaded instead, executing within the context of a trusted application and bypassing signature verification. ### Infrastructure & Attribution The final backdoor communicates with 37 distinct command-and-control (C2) servers over TCP port 15628, using a 16-byte rolling XOR cipher to encrypt traffic. Several C2 IPs reside on autonomous systems previously linked to APT-Q-27, with geolocation obfuscation masking their origins. Key indicators include: - Initial loader (photo2025060268jpg.exe) – Disguised as an image file. - Primary loader (Feedback.exe) – .NET dropper. - Legitimate binary (updat.exe) – Used for sideloading. The campaign underscores the growing sophistication of threats targeting Web3 infrastructure, where social engineering and evasion techniques are increasingly refined.
INCIDENT DETAILS -
TYPE
Malware Campaign
MOTIVATION
Financial Gain
IMPACT
Systems Affected: Workstations of Web3 support teamsOperational Impact: Persistent backdoor access established

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for 1inch ?
?
What was 1inch's A.I Rankiteo Cyber Score in August 2026 ?
?
What was 1inch's A.I Rankiteo Cyber Score in July 2026 ?
?
What was 1inch's A.I Rankiteo Cyber Score in June 2026 ?
?
What was 1inch's A.I Rankiteo Cyber Score in May 2026 ?
?
What was 1inch's A.I Rankiteo Cyber Score in April 2026 ?
?
What was 1inch's A.I Rankiteo Cyber Score in March 2026 ?
?
What was 1inch's A.I Rankiteo Cyber Score in February 2026 ?
?
What was 1inch's A.I Rankiteo Cyber Score in January 2026 ?
?
What was 1inch's A.I Rankiteo Cyber Score in December 2025 ?
?
What was 1inch's A.I Rankiteo Cyber Score in November 2025 ?
?
What was 1inch's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on 1inch's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with 1inch ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view 1inch's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?