Agentic AI is the breakthrough of the moment, in security as everywhere else: agents that are threat-aware, active, and proactive in investigation. But it is also the technology behind a recent ...
Milk Dragon, also known as NaiLong is an Adversary-in-the-Middle (AiTM) phishing kit active since October 2025. Unlike conventional phishing tactics that rely on fear and urgency, Milk Dragon lures ...
Group-IB Threat Intelligence analyzes HEAVYGRAM, a Telegram-based Windows backdoor attributed with moderate confidence to the Iran-linked threat actor Handala Hack. Active since Fall 2023, it has been ...
A widespread smishing campaign was identified in which victims received fraudulent SMS messages impersonating official entities and were instructed to click a link inside the SMS in order to “complete ...
During the “Hook for Gold” research, Group-IB discovered an application called Vwork that was installed within minutes after initial Gigabud infection along with tampered banking applications. Trials ...
This blog provides a deep-dive into the phishing kit created by Chenlun known as the Outsider Phishing Kit. It is a well established kit in the Chinese community with over 267 ready-made phishing ...
Anatomy of BraZetsu: How Cybercriminals Fuel the Underground Ecosystem Group-IB uncovers BraZetsu, a new Python-based Windows malware that serves as a master toolkit for Initial Access Brokers and ...
A new NFC relay malware designated as WindRelay, paired with SpyNote RAT enables live-call fraud, combining social engineering with dual digital and physical cash-out. Group-IB have tracked this ...
The ransomware economy has been rewired. Meet the eight ransomware groups driving the shift, from affiliate breakaways to AI-assisted attacks based on Group-IB Threat Intelligence. The ransomware ...
Capabilities RedHook’s capabilities are largely consistent with what we typically see in an Android RAT: Accessibility-driven gestures, node layout (UI tree) collection, screen streaming, keylogging, ...
This blog covers Group-IB’s overview of Scattered Spider, backed by Group-IB’s proprietary intelligence, providing additional information to what has already been reported publicly, with added ...
The Millenium RAT first surfaced in a threat report by CYFIRMA on November 3, 2023, initially tracked with malware version 2.4. Group-IB’s current intelligence suggests a significant evolution in the ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results