Group-IB
2.52K subscribers
796 photos
28 videos
2 files
584 links
Your daily source of cybersecurity news brought to you by Group-IB, one of the global industry leaders.
Download Telegram
🚨Cryptomining campaigns continue to evolve beyond simple resource theft.

In our latest research, Group-IB analysts uncovered a covert Linux-based XMRig operation that leveraged trusted third-party access to infiltrate victim environments before deploying a heavily modified cryptomining implant engineered for stealth, persistence, and defence evasion.

Key Highlights:
πŸ”Ή Abuse of Linux PAM (pam_rootok) to impersonate multiple low-privileged users and create a forensic smokescreen.
πŸ”Ή Active log suppression and the use of a /tmp/.lock mutex to ensure single-instance execution without crashing the host.
πŸ”Ή A self-unlinking XMRig implant that deletes itself from disk and continues running entirely from memory.
πŸ”Ή Process masquerading, hidden artifacts (T1564.013), and network User-Agent spoofing as Java/Agent to blend Stratum traffic with legitimate web flows.
πŸ”Ή Campaign tracking identifiers (My-V25-GEN-26) linking infections to the V25-GEN-26 operation.

Read the full technical analysis.

#DFIR #XMRig
πŸ”₯6❀2πŸ‘1
πŸŽ‰ Group-IB's Threat Intelligence solution is now available in AWS Marketplace.

Designed to provide adversary-centric intelligence, Group-IB's Threat Intelligence helps organizations identify and assess cyber threats at their earliest stages: from compromised credentials and dark web activity to emerging cybercrime groups, APT campaigns, fraud schemes, and large-scale attack indicators.

Powered by Group-IB's global Digital Crime Resistance Centers, adversary-centric research, and one of the industry's largest cybersecurity data lakes, the solution delivers verified, actionable intelligence. Proven through contributions to more than 1,600 global law enforcement investigations worldwide, it helps security teams shift from reactive response to proactive defense.

Now available on AWS Marketplace, customers can simplify procurement, consolidate billing, and gain faster access to threat intelligence.

Get started with Group-IB Threat Intelligence on AWS Marketplace today.

#GroupIB #ThreatIntelligence #AWS
πŸ”₯10πŸ‘2
🚨The most expensive fraud sits at the one stage nobody in the bank owns. Cyber sees the fake domain. Fraud sees the money leaving.

The moment a customer is compromised falls into the gap between teams, where no telemetry tells the full story.

Group-IB CEO Dmitry Volkov calls this positional, not technological: no transaction-layer tool removes it, only an observer placed earlier on the chain.

Article one in his new series, One Adversary, opens with an exercise: map your last serious fraud case stage by stage, and name the team that could have caught each one. The stage with no name beside it is where your losses live.

Read it here.

#CyberFraudFusion #FraudPrevention #CyberSecurity
πŸ‘6πŸ”₯4❀3πŸ‘3
🚨Right person. Right device. Right password. Wrong everything else.

Kyrgyz Investment and Credit Bank (KICB) set out to protect its 500,000+ customers from the attacks that traditional security struggles to stop: social engineering, account takeover, and unauthorized remote access. Fraud that looks legitimate because the customer is the one being manipulated.

Together with its implementation partner, Noventiq Kyrgyzstan, KICB deployed Group-IB Fraud Protection to detect these attacks in real time and give investigators the context they need to act quickly.

"The most significant result we have seen so far is in combating social engineering attacks. Fraud Protection helps us identify events that were previously difficult to detect through manual review and provides significantly more context for investigating suspicious activity." β€” Aida Isakova, Head of Anti-Fraud, KICB

Read the full story.

#CyberSecurity #SocialEngineering #FinancialSecurity
πŸ‘6πŸ”₯4
☎️ A live phone call. A remote access trojan. An NFC relay malware.

Group-IB researchers uncovered WindRelay, a previously unseen Android NFC relay malware deployed alongside SpyNote RAT in a live-call fraud scheme.

The investigation reveals how threat actors are combining:
πŸ”Ή Social engineering calls with personalized RAT delivery
πŸ”Ή Remote sideloading of NFC relay malware
πŸ”Ή Real-time interception and relay of EMV card transactions
πŸ”Ή 23 related samples and four C2 IPs linked to WindRelay activity

The findings also highlight why defenders should look beyond screen-sharing detection and monitor Accessibility Service abuse, sideloaded apps, suspicious permissions, and NFC activity.

πŸ‘‰ Read the full technical analysis.

#AndroidMalware #SpyNoteRAT #WindRelay #FraudPrevention
πŸ”₯5πŸ‘4
πŸ•°οΈ Every fraud operating model contains an assumption nobody wrote down: the money will wait while the case file travels.

