es
Feedback
Group-IB

Group-IB

Ir al canal en Telegram

Your daily source of cybersecurity news brought to you by Group-IB, one of the global industry leaders.

Mostrar más
2 366
Suscriptores
-424 horas
+27 días
+3130 días
Atraer Suscriptores
julio '26
julio '26
+53
en 0 canales
junio '26
+2 345
en 1 canales
Get PRO
mayo '260
en 0 canales
Get PRO
abril '26
+46
en 0 canales
Get PRO
marzo '26
+82
en 0 canales
Get PRO
febrero '26
+94
en 1 canales
Get PRO
enero '26
+62
en 0 canales
Get PRO
diciembre '25
+53
en 0 canales
Get PRO
noviembre '25
+64
en 0 canales
Get PRO
octubre '25
+2 159
en 0 canales
Get PRO
septiembre '25
+18
en 0 canales
Get PRO
agosto '25
+42
en 0 canales
Get PRO
julio '25
+56
en 0 canales
Get PRO
junio '25
+32
en 0 canales
Get PRO
mayo '25
+43
en 0 canales
Get PRO
abril '25
+57
en 0 canales
Get PRO
marzo '25
+46
en 1 canales
Get PRO
febrero '25
+63
en 0 canales
Get PRO
enero '25
+73
en 0 canales
Get PRO
diciembre '24
+71
en 0 canales
Get PRO
noviembre '24
+81
en 0 canales
Get PRO
octubre '24
+70
en 0 canales
Get PRO
septiembre '24
+117
en 0 canales
Get PRO
agosto '24
+75
en 0 canales
Get PRO
julio '24
+85
en 0 canales
Get PRO
junio '24
+74
en 0 canales
Get PRO
mayo '24
+85
en 0 canales
Get PRO
abril '24
+95
en 0 canales
Get PRO
marzo '24
+92
en 1 canales
Get PRO
febrero '24
+122
en 0 canales
Get PRO
enero '24
+106
en 2 canales
Get PRO
diciembre '23
+109
en 1 canales
Get PRO
noviembre '23
+87
en 0 canales
Get PRO
octubre '23
+89
en 0 canales
Get PRO
septiembre '23
+104
en 0 canales
Get PRO
agosto '23
+95
en 0 canales
Get PRO
julio '23
+149
en 0 canales
Get PRO
junio '23
+102
en 0 canales
Get PRO
mayo '23
+102
en 0 canales
Get PRO
abril '23
+87
en 0 canales
Get PRO
marzo '23
+32
en 0 canales
Get PRO
febrero '23
+176
en 0 canales
Get PRO
enero '23
+15
en 0 canales
Get PRO
diciembre '22
+16
en 0 canales
Get PRO
noviembre '22
+24
en 0 canales
Get PRO
octubre '22
+17
en 0 canales
Get PRO
septiembre '22
+76
en 0 canales
Get PRO
agosto '22
+29
en 0 canales
Get PRO
julio '22
+71
en 0 canales
Get PRO
junio '22
+20
en 0 canales
Get PRO
mayo '22
+14
en 0 canales
Get PRO
abril '22
+29
en 0 canales
Get PRO
marzo '22
+21
en 0 canales
Get PRO
febrero '22
+15
en 0 canales
Get PRO
enero '22
+25
en 0 canales
Get PRO
diciembre '21
+38
en 0 canales
Get PRO
noviembre '21
+13
en 0 canales
Get PRO
octubre '21
+25
en 0 canales
Get PRO
septiembre '21
+20
en 0 canales
Get PRO
agosto '21
+23
en 0 canales
Get PRO
julio '21
+20
en 0 canales
Get PRO
junio '21
+261
en 0 canales
Fecha
Crecimiento de Suscriptores
Menciones
Canales
27 julio+1
26 julio0
25 julio+4
24 julio+3
23 julio0
22 julio+1
21 julio+2
20 julio+2
19 julio+4
18 julio+3
17 julio+4
16 julio+2
15 julio+1
14 julio+1
13 julio0
12 julio+2
11 julio+4
10 julio0
09 julio+3
08 julio+1
07 julio+2
06 julio+2
05 julio0
04 julio+2
03 julio+3
02 julio+2
01 julio+4
Publicaciones del Canal
🚨A single OPSEC mistake exposed an entire China-nexus operation. An exposed Alibaba Cloud staging server provided a rare vie
🚨A single OPSEC mistake exposed an entire China-nexus operation. An exposed Alibaba Cloud staging server provided a rare view into an active threat operation. The infrastructure revealed attacker tooling, bash history, victim paths, and post-exploitation activity, leading to the discovery of a previously undocumented threat cluster we track as JadeProx. Key Highlights: 🔹Discovery of TriBack Loader, a previously undocumented malware family observed across four infection chains. 🔹Targeting of government, healthcare, and education organizations across Southeast Asia, alongside phishing campaigns in Latin America. 🔹Abuse of signed Microsoft and G DATA binaries for DLL sideloading and payload execution. 🔹Use of InitOnceExecuteOnce, TimerQueue callbacks, and EtwpCreateEtwThread for evasion. 🔹Deployment of AdaptixC2 and the Beagle backdoor through a shared loader architecture. 🔹Large-scale vulnerability scanning, credential harvesting, and tunneling activity. 🔗 Read the full blog #ThreatIntelligence

2
🚨 Group-IB Threat Intelligence researchers have uncovered HOLLOWGRAPH, a Windows malware linked with high confidence to the
