Group-IB Global

3.8K posts

Group-IB Global banner
Group-IB Global

Group-IB Global

@GroupIB

A leading creator of cybersecurity technologies to investigate, prevent, and fight digital crime. Combating cybercrime since 2003

Singapore Katılım Ağustos 2016
643 Takip Edilen9.8K Takipçiler
Group-IB Global
Group-IB Global@GroupIB·
Fraud isn't a moment. It's a process, built over weeks, inside accounts you think are clean. #Muleaccounts warm up for 4-8 weeks before they're deployed. Synthetic identities build credit histories before they apply for loans. #Deepfake tools rehearse before they hit your KYC. If your monitoring is periodic, you're watching a replay. The crime already happened. A few questions to ask yourself about how your detection actually works. Download Now: link.group-ib.com/4vwESD8 #CyberSecurity #FinancialSecurity #Compliance
Group-IB Global tweet mediaGroup-IB Global tweet mediaGroup-IB Global tweet mediaGroup-IB Global tweet media
English
0
1
1
278
Group-IB Global
Group-IB Global@GroupIB·
🚨Is your #emailsecurity still watching for bad emails? Attackers aren't sending bad emails. They're sending real ones, from your employees' compromised accounts. Infostealers harvest credentials, #darkweb markets resell them, and weeks later someone logs into a legitimate mailbox. Every message passes every check because the account is real, even though the sender is not. Group-IB tracked 466 corporate access listings on dark web forums in Q2 2026. Separately, #infostealers compromised 115,158 hosts in the same period, with Vidar, RedLine, and Acreed doing most of the harvesting. Either one can become an entry point for business email compromise, lateral #phishing, or #ransomware deployment. The good news: there is a window between credential theft and business email compromise. One capability can close it. Read our blog post to learn which one: link.group-ib.com/4fp94LY
Group-IB Global tweet media
English
1
0
2
611
Group-IB Global
Group-IB Global@GroupIB·
#Qilin is exploiting a critical Palo Alto VPN vulnerability. But that’s only the entry point. The #ransomware group has also claimed to operate a “legal department” that files complaints against organizations that refuse to pay. Modern ransomware is no longer just about encryption. It's evolving into a full-fledged business model, combining technical attacks with legal and psychological pressure. Read more: link.group-ib.com/4fR8ir5 #CyberSecurity #ThreatIntelligence
Group-IB Global tweet mediaGroup-IB Global tweet media
English
1
21
60
6.3K
Group-IB Global
Group-IB Global@GroupIB·
Group-IB was honored to participate in the 11th @INTERPOL_HQ Digital Forensics Expert Group (DFEG) Meeting, hosted on July 13–14, 2026, at the National Forensic Sciences University (@NFSU_Official), Gandhinagar, Gujarat, #India. Representing Group-IB, Nam Le delivered a presentation titled Ghost in the Hub to an audience of law enforcement officials, cybercrime investigators, and digital forensics experts from around the world. The session explored a real-world investigation involving a low-end piece of hardware successfully defeating a modern enterprise security architecture. Through the case study, Nam detailed the mechanics of the physical intrusion and demonstrated how forensic artifact correlation and deep packet inspection were used to identify, trace, and understand the threat. We are grateful for the opportunity to contribute to this important forum and to collaborate with the global digital forensics community in addressing emerging cyber threats and advancing investigative capabilities. #INTERPOL #DigitalForensics #CyberSecurity
Group-IB Global tweet mediaGroup-IB Global tweet mediaGroup-IB Global tweet mediaGroup-IB Global tweet media
English
1
0
3
380
Group-IB Global
Group-IB Global@GroupIB·
🇦🇺 🇳🇿 Threat actors are actively shifting tactics across Australia and New Zealand. Are your defenses prioritized correctly? Join us for a live deep dive into our ANZ Quarterly Threat Evolution Report to see exactly who is targeting the region. 👉 Save your spot: link.group-ib.com/4yClcAJ 🗓️ 30 July 2026 🕑 2 PM - 3 PM AEST / GMT+10 Speaker: Claudia Nave, ANZ Cyber Threat Intelligence Analyst We’re skipping global averages and focusing on local telemetry to cover: 🔹 The rapidly shifting mix of infostealers driving account compromises in ANZ. 🔹 Active ransomware groups hitting local orgs (including Qilin, Play, and LockBit). 🔹 Why Australia just jumped to 7th globally for compromised bank cards. Built for CISOs, SOC leads, and risk leaders. Leave with actionable detection and response priorities, so your team can act before the next campaign lands. #CyberSecurity #ThreatIntelligence #GroupIB #ANZ #Ransomware #InfoSec
Group-IB Global tweet media