Confirm the case. Assemble the file. Cross the team boundary: email, ticket, weekly sync. Each step is reasonable. The sum assumes the money waits.

It does not. RUSI research on UK banking data: 28% of stolen funds gone within fifteen minutes of the fraudulent transfer. Over 85% within a day.

Dmitry Volkov's second article, One Adversary: The Fifteen-Minute Problem, argues this number ends the case file era, and shows where the time is won back: not by hurrying investigators, but in the weeks of preparation every fifteen minute execution is bought with.

He gives that interval a name, Defensive Lead Time, and a metric to manage it by.

Learn more about it in the most useful six minutes read you’ll indulge in this week.

#FraudPrevention #FinancialCrime #CyberSecurity
πŸ”₯5❀2πŸ‘2
🚨Balonx Sistema shows how Phishing-as-a-Service (PhaaS) is evolving into a multi-vector financial fraud operation targeting Mexican banking customers.

In our latest technical investigation, Group-IB uncovers how the operation combines:
πŸ”Ή Weekly PhaaS subscriptions targeting 20+ financial institutions (3,000–6,000 MXN/week)
πŸ”Ή 1,100+ harvested credentials and financial records since October 2025
πŸ”Ή WebSocket-based real-time session hijacking with 14 screen types for MFA interception
πŸ”Ή Spyroid-based Android RAT (BankProtect) for persistent device control
πŸ”Ή AI-powered vishing using GPT-4o-mini, ElevenLabs, and OpenAI Whisper
πŸ”Ή 350+ domains linked to the Balonx and Aclaraciones Bancarias campaigns

The investigation reveals how phishing, malware, and AI-driven social engineering are being integrated into a single criminal ecosystem with active domain rotation and centralized PostgreSQL infrastructure.

Read the full technical analysis.

#Phishing #FinancialFraud #CyberSecurity #MalwareThreats
πŸ”₯7πŸ‘2πŸ‘1
The hardest fraud to stop is the one the customer approves. By the time the money moves, there is nothing left to refuse.

Investment scams and fake platforms cost billions annually. If you try to fight these operations at the transaction layer, you lose, because the payment is the criminals' most defensible point.

But Group-IB’s latest analysis reveals their fatal flaw: fraud at this scale cannot afford to be artisanal. What makes these operations industrial also makes them profoundly networked through shared hosting, reused templates, and connected mule accounts.

Article three, in Dmitry Volkov's One Adversary series, shifts the focus from the payment to the network. It challenges you to ask the exact question every CRO should be putting on the agenda: how do we see what peer institutions have flagged without customer data ever leaving the bank?

Read it here.

#CyberFraudFusion #FraudPrevention #CyberSecurity
πŸ‘8πŸ”₯5πŸ‘2❀1
🚨Tortoiseshell is evolving its infrastructure and expanding its operational footprint across Europe and the Middle East.

In our latest technical analysis, Group-IB Threat Intelligence uncovered new infrastructure and malware associated with the Iranian-nexus APT, including a reverse SSH tunneling tool disguised as wtsapi32.dll and TWOSTROKE C++ backdoor capable of command execution, file exfiltration, in-memory DLL execution, and host reconnaissance.

Our research also identified additional C2 infrastructure and geographically named subdomains that may indicate a broader targeting profile.

Read the full technical analysis to explore Tortoiseshell's evolving toolset, infrastructure, C2 architecture, and defensive recommendations.

#ThreatIntelligence #APT #CyberSecurity #Tortoiseshell
πŸ‘6πŸ”₯3❀1
🚨 By the time a bank detects fraud, legacy systems are simply watching the end of a story they missed.

When an industrial malware campaign hit 11,000 devices, unfused banks drowned in isolated alerts while losses compounded.

But institutions with cyber-fraud fused defense held fraud success to just 0.027%, a 9x reduction compared to the market.

Global regulators are taking note, rapidly shifting mandates to require cyber and fraud to operate as a single architecture.

Article three in Dmitry Volkov's One Adversary series turns strategy debates into hard proof. It delivers the exact two questions your Risk Committee needs to answer before the next campaign hits. Read it here.

#FinancialSecurity #RiskManagement #CyberSecurity #Compliance
πŸ”₯8πŸ‘Œ4❀1
🚨 Cybercrime is evolving, and so is the underground economy behind it.

Group-IB has uncovered BraZetsu, a sophisticated malware framework attributed to Brazilian threat actor Exilware, revealing how cybercriminals are using AI-enhanced reconnaissance to identify high-value targets across banking, ERP, government, and industrial environments.