🚨 Group-IB Threat Intelligence researchers have uncovered HOLLOWGRAPH, a Windows malware linked with high confidence to the Cavern framework that abuses Microsoft Graph API and compromised Microsoft 365 accounts to establish a covert command-and-control channel. Key findings from our research: 🔹 Microsoft 365 calendars repurposed as two-way dead drops for command execution and data exfiltration 🔹 Commands and stolen files hidden inside encrypted calendar event attachments scheduled for the year 2050 🔹 DNS tunneling over IPv6 AAAA records used to refresh Microsoft Entra ID credentials required for cloud-based C2 communications 🔹 At least 12 identified victims, with telemetry suggesting a highly targeted operation focused on Israeli entities 🔹 Technical overlaps linking HOLLOWGRAPH to the broader Cavern framework Read the full technical analysis. #ThreatIntelligence #CyberSecurity #MalwareAnalysis
447
3
🚨Group-IB researchers have uncovered ClickLock Stealer, a previously undocumented macOS malware that combines ClickFix socia
🚨Group-IB researchers have uncovered ClickLock Stealer, a previously undocumented macOS malware that combines ClickFix social engineering, credential theft, crypto wallet harvesting, Keychain extraction, and persistent remote access into a single attack chain. Key findings: 🔹At least 100 victims identified across 33 countries, with more than 50% located in Europe 🔹Targets 8 browsers, 31 crypto wallet extensions, 7 password manager extensions, and 8 desktop wallet applications 🔹Uses coercive "locker" techniques that repeatedly kill user applications until victims enter passwords or approve Keychain access 🔹Leverages Telegram bots for exfiltration and a modified GSocket backdoor for persistent access 🔹Relies entirely on social engineering, requiring no exploits or elevated privileges to compromise systems 🔹Had zero detections at the time of discovery Read the full technical analysis. #ThreatIntelligence #MalwareAnalysis #CyberSecurity #ClickLockStealer
594
4
Android malware continues to evolve, and RedHook is a prime example of how legitimate developer features can be repurposed fo
Android malware continues to evolve, and RedHook is a prime example of how legitimate developer features can be repurposed for malicious gain. Our latest research analyzes the newest version of the RedHook Android RAT, which introduces a sophisticated privilege abuse chain by leveraging ADB Wireless Debugging to obtain shell-level access.. Key Highlights: 🔹 Autonomous abuse of ADB Wireless Debugging to gain shell-level privileges (uid 2000) 🔹 Integration of the Shizuku framework to execute protected Android system APIs 🔹 An expanded command-and-control framework supporting 53 remote commands 🔹 A robust persistence stack designed to survive reboots and evade process termination 🔹 Distribution through spoofed government and financial websites, with malicious APKs hosted on trusted platforms such as GitHub and AWS S3 🔹 Recent activity indicating an expansion of targeting from Vietnam to Indonesia Read the full technical analysis. #ThreatIntelligence #ThreatResearch #AndroidMalware
749
5
Scattered Spider has been linked to major cyberattacks in recent years, but our latest research suggests the threat is often
Scattered Spider has been linked to major cyberattacks in recent years, but our latest research suggests the threat is often misunderstood. Group-IB's investigation shows Scattered Spider is not a single threat group but a decentralized cybercrime collective of independent subclusters connected by shared TTPs. Key findings: 🔹 Scattered Spider is better understood as a network of autonomous subclusters rather than a centralized organization. 🔹 Oktapus represents one subcluster within the Scattered Spider ecosystem, not the collective itself. 🔹 The same subclusters have been linked to SIM swapping, crypto theft, enterprise intrusions, ransomware, and access brokerage. 🔹 Social engineering remains the primary access vector, with phishing, vishing, & smishing campaigns leveraging short-lived identity provider impersonation sites. 🔹 Its decentralized structure allows operations to continue despite arrests & law enforcement action. Read the full technical analysis here. #ThreatIntelligence #ScatteredSpider
667
6