English
0
1
7
514
Group-IB Global
Group-IB Global@GroupIB·
A single OPSEC mistake exposed an entire China-nexus operation. During routine monitoring, we uncovered an exposed #Alibaba Cloud staging server that provided a rare glimpse into an active threat cluster we track as #JadeProx. The exposed infrastructure revealed attacker bash history, victim paths, proxy and tunneling tools, webshell deployments, and post-exploitation tooling, enabling us to reconstruct the operation from initial access to command and control. Key highlights from the investigation: 🔹 Discovery of #TriBack Loader, a previously undocumented #malware family observed across four infection chains. 🔹 Active targeting of government, healthcare, and education organizations across Vietnam, Malaysia, Hong Kong, Honduras, and Venezuela. 🔹 Abuse of signed Microsoft and G DATA binaries for DLL sideloading and stealthy payload execution. 🔹 Use of alternative callback-based execution techniques including InitOnceExecuteOnce, TimerQueue callbacks, and EtwpCreateEtwThread to evade detection. 🔹 Deployment of AdaptixC2 and the Beagle backdoor through a shared loader architecture. 🔹 Large-scale vulnerability scanning against more than 14,000 Hong Kong-related assets alongside phishing campaigns targeting LATAM entities. 🔹 Consistent use of NameSilo-registered domains and Cloudflare-fronted C2 infrastructure across all campaigns. 🔹 Infrastructure, tooling, and tradecraft overlapping with multiple PRC-linked threat actor ecosystems while remaining distinct enough to warrant separate tracking as JadeProx. This investigation offers a rare end-to-end view of a modern espionage operation, from exposed staging infrastructure and intrusion activity to phishing operations and malware deployment. Read the full technical analysis: link.group-ib.com/44Oh1Ee
Group-IB Global tweet mediaGroup-IB Global tweet mediaGroup-IB Global tweet media
English
1
38
103
8K
Group-IB Global
Group-IB Global@GroupIB·
🚨 Group-IB is a proud partner of the International Cybersecurity Olympiad (ICO) 2026! Held this year in Tunisia with teams from 20 countries, we've partnered with ICO during the second year of this Olympics. Our local manager Synda Hleli presented the gold, silver, and bronze prizes at the closing ceremony. Baha Baghdadi ran a workshop for mentors, professors, and students on CTF vs. red teaming, bringing real-world practice into academic competitions. Associate Professor Sun Teck Tan, President of the International Olympiad in Informatics, shared: "Group-IB came at a particularly important time, providing valuable resources and confidence that enabled us to successfully deliver the competition. We look forward to your continued partnership in future editions." Growing the next generation of cybersecurity talent is part of our mission. #CyberSecurity #CyberTalent #InfoSec #RedTeaming
Group-IB Global tweet mediaGroup-IB Global tweet mediaGroup-IB Global tweet mediaGroup-IB Global tweet media
English
0
2
13
987
Group-IB Global
Group-IB Global@GroupIB·
The threat actor claiming responsibility for the latest breach is the same, 888, #hacker who claimed to have stolen a massive Accenture employee database in 2024. Operating on underground forums, 888 specializes in selling stolen databases and unauthorized access to corporate environments including #AWS S3, Jira, Bitbucket, and MySQL. Group-IB already highlighted it as one of six main threat actors who actively use supply-chain attacks as part of their tactics: group-ib.com/blog/supply-ch…
Group-IB Global tweet media
English
0
1
5
494
Group-IB Global
Group-IB Global@GroupIB·
On July 7, Accenture confirmed awareness of the incident, stating that the source of the issue had been remediated and that there was no impact on operations or service delivery. Investigation into the scope and validity of the advertised dataset remains ongoing.
English
1
1
4
496
Group-IB Global
Group-IB Global@GroupIB·
A threat actor operating as "888" advertised the sale of 35GB of data allegedly stolen from #Accenture, claiming the dataset contains source code, RSA keys, SSH keys, Azure PATs, Azure Storage access keys, and configuration files. Unlike many breach sale listings, the actor published evidence intended to support the claim, including repository screenshots and a file tree of the alleged data. #ThreatIntel
Group-IB Global tweet media
English
2
30
118
12.3K
Group-IB Global
Group-IB Global@GroupIB·
🚨 Collection has never been better. Action has never been further behind. Threat intelligence is quietly becoming the most connected layer in security — not a feed on the side, but the tissue between risk, vulnerabilities, and response. Read the blog to know: link.group-ib.com/4vHFAO7
