5 Aug 2026, 08:33 UTC251 views13 reactionsread 7 August 2026 Photo
🚨The most expensive fraud sits at the one stage nobody in the bank owns. Cyber sees the fake domain. Fraud sees the money leaving.
The moment a customer is compromised falls into the gap between teams, where no telemetry tells the full story.
Group-IB CEO Dmitry Volkov calls this positional, not technological: no transaction-layer tool removes it, only an observer placed earlier on the chain.
Article one in his ne…
👍6🔥3❤2👏2
4 Aug 2026, 08:35 UTC329 views11 reactionsread 7 August 2026 Photo
🎉 Group-IB's Threat Intelligence solution is now available in AWS Marketplace.
Designed to provide adversary-centric intelligence, Group-IB's Threat Intelligence helps organizations identify and assess cyber threats at their earliest stages: from compromised credentials and dark web activity to emerging cybercrime groups, APT campaigns, fraud schemes, and large-scale attack indicators.
Powered by Group-IB's global …
🔥9👍2
30 Jul 2026, 07:46 UTC507 views9 reactionsread 7 August 2026 Photo
🚨Cryptomining campaigns continue to evolve beyond simple resource theft.
In our latest research, Group-IB analysts uncovered a covert Linux-based XMRig operation that leveraged trusted third-party access to infiltrate victim environments before deploying a heavily modified cryptomining implant engineered for stealth, persistence, and defence evasion.
Key Highlights:
🔹 Abuse of Linux PAM (pam_rootok) to impersonate …
🔥6❤2👍1
30 Jul 2026, 05:30 UTC454 views12 reactionsread 7 August 2026 Photo
🚨 Fraud teams at banks and payment providers are under more pressure than ever. ATO, APP fraud, scams, and mule activity are accelerating, and regulators are watching.
KuppingerCole has published its Buyer’s Compass for Fraud Reduction Intelligence Platforms (FRIP) – Finance 2026, an independent framework for evaluating FRIP solutions, mapping capabilities to use cases, and providing structured RFP guidance.
Group-…
🔥6👍5❤1
23 Jul 2026, 09:04 UTC650 views10 reactionsread 7 August 2026 Photo
🚨A single OPSEC mistake exposed an entire China-nexus operation.
An exposed Alibaba Cloud staging server provided a rare view into an active threat operation. The infrastructure revealed attacker tooling, bash history, victim paths, and post-exploitation activity, leading to the discovery of a previously undocumented threat cluster we track as JadeProx.
Key Highlights:
🔹Discovery of TriBack Loader, a previously und…
🔥8👍2
20 Jul 2026, 07:54 UTC668 views10 reactionsread 7 August 2026 Photo
🚨 Group-IB Threat Intelligence researchers have uncovered HOLLOWGRAPH, a Windows malware linked with high confidence to the Cavern framework that abuses Microsoft Graph API and compromised Microsoft 365 accounts to establish a covert command-and-control channel.
Key findings from our research:
🔹 Microsoft 365 calendars repurposed as two-way dead drops for command execution and data exfiltration
🔹 Commands and stolen…
🔥8❤2
16 Jul 2026, 07:19 UTC728 views19 reactionsread 7 August 2026 Photo
🚨Group-IB researchers have uncovered ClickLock Stealer, a previously undocumented macOS malware that combines ClickFix social engineering, credential theft, crypto wallet harvesting, Keychain extraction, and persistent remote access into a single attack chain.
Key findings:
🔹At least 100 victims identified across 33 countries, with more than 50% located in Europe
🔹Targets 8 browsers, 31 crypto wallet extensions, 7 p…
🔥9❤5👍4🏆1
9 Jul 2026, 07:17 UTC863 views9 reactionsread 7 August 2026 Photo
Android malware continues to evolve, and RedHook is a prime example of how legitimate developer features can be repurposed for malicious gain.
Our latest research analyzes the newest version of the RedHook Android RAT, which introduces a sophisticated privilege abuse chain by leveraging ADB Wireless Debugging to obtain shell-level access..
Key Highlights:
🔹 Autonomous abuse of ADB Wireless Debugging to gain shell-l…
🔥9
7 Jul 2026, 08:52 UTC749 views10 reactionsread 7 August 2026 Photo
Scattered Spider has been linked to major cyberattacks in recent years, but our latest research suggests the threat is often misunderstood.
Group-IB's investigation shows Scattered Spider is not a single threat group but a decentralized cybercrime collective of independent subclusters connected by shared TTPs.
Key findings:
🔹 Scattered Spider is better understood as a network of autonomous subclusters rather than a…
🔥7❤3
1 Jul 2026, 10:01 UTC922 views10 reactionsread 7 August 2026 Photo
🚨Smishing campaigns continue to evolve beyond convincing lures. Modern phishing operations are increasingly engineered to evade detection.
In our latest technical analysis, Group-IB researchers dissect a campaign targeting drivers in Serbia through fake traffic fine SMS notifications. The investigation links the operation to two Phishing-as-a-Service ecosystems, Darcula and Phoenix, and reveals a phishing framework …
👏8👍1🔥1
11 Jun 2026, 07:40 UTC≈1,290 views18 reactionsread 7 August 2026 Photo
Group-IB supported INTERPOL and the Algerian National Police in dismantling SniperDz, a phishing-as-a-service (PhaaS) platform that operated for nearly a decade and enabled cybercriminals to launch phishing campaigns at scale.
Key findings:
🔹 20,000+ domains linked to the ecosystem
🔹 30+ global brands impersonated
🔹 80 phishing templates across five languages
🔹 45,000+ victim records reported by the platform in 2016…
❤7🔥7👍2🖕2
10 Jun 2026, 07:46 UTC≈1,040 views13 reactionsread 7 August 2026 Photo
Our latest research examines SilabRAT, a Malware-as-a-Service platform sold on underground forums that combines credential theft, browser profile cloning, HVNC, Chrome App-Bound Encryption bypass techniques, and cryptocurrency-focused capabilities into a single offering.
Key findings:
🔹 SilabRAT has been marketed on underground forums since late 2025 for $5,000/month
🔹 Leverages HVNC for invisible interaction with v…
🔥6👍5🖕2
Showing the 12 most recent of 20 posts we hold for @Group_IB. View and reaction counts are the latest single reading for each post, not a live figure, and a recent post is still accumulating both. A view count marked ≈ was rounded by Telegram before we ever saw it — t.me prints views in full below 1,000 and to three significant figures above, so ≈1,200,000 means somewhere between 1,150,000 and 1,249,999. Unmarked counts are exact. Text is reproduced from the public post preview and truncated for length.