Scattered Spider has been linked to some of the most high-profile cyberattacks in recent years, but our latest research suggests the threat has been misunderstood. Based on Group-IB's investigation, Scattered Spider is not a single organized threat group. Instead, it is a decentralized cybercrime collective made up of independent subclusters connected by shared tactics, techniques, and procedures (TTPs). Key findings: Scattered Spider is better understood as a network of autonomous subclusters rather than a centralized organization. Oktapus represents one subcluster within the broader Scattered Spider ecosystem, not the collective itself. The same subclusters have been linked to SIM swapping, cryptocurrency theft, enterprise intrusions, ransomware, and access brokerage. Social engineering remains the primary initial access vector, with attackers combining phishing, vishing, and smishing while deploying short-lived Okta, Microsoft, and Citrix impersonation sites. The collective's decentralized structure makes it highly resilient, allowing operations to continue despite arrests and law enforcement disruption as evidenced by ongoing activity into 2025. Read the full technical analysis to understand how Scattered Spider operates and what defenders should watch for
1
7
🚨Smishing campaigns continue to evolve beyond convincing lures. Modern phishing operations are increasingly engineered to ev
🚨Smishing campaigns continue to evolve beyond convincing lures. Modern phishing operations are increasingly engineered to evade detection. In our latest technical analysis, Group-IB researchers dissect a campaign targeting drivers in Serbia through fake traffic fine SMS notifications. The investigation links the operation to two Phishing-as-a-Service ecosystems, Darcula and Phoenix, and reveals a phishing framework built for scale, resilience, and evasion. The report explores how attackers: 🔹Deploy disposable lookalike domains and cloned government portals 🔹Use JavaScript-based runtime decoding and client-side obfuscation to hide phishing content from automated scanners 🔹Leverage browser APIs such as requestIdleCallback and IntersectionObserver to selectively render malicious content 🔹Rotate infrastructure rapidly to stay ahead of detection and takedowns Read the full technical analysis. #Phishing #Smishing #CyberSecurity
851
8
Group-IB supported INTERPOL and the Algerian National Police in dismantling SniperDz, a phishing-as-a-service (PhaaS) platfor
Group-IB supported INTERPOL and the Algerian National Police in dismantling SniperDz, a phishing-as-a-service (PhaaS) platform that operated for nearly a decade and enabled cybercriminals to launch phishing campaigns at scale. Key findings: 🔹 20,000+ domains linked to the ecosystem 🔹 30+ global brands impersonated 🔹 80 phishing templates across five languages 🔹 45,000+ victim records reported by the platform in 2016 alone Following a multi-month investigation, the operation led to the disruption of SniperDz infrastructure and the arrest of its primary developer and administrator. The takedown of a platform operating at this scale is a major blow to the phishing ecosystem and helps better protect users of financial, telecom, entertainment, and other online services. 🔗 Read the full story. #CyberSecurity #Phishing #ThreatIntelligence #INTERPOL
1 057
9
Our latest research examines SilabRAT, a Malware-as-a-Service platform sold on underground forums that combines credential th
Our latest research examines SilabRAT, a Malware-as-a-Service platform sold on underground forums that combines credential theft, browser profile cloning, HVNC, Chrome App-Bound Encryption bypass techniques, and cryptocurrency-focused capabilities into a single offering. Key findings: 🔹 SilabRAT has been marketed on underground forums since late 2025 for $5,000/month 🔹 Leverages HVNC for invisible interaction with victim systems; other session access options include browser profile cloning, cookie theft 🔹 Includes functionality to bypass Chrome App-Bound Encryption (ABE) and extract protected browser data 🔹 Features automated cryptocurrency wallet targeting and password recovery capabilities 🔹 Observed in real-world campaigns leveraging ClickFix social engineering techniques As cybercriminals move beyond simple credential theft toward full session compromise, understanding emerging RAT capabilities is critical for defenders. 🔗 Read the full analysis. #ThreatIntel #MalwareAnalysis #CyberSecurity
859
10
💳 The $48 Billion Blind Spot: Why Merchants Pay for Card Breaches They Can’t See The scale of the problem: 🔹200M+ compromis
