Group-IB
2.55K subscribers
799 photos
28 videos
2 files
587 links
Your daily source of cybersecurity news brought to you by Group-IB, one of the global industry leaders.
Download Telegram
🚨Tortoiseshell is evolving its infrastructure and expanding its operational footprint across Europe and the Middle East.

In our latest technical analysis, Group-IB Threat Intelligence uncovered new infrastructure and malware associated with the Iranian-nexus APT, including a reverse SSH tunneling tool disguised as wtsapi32.dll and TWOSTROKE C++ backdoor capable of command execution, file exfiltration, in-memory DLL execution, and host reconnaissance.

Our research also identified additional C2 infrastructure and geographically named subdomains that may indicate a broader targeting profile.

Read the full technical analysis to explore Tortoiseshell's evolving toolset, infrastructure, C2 architecture, and defensive recommendations.

#ThreatIntelligence #APT #CyberSecurity #Tortoiseshell
πŸ‘6πŸ”₯3❀1
🚨 By the time a bank detects fraud, legacy systems are simply watching the end of a story they missed.

When an industrial malware campaign hit 11,000 devices, unfused banks drowned in isolated alerts while losses compounded.

But institutions with cyber-fraud fused defense held fraud success to just 0.027%, a 9x reduction compared to the market.

Global regulators are taking note, rapidly shifting mandates to require cyber and fraud to operate as a single architecture.

Article three in Dmitry Volkov's One Adversary series turns strategy debates into hard proof. It delivers the exact two questions your Risk Committee needs to answer before the next campaign hits. Read it here.

#FinancialSecurity #RiskManagement #CyberSecurity #Compliance
πŸ”₯8πŸ‘Œ4❀1
🚨 Cybercrime is evolving, and so is the underground economy behind it.

Group-IB has uncovered BraZetsu, a sophisticated malware framework attributed to Brazilian threat actor Exilware, revealing how cybercriminals are using AI-enhanced reconnaissance to identify high-value targets across banking, ERP, government, and industrial environments.

BraZetsu powers the Infected Marketplace, where initial access to compromised systems is sold as a tradable commodity, allowing buyers to deploy their own malicious payloads without ever establishing the initial foothold themselves.

Read the full technical analysis.

#Cybersecurity #ThreatIntelligence #BraZetsu #AI
πŸ”₯6πŸ‘4❀1πŸ‘1
🚨 Outsider Phishing Kit: a resilient PhaaS threat

Group-IB researchers uncovered the Outsider Phishing Kit, operated by threat actor ChenLun, which has enabled large-scale smishing campaigns targeting 54+ countries.

From December 2025 to May 2026, researchers identified 100,000+ phishing pages and 267+ ready-made templates targeting financial services, telecom, government, logistics and other sectors.

The kit includes AiTM capabilities, real-time credential and payment card interception, MFA manipulation, WebSocket-based C2 communication and anti-analysis techniques.

Even after law enforcement action, Group-IB identified 700+ new phishing pages and domains, highlighting the resilience of the ecosystem.

Read the full technical analysis.

#CyberSecurity #Phishing #Smishing #PhaaS
πŸ”₯8❀2πŸ‘2πŸ‘1🍌1
🚨 Group-IB uncovers Vwork, a weaponized fork of the open-source Android app cloner Shelter, used alongside the Gigabud banking trojan.

Vwork abuses Android Work Profiles to clone banking apps into an isolated environment, helping attackers evade detection and bypass fraud controls.

Vwork-compatible Gigabud samples were identified across LATAM, MENA, and APAC, targeting Brazil, Colombia, Egypt, Indonesia, Laos, Mexico, Morocco, the Philippines, Thailand, TΓΌrkiye, and a GCC member state.

In Indonesia, Group-IB observed 1,469 compromised devices and 1,281 potentially compromised logins between February and July 2026, with estimated losses of $960,939.

Read the full technical analysis.

#ThreatIntelligence #AndroidMalware #Vwork #Gigabud
❀6πŸ”₯6🍌2πŸ‘1πŸ‘1😁1
🚨 Inside the Smishing Triad’s Phishing Cockpit

Group-IB’s latest research dives into JWR, a phishing kit used by the Outsider cluster, revealing how attackers turn phishing pages into real-time fraud operations.

Key findings:
πŸ”Ή32 operator commands for real-time victim manipulation
πŸ”ΉKeystroke-level credential and payment-data capture
πŸ”Ή~70 data fields for PII, cards, OTPs, credentials and device data
πŸ”ΉWebSocket C2 with AES-256-CTR encrypted communications
πŸ”ΉDistinctive fingerprints, IOCs, YARA and Suricata detection rules

Read the full technical analysis.