Group-IB Global tweet media
English
0
5
4
501
Group-IB Global
Group-IB Global@GroupIB·
Your fraud stack checks devices, behavior, and networks. It doesn’t check whether the card is already compromised. New blog: Inside the matching engine, this article explains how distributed tokenization identifies compromised cards before authorization without exposing them. Read More: link.group-ib.com/4fNExGH #FraudPrevention #EcommerceSecurity
Group-IB Global tweet media
English
0
1
3
354
Group-IB Global
Group-IB Global@GroupIB·
⚠️ Nigerian banks: the July 2026 #CBN deadline is only days away. Fraud losses reached ₦52.26 billion in 2024. Actual losses surged 603% in Q1 2025. Meanwhile, the Central Bank of Nigeria has introduced new requirements that fundamentally change how fraud prevention, authentication, onboarding, and cybersecurity controls must operate across digital banking channels. The challenge? Compliance is not simply about adding another control. Banks must align fraud monitoring, authentication, device trust, onboarding, and audit readiness under two interconnected CBN mandates. That's why we created this guide. Inside, you'll discover: 🔹 What the 2024 Risk-Based #Cybersecurity Framework requires in practice 🔹 What the 2026 #InstantPayment Circular changes for digital banking operations 🔹 The most common compliance gaps exposing institutions to fraud and audit risk 🔹 A straightforward roadmap to become audit-ready before enforcement 🔹 How behavioural analytics, device intelligence, biometrics, and real-time fraud monitoring support compliance and fraud resilience How can Group-IB help? Through #FraudProtection and BioConfirm, Group-IB helps Nigerian #financialinstitutions strengthen #fraudprevention, implement risk-based authentication, improve onboarding security, and build audit-ready controls aligned to CBN requirements. 👉 Download the guide and start preparing before the deadline arrives: link.group-ib.com/4wgoSGK
Group-IB Global tweet media
English
0
2
4
386
Group-IB Global
Group-IB Global@GroupIB·
🚨 Threat actors continue to find new ways to hide malicious activity inside trusted enterprise services. Group-IB Threat Intelligence researchers have uncovered #HOLLOWGRAPH, a Windows malware linked with high confidence to the Cavern framework that abuses Microsoft Graph API and compromised #Microsoft365 accounts to establish a covert command-and-control channel. Key findings from our research: 🔹 Microsoft 365 calendars repurposed as two-way dead drops for command execution and data exfiltration 🔹 Commands and stolen files hidden inside encrypted calendar event attachments scheduled for the year 2050 🔹 DNS tunneling over IPv6 AAAA records used to refresh Microsoft Entra ID credentials required for cloud-based C2 communications 🔹 At least 12 identified victims, with telemetry suggesting a highly targeted operation focused on Israeli entities 🔹 Technical overlaps linking HOLLOWGRAPH to the broader Cavern framework As threat actors increasingly leverage legitimate cloud infrastructure to evade detection, defenders must expand visibility beyond traditional network indicators and monitor for abuse of trusted services. Read the full technical analysis: link.group-ib.com/4wS8490 #ThreatIntelligence #CyberSecurity #MalwareAnalysis #CloudSecurity
Group-IB Global tweet media
English
0
5
9
939
Group-IB Global
Group-IB Global@GroupIB·
❗ 6 days to go: see the cognitive core in action Tired of AI that just helps you type faster? In three days, watch Prevyn AI do the work. In our live webinar, Prevyn AI takes one question and runs a full investigation in Threat Intelligence — live, end to end, every step analyst-reviewable. 🗓️ Thursday, July 23, 2026 | 10:00 AM CEST| 45 min 🔹 Live, end-to-end research investigation in Threat Intelligence 🔹 The new Graph Agent in action 🔹 Grounded in 20+ years of proprietary intelligence Save your seat: link.group-ib.com/4fncYUn #AgenticAI #ThreatIntel #SOC #AIinCybersecurity #Webinar #PrevynAI
Group-IB Global tweet media
English
0
0
3
370
Group-IB Global
Group-IB Global@GroupIB·
In October 2025, #cybercriminals registered one lookalike domain and configured it to pass every email authentication check. At least four npm developers received the same message. Once they entered their credentials, the attackers pushed a #cryptocurrency clipper into 20 popular npm packages with 2.8 billion combined weekly downloads. None of those emails were spoofed. Each one passed SPF, DKIM, and DMARC, because the attacker owned the domain. This is one of five #emailattack patterns in our new report on 2026 threats bypassing company email security. If you use email, you're a target. Download the research: link.group-ib.com/3RDYS9a
Group-IB Global tweet media
English
1
4
10
1K