💳 The $48 Billion Blind Spot: Why Merchants Pay for Card Breaches They Can’t See The scale of the problem: 🔹200M+ compromised payment cards actively circulating in underground markets 🔹E-commerce fraud projected to reach $53 billion in 2025 🔹Every $1 of fraud costs merchants $4.61 once chargebacks, fees, and operational costs are factored in Why merchants can’t access the intelligence: 1️⃣ PCI DSS prohibits storing raw card data 2️⃣ Card network notification systems (Visa CAMS, Mastercard SAFE) operate issuer-to-issuer only 3️⃣ GDPR and data protection laws block cross-border sharing of personal identifiers The result: Merchants absorb losses from cards that were already confirmed compromised. They just had no way to know. What’s changing: Privacy-preserving Distributed Tokenization enables real-time compromised card checks at authorization, without raw card data or PCI DSS scope expansion. Read the full analysis. #FraudPrevention #EcommerceSecurity #Cybersecurity
695
11
🚨Group-IB researchers uncovered a sophisticated global smishing operation that has impersonated more than 267 brands across
🚨Group-IB researchers uncovered a sophisticated global smishing operation that has impersonated more than 267 brands across 72 countries and generated over 4,389 phishing domains since the second half of 2025. The campaign combines SMS phishing, geofencing, device fingerprinting, fake Cloudflare error pages, and encrypted WebSocket communications to evade detection and harvest personal and payment card data in real time. Key findings: 🔹 Telecommunications emerged as the most targeted sector with 1,754 domains, followed by financial services with 696 domains and consumer rewards programs with 488 domains. 🔹 Malicious content is revealed only to victims matching specific geographic and mobile device criteria. 🔹 Stolen data is exfiltrated through encrypted WebSocket channels using binary encoded payloads. 🔹 Approximately 30 percent of the infrastructure is hosted on Tencent Cloud and Alibaba origin servers while being fronted by Cloudflare. Read the full technical analysis. #DRP #Smishing
830
12
🚨Group-IB researchers uncovered a large-scale fraud ecosystem operating ahead of kickoff, with more than 4,300 fraudulent do
🚨Group-IB researchers uncovered a large-scale fraud ecosystem operating ahead of kickoff, with more than 4,300 fraudulent domains impersonating the tournament’s official web presence and over 300 active phishing domains targeting fans globally. At the center of the operation is GHOST STADIUM, a sophisticated phishing campaign leveraging cloned SSO authentication flows, fake hospitality portals, coordinated social media distribution, and multi-rail payment fraud infrastructure. Key Highlights: 🔹4,300+ fraudulent tournament-themed domains identified. 🔹300+ active phishing domains linked to one coordinated operator. 🔹2,513 compromised credential pairs circulating on dark web markets. 🔹Estimated premium ticket fraud losses ranging from $71M to $474M USD. 🔹130,000+ infostealer logs containing tournament-related data. 🔹Underground Fraud-as-a-Service vendors selling phishing kits and ticket scam infrastructure. Read the full technical analysis. #ThreatIntelligence #FraudProtection
960
13
🚨Chinese-language dark web forums and Telegram channels are flooding cybercrime ecosystems with claims of stolen data from f
🚨Chinese-language dark web forums and Telegram channels are flooding cybercrime ecosystems with claims of stolen data from financial institutions worldwide. Group-IB researchers dug in, and the datasets don't hold up. After analyzing 17,000+ messages across five active sources, names and phone numbers trace back to the 2021 Facebook leak, password hashes to the 2020 Eatigo breach, assigned to entirely different individuals. These are not fresh breaches. They are repackaged old data sold as new. The research includes sample validation walkthroughs, upstream source mapping, and identification markers organizations can use to assess similar claims. Read the full analysis. #CyberSecurity #DarkWeb #InfoSec #ThreatIntelligence
1 076
14
🚨201 arrests. 3,867 victims identified. 53 servers seized. Group-IB supported INTERPOL’s Operation Ramz, the first large-sca