#Phishing #Smishing #CyberCrime
πŸ”₯10πŸ‘3😍3❀1
🚨Group-IB Threat Intelligence has uncovered 29 new samples linked to the HEAVYGRAM and CRUDEEXCLUDE malware families, expanding our understanding of activity attributed with moderate confidence to Handala Hack.

The investigation reveals a multi-stage Windows infection chain combining social engineering, legitimate application masquerading, PowerShell execution, Defender exclusions and persistent access.

At the centre of the operation is HEAVYGRAM, a Python-based Windows backdoor that uses Telegram’s Bot API for C2 and data exfiltration. Operators can remotely execute commands, capture screenshots, collect system and process information, steal Telegram session data and deploy additional payloads.

The research also shows how CRUDEEXCLUDE is used to prepare compromised systems by adding paths to Microsoft Defender exclusions before deploying subsequent stages.

Read the full technical analysis.

#ThreatIntelligence #HandalaHack #HEAVYGRAM
πŸ”₯8❀2πŸ‘2
🚨Group-IB researchers have uncovered RemControl, a previously undocumented Android banking trojan operating as Malware-as-a-Service (MaaS). First observed in July 2026, RemControl abuses Android’s Accessibility Service to inject phishing overlays over legitimate banking applications, capture sensitive credentials, stream the victim’s screen, log interactions, and remotely control the device.

The threat goes beyond credential theft. Its infrastructure includes an exposed operator panel for managing bots, overlay templates, stolen credentials, remote sessions, and affiliate-specific APK builds. The malware also uses a local VPN to interfere with Google Play Protect during installation and retrieves its command-and-control address through an encrypted Telegram dead-drop mechanism.

Researchers also identified evidence of AI-assisted development, including an AI-generated response accidentally left inside a live phishing page.

Read the full blog.

#CyberSecurity #AndroidMalware #BankingTrojan
πŸ”₯8❀6πŸ‘2❀‍πŸ”₯1
🏦 There's a stage in every major fraud that belongs to no one in your bank.

Not the cyber team. Not the fraud team. Not AML. And the criminals know exactly where it is.

We're constantly reinforcing this because the gap is still open, unowned, and being worked while the industry nods along. Fraud and cybercrime aren't two problems. They're one operation.

This is the convergence our CEO Dmitry Volkov has been strongly making the case for, and we've brought it together in one whitepaper: One Adversary, One Workflow.

So that's what the paper does. Make the defence the same shape as the attack: one picture of the adversary, one chain defended end to end, one loop where every blocked session sharpens the next detection. On a live malware campaign, institutions running that fused model held fraud success to 0.027% of infected devices, roughly 9Γ— below the market.

Download report.

#FraudPrevention #FinancialSecurity
πŸ”₯6πŸ‘3❀1
πŸ›οΈThat β€œtoo good to be true” deal could be the lure.

Milk Dragon, also known as NaiLong, has targeted over 6,159 victims across 66 countries since October 2025. With 258 identified phishing pages, the operation impersonates major brands like LEGO, Calvin Klein, and Aeon Malaysia.

Instead of suspicious emails or urgent messages, this phishing operation uses heavily discounted products promoted through Facebook & TikTok marketplaces to lead victims to fake WordPress and WooCommerce e-commerce sites.

Behind the scenes, its custom BytePress plugin can capture payment data in real time, intercept OTPs through Adversary-in-the-Middle techniques, and give operators centralized control over multiple phishing campaigns via a WebSocket connection.

Sold as Phishing-as-a-Service through Telegram starting at 300 USDT per month, Milk Dragon shows how cybercriminals are turning trusted social platforms & familiar shopping experiences into attack infrastructure.

Read more.

#Phishing #CyberSecurity #ThreatIntelligence
❀4πŸ‘4πŸ”₯4
🚨Operation KillSwitch, led by German authorities, with support from Europol and Eurojust, has taken action against KillSec, a ransomware-as-a-service group linked to around 1,000 suspected attacks worldwide.

Key Highlights:
πŸ”Ή 274 organizations were publicly claimed as victims on KillSec’s leak site.
πŸ”Ή Around 35% of identified victims were in North America, 30% in Asia-Pacific, and 14% in Europe
πŸ”Ή Financial services, healthcare, and government were among the most affected sectors
πŸ”Ή The group operated a fully functional affiliate platform with ransom negotiation and payment handling capabilities, payload configuration for Windows and VMware ESXi environments, a Tor-based DLS, and more

Group-IB supported the international Operation KillSwitch with investigative intelligence on KillSec’s operations, infrastructure, and key enablers.

Read the full press release to learn more.

#CyberSecurity #Ransomware #OperationKillSwitch
πŸ”₯8❀4