BraZetsu powers the Infected Marketplace, where initial access to compromised systems is sold as a tradable commodity, allowing buyers to deploy their own malicious payloads without ever establishing the initial foothold themselves.

Read the full technical analysis.

#Cybersecurity #ThreatIntelligence #BraZetsu #AI
πŸ”₯6πŸ‘4❀1πŸ‘1
🚨 Outsider Phishing Kit: a resilient PhaaS threat

Group-IB researchers uncovered the Outsider Phishing Kit, operated by threat actor ChenLun, which has enabled large-scale smishing campaigns targeting 54+ countries.

From December 2025 to May 2026, researchers identified 100,000+ phishing pages and 267+ ready-made templates targeting financial services, telecom, government, logistics and other sectors.

The kit includes AiTM capabilities, real-time credential and payment card interception, MFA manipulation, WebSocket-based C2 communication and anti-analysis techniques.

Even after law enforcement action, Group-IB identified 700+ new phishing pages and domains, highlighting the resilience of the ecosystem.

Read the full technical analysis.

#CyberSecurity #Phishing #Smishing #PhaaS
πŸ”₯8πŸ‘2❀1πŸ‘1🍌1
🚨 Group-IB uncovers Vwork, a weaponized fork of the open-source Android app cloner Shelter, used alongside the Gigabud banking trojan.

Vwork abuses Android Work Profiles to clone banking apps into an isolated environment, helping attackers evade detection and bypass fraud controls.

Vwork-compatible Gigabud samples were identified across LATAM, MENA, and APAC, targeting Brazil, Colombia, Egypt, Indonesia, Laos, Mexico, Morocco, the Philippines, Thailand, TΓΌrkiye, and a GCC member state.

In Indonesia, Group-IB observed 1,469 compromised devices and 1,281 potentially compromised logins between February and July 2026, with estimated losses of $960,939.

Read the full technical analysis.

#ThreatIntelligence #AndroidMalware #Vwork #Gigabud
πŸ”₯6❀5🍌2πŸ‘1πŸ‘1😁1
🚨 Inside the Smishing Triad’s Phishing Cockpit

Group-IB’s latest research dives into JWR, a phishing kit used by the Outsider cluster, revealing how attackers turn phishing pages into real-time fraud operations.

Key findings:
πŸ”Ή32 operator commands for real-time victim manipulation
πŸ”ΉKeystroke-level credential and payment-data capture
πŸ”Ή~70 data fields for PII, cards, OTPs, credentials and device data
πŸ”ΉWebSocket C2 with AES-256-CTR encrypted communications
πŸ”ΉDistinctive fingerprints, IOCs, YARA and Suricata detection rules

Read the full technical analysis.

#Phishing #Smishing #CyberCrime
πŸ”₯10πŸ‘3😍3
🚨Group-IB Threat Intelligence has uncovered 29 new samples linked to the HEAVYGRAM and CRUDEEXCLUDE malware families, expanding our understanding of activity attributed with moderate confidence to Handala Hack.

The investigation reveals a multi-stage Windows infection chain combining social engineering, legitimate application masquerading, PowerShell execution, Defender exclusions and persistent access.

At the centre of the operation is HEAVYGRAM, a Python-based Windows backdoor that uses Telegram’s Bot API for C2 and data exfiltration. Operators can remotely execute commands, capture screenshots, collect system and process information, steal Telegram session data and deploy additional payloads.

The research also shows how CRUDEEXCLUDE is used to prepare compromised systems by adding paths to Microsoft Defender exclusions before deploying subsequent stages.

Read the full technical analysis.

#ThreatIntelligence #HandalaHack #HEAVYGRAM
πŸ”₯8πŸ‘2❀1
🚨Group-IB researchers have uncovered RemControl, a previously undocumented Android banking trojan operating as Malware-as-a-Service (MaaS). First observed in July 2026, RemControl abuses Android’s Accessibility Service to inject phishing overlays over legitimate banking applications, capture sensitive credentials, stream the victim’s screen, log interactions, and remotely control the device.

The threat goes beyond credential theft. Its infrastructure includes an exposed operator panel for managing bots, overlay templates, stolen credentials, remote sessions, and affiliate-specific APK builds. The malware also uses a local VPN to interfere with Google Play Protect during installation and retrieves its command-and-control address through an encrypted Telegram dead-drop mechanism.

Researchers also identified evidence of AI-assisted development, including an AI-generated response accidentally left inside a live phishing page.

Read the full blog.

#CyberSecurity #AndroidMalware #BankingTrojan
πŸ”₯7❀4❀‍πŸ”₯1πŸ‘1