🚨201 arrests. 3,867 victims identified. 53 servers seized. Group-IB supported INTERPOL’s Operation Ramz, the first large-scale cybercrime operation across the MENA region, spanning 13 countries and targeting phishing, malware, and cyber fraud infrastructure. Key contributions from Group-IB: 🔹Intelligence on 5,000+ compromised accounts, including government-linked accounts 🔹Identification of active phishing infrastructure across MENA 🔹 Mapping of threat actor clusters involved in phishing distribution and leaked data trafficking This operation reflects what public-private collaboration can achieve when intelligence is regionally grounded and globally coordinated. Our Digital Crime Resistance Centers in Egypt and the UAE were central to delivering that visibility. We remain committed to supporting international efforts to dismantle cybercriminal ecosystems and protect individuals and organisations across the MENA region and beyond. Read More. #ThreatIntelligence #INTERPOL #DCRC #Phishing
904
15
🚨The new Group-IB research uncovers a sophisticated fraud operation targeting SNCF customers through phishing emails, fake S
🚨The new Group-IB research uncovers a sophisticated fraud operation targeting SNCF customers through phishing emails, fake SNCF-themed websites, legitimate payment processors, and social engineering phone calls impersonating bank advisors. Key findings from the investigation: 🔹Fraud infrastructure was timed around French school holidays to exploit periods of increased travel activity 🔹Victims were redirected through legitimate Stripe-hosted payment pages to reduce suspicion during checkout 🔹Targeted users were linked to previously exposed data from the Addka72424 breach, indicating the use of leaked datasets for precision targeting 🔹Threat actors leveraged emotional manipulation and real-time phone calls to extract OTPs, IBAN details, and authorize secondary payments 🔹Infrastructure overlaps and recurring domain patterns suggest a centralized and scalable fraud ecosystem Read the full analysis #Cybersecurity #Phishing #FraudPrevention
968
16
🎉 Group-IB unveils Prevyn AI, the cognitive core of its Unified Risk Platform designed to shift cybersecurity from reactive
🎉 Group-IB unveils Prevyn AI, the cognitive core of its Unified Risk Platform designed to shift cybersecurity from reactive detection to predictive defense. Powered by decades of cybercrime intelligence and real-world investigative logic, Prevyn AI enables organizations to anticipate threats, accelerate response, and outpace machine-speed attacks. Think Faster Than The Threat. Learn More #PrevynAI
890
17
🚨Our latest investigation uncovers how threat actors are combining deepfake impersonation, social engineering, and cryptocur
🚨Our latest investigation uncovers how threat actors are combining deepfake impersonation, social engineering, and cryptocurrency infrastructure to operate at industrial scale across Australia and the United States. Key highlights: 🔹 A network of 208+ connected fake investment platforms with an estimated $187M in illicit revenue. 🔹 Threat actors impersonate well-known financial professionals using deepfake technology & geo-targeted social media advertisements to funnel victims into WhatsApp-based coordination groups. 🔹 20+ fake WhatsApp accounts impersonating a single Australian economist were identified, indicating centralized control by an organized group. 🔹 Coordinated inflows of $1.5M to $3M, achievable with 500 to 3,000 victims, can drive up to 12.4% price movement in a NASDAQ-listed small-cap stock. 🔹 Use of KYC-compliant exchanges for cash-out, with minimal obfuscation, creating both risk and investigative opportunity. 🔗 Read the full analysis. #CyberSecurity #FraudPrevention #InvestmentScams
1 042
18
🚨 Group-IB’s latest research exposes the Phoenix System, a Phishing-as-a-Service platform powering reward point scams, fake
🚨 Group-IB’s latest research exposes the Phoenix System, a Phishing-as-a-Service platform powering reward point scams, fake parcel delivery lures, and large-scale mobile phishing campaigns worldwide. Key highlights: 🔹 SMS delivery via fake BTS to bypass carrier-level filtering and spoof trusted brands. 🔹 2,500+ phishing domains linked to the operation since January 2025. 🔹 More than 70 organizations targeted across finance, telecom, and logistics globally. 🔹 The phishing sites implement IP-based filtering and geofencing to precisely target victims within specific countries. 🔹 Shared infrastructure is found across reward scam and parcel delivery campaigns despite differences in their attack contexts and target audiences. 🔹 Both campaigns use the Phoenix System, successor to the Mouse System. 🔹 The phishing kits are distributed via a dedicated Telegram ecosystem. Read the full analysis here. #Phishing #CyberSecurity #Smishing #ThreatIntelligence
1 110