home.social

#groupib — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #groupib, aggregated by home.social.

fetched live
  1. Hackers Use AI Voice Calls and Fake Banking Pages to Bypass MFA and Steal Accounts

    Indicators extracted from public reporting. Source: group-ib.com/blog/balonx-siste

    Pulse ID: 6a85c43554b382dba75c54b7
    Pulse Link: otx.alienvault.com/pulse/6a85c
    Pulse Author: CyberHunter_NL
    Created: 2026-08-19 14:56:53

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Bank #CyberSecurity #GroupIB #HTTP #HTTPS #InfoSec #MFA #Mexico #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  2. Gone with the WindRelay: A New Malware Combo Behind a Growing Fraud Scheme

    A new NFC relay malware family called WindRelay has been discovered operating in combination with SpyNote RAT to enable sophisticated contactless payment fraud. The scheme uses live social engineering phone calls where fraudsters impersonate bank employees and guide victims to install personalized RAT malware labeled with the victim's own name. Once installed, the RAT enables silent deployment of WindRelay, which captures contactless payment card data via NFC when victims tap their cards to their phones. The captured data is relayed in real-time to fraudster-controlled terminals for immediate cash-out through physical purchases or ATM withdrawals. The operation employs dual monetization, combining RAT-driven digital loan fraud with NFC-based card-present transactions. Group-IB identified 23 WindRelay samples targeting victims in Czechia, Slovakia, and Slovenia between November 2025 and July 2026.

    Pulse ID: 6a7c6340682f0dc9b225d8d6
    Pulse Link: otx.alienvault.com/pulse/6a7c6
    Pulse Author: AlienVault
    Created: 2026-08-12 12:12:48

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Bank #CyberSecurity #GroupIB #InfoSec #Malware #OTX #OpenThreatExchange #RAT #Slovenia #SocialEngineering #SpyNote #Troll #bot #AlienVault

  3. 13-Minute WindRelay Malware Attack Uses SpyNote RAT and NFC Relay Malware to Drain Victim Accounts

    Indicators extracted from public reporting. Source: group-ib.com/blog/windrelay-nf

    Pulse ID: 6a7c6d65bad96416b5bbfbd3
    Pulse Link: otx.alienvault.com/pulse/6a7c6
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 12:56:05

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #GroupIB #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RAT #RCE #SpyNote #bot #CyberHunter_NL

  4. XMRig Covert Ops: The Cryptomining Campaign That Abuses Trusted Access and Deploys Forensic Smokescreens | Group-IB Blog

    Join the Cybercrime Fighters Club, a group of professionals dedicated to combat cybercrime and other forms of cyber-crime. £1.5m in funding, research, development and training.

    Pulse ID: 6a6b19baacfdff5ea7386d10
    Pulse Link: otx.alienvault.com/pulse/6a6b1
    Pulse Author: CyberHunter_NL
    Created: 2026-07-30 09:30:34

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CryptoMining #CyberCrime #CyberSecurity #GroupIB #InfoSec #OTX #OpenThreatExchange #Rust #bot #CyberHunter_NL

  5. JadeProx: il cluster cinese che si è tradito da solo mentre colpiva ospedali, ministeri e università in Asia

    Un server Alibaba Cloud lasciato esposto ha rivelato JadeProx, cluster China-nexus dietro intrusioni contro un ospedale vietnamita, il Ministero degli Esteri malese e l'ateneo di Hong Kong. Al centro, il nuovo TriBack Loader e un finto installer di Claude usato come esca.

    insicurezzadigitale.com/jadepr

  6. HollowGraph: la backdoor che trasforma il calendario di Microsoft 365 in un canale C2 cifrato

    Group-IB ha scoperto HollowGraph, un impianto legato al framework iraniano Cavern che usa eventi di calendario Microsoft 365 datati al 2050 come dead drop per comandi e dati rubati, mascherando tutto da traffico Graph API legittimo. Colpita un'organizzazione israeliana.

    insicurezzadigitale.com/hollow

  7. Четыре года делу Сачкова: конфликт глобальной профессии и локального долга в кибербезопасности

    29 сентября исполнится четыре года со дня ареста Ильи Сачкова. Вроде бы споры вокруг этой истории поутихли, но каждый раз, когда речь заходит о ней в профессиональном кругу, тема оживает и вызывает живой отклик. Слишком много неясного и противоречивого, слишком серьёзные вопросы затронуты. Для меня это стало поводом взглянуть шире: не только на само дело, но и на ту этическую ловушку, в которую попадают специалисты по кибербезопасности. Как честно работать в глобальном сообществе, при этом оставаясь гражданами конкретной страны, со своими законами и ограничениями? Где искать баланс? Какие ориентиры появятся в ближайшем будущем — и что нам даёт новый международный Code of Professional Conduct от ISC2?

    habr.com/ru/articles/948938/

    #сачков #groupib #кибербезопасность #этика #cpc #цифровой_суверенитет #законодательство

  8. In search of riches, #hackers plant 4G-enabled #RaspberryPi in bank network

    The researchers with security firm Group-IB said the “unprecedented tactic allowed the attackers to bypass perimeter defenses entirely.” The hackers combined the physical #intrusion with remote access #malware that used another novel technique to conceal itself, even from sophisticated #forensic tools.
    #4g #security #privacy #GroupIB

    arstechnica.com/security/2025/

  9. In 2024, a group known as DarkCasino emerged as a cyber threat entity. This group has been linked to exploiting a vulnerability in WinRAR, specifically identified as CVE 2023 38831. DarkCasino has been using this security loophole to carry out phishing attacks targeting users in industries such as casinos, financial services, and government sectors across countries. Their strategy involves sending emails containing manipulated archives to distribute malicious software and gather sensitive information.

    DarkCasino, while sharing similarities with other cyber threat groups, stands out for its sophisticated techniques and primarily financial motivation. Their use of Visual Basic-based Trojan horse programs is a testament to their advanced capabilities. Their activities underscore the ever-evolving landscape of risks and the critical need for robust cybersecurity measures. Ongoing surveillance and analysis by cybersecurity firms like NSFOCUS and Group IB have provided insights into DarkCasino's operations, but many specifics regarding their targets and the complete extent of their actions remain undisclosed, adding to the complexity of the challenge.

    #DarkCasino #APT #CyberSecurity #WinRAR #ZeroDay #PhishingAttacks #CyberThreats #DataExfiltration #Malware #AdvancedThreats #VisualBasic #TrojanHorse #FinancialServices #GovernmentSecurity #NSFOCUS #GroupIB #CyberEspionage #ThreatDetection #InformationSecurity #EconomicMotivation

  10. A new advanced threat actor known as #DarkPink, also referred to as #Saaiwc Group, has been found to be targeting government agencies and military bodies in multiple countries in the #APAC region using custom malware to steal confidential information. #GroupIB #cybersecurity #APT andreafortuna.org/2023/01/11/n