Group-IB
2.21K subscribers
744 photos
26 videos
2 files
530 links
Your daily source of cybersecurity news brought to you by Group-IB, one of the global industry leaders.
Download Telegram
GISEC Global 2023 was 🔥

Group-IB was excited to be part of the Middle East’s largest and most impactful cybersecurity event, which brought together the leading cybersecurity brands and experts!

With cyber threats evolving, it's vital to share knowledge, develop best practices, boost cyber resilience and contribute to the global fight against cybercrime. The Group-IB team was happy to share our fresh insights and show how our products can help you stay ahead of cybercriminals.

#GISECGlobal #FightAgainstCybercrime
🔥24👍2🏆1
We are happy to announce that Group-IB has been awarded a Cybersecurity Service Provider License. The license issued by the Cybersecurity Services Regulation Office of Singapore (CSRO) enables Group-IB to provide Penetration Testing and Managed Security Operations Centre (SOC) Monitoring Services.

To obtain a license, Group-IB went through a rigorous 6-month evaluation process that involved demonstrating its high level of experience and technological capabilities in providing pentesting and managed Security Operations Centre monitoring services. The licensing process also evaluated the company services’ compliance with Singapore’s Cybersecurity Act which limits the provision of such services to licensed entities.

Check out our website for more details👈

#FightAgainstCybercrime
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥9👍31🏆1
👨‍💻The job hunt can be an extremely trying experience at the best of times, and a fake job scam campaign doesn't make it easier.

Fake job vacancies are one type of scam that is growing in visibility in the Middle East and Africa region. Group-IB’s Digital Risk Protection uncovered more than 2,400 scam pages on Facebook advertising fake jobs for Arabic speakers. On these pages, scammers spoofed more than 40 of the MEA region’s largest enterprises and published vacancies offering salaries that are too good to be true; a social engineering ploy that aims to get the victims to interact with the post. The eventual goal of the threat actors is the theft of the user’s social network account credentials.

Check out our fresh blog post to get more details on this scam scheme as well as recommendations for users and companies. Read👈

#scam
👍73🔥2
👏We continue to share the great news! Group-IB has joined the Asia Pacific Computer Emergency Response Team (APCERT), the largest consortium of Computer Emergency Response Teams in the Asia-Pacific region.

Group-IB’s Computer Emergency Response Team (CERT-GIB) became the first Corporate Partner and only the second organization from Singapore, after SingCERT, to be accepted into the APCERT community. That's huge! By joining APCERT, Group-IB will be better equipped to identify and respond to cybersecurity threats and mitigate their impact on its customers and business operations.

Check out our website for more details👈

#FightAgainstCybercrime #partnership
Please open Telegram to view this post
VIEW IN TELEGRAM
5👍5🔥3
🏆 Group-IB is proud to announce that its Fraud Protection platform has been recognized as the most complete anti-fraud solution on the market by Frost & Sullivan!

Out of nine vendors and products surveyed by Frost & Sullivan in its Global Fraud Detection & Prevention (FDP) Market Study, Group-IB’s Fraud Protection differentiated itself from other offerings by being the only anti-fraud solution to contain all seven key functionalities listed by Frost & Sullivan, including bot detection, behavioral biometrics, explainable AI, and API security.

Learn more about the solution👈

#FraudProtection
🔥196👍2🏆1
🌐 If your Instagram account isn't secured with two-factor authentication, you'd better activate it now.

Group-IB uncovered a new scam campaign targeting both Instagram and banking users in Indonesia, which aims to gain access to their bank accounts. Our team identified more than 600 hijacked Instagram accounts used to spread phishing links to fake websites disguised as login pages of mobile banking applications for one of Indonesia’s leading financial institutions.

Want to learn how the scheme works and how to avoid falling victim to it? Visit our website to read the full story👈

#DigitalRiskProtection #scam #phishing
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥114
🔍 In January 2023, Group-IB’s Digital Forensics and Incident Response team investigated an attack against an industrial sector company in Europe. Our experts established that the victim had been encrypted with a previously unknown ransomware strain. The strain was codenamed BabLock, because its versions for Linux and ESXi share similarities with the leaked Babuk ransomware. Despite these slight similarities, the group has a very distinct modus operandi and custom sophisticated ransomware for Windows. Additionally, the BabLock gang (also tracked under the name “Rorschach”), unlike most of its “industry peers”, is not using a dedicated leak site and is communicating with its victims via email. Group-IB researchers immediately notified the company’s customers of its discovery.

Check out our new blog post to get a comprehensive description of the BabLock attack: their toolset, the strain’s samples for Windows, ESXi, and Linux as well as TTPs used by the BabLock gang mapped to MITRE ATT&CK®. Read👈

#ransomware #BabLock
9🔥4👍3
Group-IB’s Threat Intelligence team identified new infrastructure used by APT MuddyWater. We also uncovered that this group uses SimpleHelp, a legitimate remote device control and management tool, to ensure persistence on victim devices.

According to our data, MuddyWater used SimpleHelp for the first time on June 30, 2022. At the time of writing, the group has at least eight servers on which they have SimpleHelp installed.

Our new blog post describes MuddyWater’s previously unknown infrastructure and points to links with some of the group’s publicly known IP addresses. Read now👈

#APT #MuddyWater
🔥10👍4👏2
Group-IB will no longer be present in the Russian market. This comes after Dmitry Volkov, co-founder and CEO, sold his stake in Group-IB’s Russia-based business to the company’s local management. Group-IB’s branding and trademarks will not be permitted in Russia.

This process marks the completion of the second stage of the regional business diversification announced by Group-IB in July 2022, and encompasses changes to the ownership structure, separation of Group-IB’s business and technical units, and the final withdrawal of the Group-IB brand from the Russian market.

More details👈
Please open Telegram to view this post
VIEW IN TELEGRAM
😢13🔥6👏3👍2
🎣 Phishing attacks are becoming ever more sophisticated and their scale is increasing exponentially.

There are a few approaches to investigate a phishing campaign efficiently. In our new blog post, we present a practical guide based on the investigation into a Chinese-speaking phishing campaign that was observed in July 2022. The campaign was carried out by a phishing gang named PostalFurious by Group-IB. PostalFurious targeted users in APAC, specifically in Singapore, Australia, and some other countries by impersonating postal and, to a lesser extent, toll operators.

Read more👈

#phishing #PostalFurious
🔥8👍3