Group-IB, a leading creator of predictive cybersecurity technologies to investigate, prevent, and fight digital crime, today signed a memorandum of understanding (MoU) with the Ministry of Digital ...
Group-IB, a leading creator of predictive cybersecurity technologies to investigate, prevent, and fight digital crime, today announced the launch of Masked Actors: BelArabi, the first Arabic-language ...
In the first episode of Masked Actors: BelArabi_بالعربي, Mohammad Gamal and Mansour Alhmoud examine what drives modern cyber threats and unpack MuddyWater’s latest activity across the Middle East, ...
Group-IB researchers have discovered a previously undocumented Android banking trojan, internally named RemControl by its operator, targeting retail banking customers across Western Europe, the Middle ...
Group-IB Threat Intelligence analyzes HEAVYGRAM, a Telegram-based Windows backdoor attributed with moderate confidence to the Iran-linked threat actor Handala Hack. Active since Fall 2023, it has been ...
A widespread smishing campaign was identified in which victims received fraudulent SMS messages impersonating official entities and were instructed to click a link inside the SMS in order to “complete ...
Every security team believes it’s ready for ransomware, until an attack proves otherwise. That gap between belief and reality doesn’t show up in a plan sitting in a drawer; it shows up in the data.
This blog provides a deep-dive into the phishing kit created by Chenlun known as the Outsider Phishing Kit. It is a well established kit in the Chinese community with over 267 ready-made phishing ...
Group-IB exposes a Mexican PhaaS operation targeting over 20 financial institutions with live phishing, AI vishing, and mobile RAT capabilities. Mexico’s banking infrastructure has emerged as a ...
A new NFC relay malware designated as WindRelay, paired with SpyNote RAT enables live-call fraud, combining social engineering with dual digital and physical cash-out. Group-IB have tracked this ...
Dive into a covert Linux XMRig campaign exploiting trusted access, weaponizing PAM to create forensic smokescreens, and deploying self-unlinking payloads. In May 2026, a highly covert Monero (XMR) ...
The ransomware economy has been rewired. Meet the eight ransomware groups driving the shift, from affiliate breakaways to AI-assisted attacks based on Group-IB Threat Intelligence. The ransomware ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results