Group-IB

@group_ibПроверенLive API

КатегорияOtherЯзыкRUДобавлен06 июл. 2026 г.КачествоПроверен
Открыть в Telegram
Подписчики2.9K
Сред. просмотры996
ERR33.9%
Цена-- RUB
Цена / подписчик--
Цена / просмотр--
Метрики обновлены: 06 июл. 2026 г.
Последние посты
🚨 Smishing campaigns continue to evolve beyond convincing lures. Modern phishing operations are increasingly engineered to evade detection. In our latest technical analysis, Group-IB researchers dissect a campaign targeting drivers in Serbia through fake traffic fine SMS notifications. The investigation links the operation to two Phishing-as-a-Service ecosystems, Darcula and Phoenix, and reveals a phishing framework built for scale, resilience, and evasion. The report explores how attackers: 🔹 Deploy disposable lookalike domains and cloned government portals 🔹 Use JavaScript-based runtime decoding and client-side obfuscation to hide phishing content from automated scanners 🔹 Leverage browser APIs such as requestIdleCallback and IntersectionObserver to selectively render malicious content 🔹 Rotate infrastructure rapidly to stay ahead of detection and takedowns Read the full technical analysis . #Phishing #Smishing #CyberSecurity
3941 июл.
Group-IB supported INTERPOL and the Algerian National Police in dismantling SniperDz, a phishing-as-a-service (PhaaS) platform that operated for nearly a decade and enabled cybercriminals to launch phishing campaigns at scale. Key findings: 🔹 20,000+ domains linked to the ecosystem 🔹 30+ global brands impersonated 🔹 80 phishing templates across five languages 🔹 45,000+ victim records reported by the platform in 2016 alone Following a multi-month investigation, the operation led to the disruption of SniperDz infrastructure and the arrest of its primary developer and administrator. The takedown of a platform operating at this scale is a major blow to the phishing ecosystem and helps better protect users of financial, telecom, entertainment, and other online services. 🔗 Read the full story . #CyberSecurity #Phishing #ThreatIntelligence #INTERPOL
91411 июн.
Our latest research examines SilabRAT, a Malware-as-a-Service platform sold on underground forums that combines credential theft, browser profile cloning, HVNC, Chrome App-Bound Encryption bypass techniques, and cryptocurrency-focused capabilities into a single offering. Key findings: 🔹 SilabRAT has been marketed on underground forums since late 2025 for $5,000/month 🔹 Leverages HVNC for invisible interaction with victim systems; other session access options include browser profile cloning, cookie theft 🔹 Includes functionality to bypass Chrome App-Bound Encryption (ABE) and extract protected browser data 🔹 Features automated cryptocurrency wallet targeting and password recovery capabilities 🔹 Observed in real-world campaigns leveraging ClickFix social engineering techniques As cybercriminals move beyond simple credential theft toward full session compromise, understanding emerging RAT capabilities is critical for defenders. 🔗 Read the full analysis . #ThreatIntel #MalwareAnalysis #CyberSecurity
76410 июн.
💳 The $48 Billion Blind Spot: Why Merchants Pay for Card Breaches They Can’t See The scale of the problem: 🔹 200M+ compromised payment cards actively circulating in underground markets 🔹 E-commerce fraud projected to reach $53 billion in 2025 🔹 Every $1 of fraud costs merchants $4.61 once chargebacks, fees, and operational costs are factored in Why merchants can’t access the intelligence: 1️⃣ PCI DSS prohibits storing raw card data 2️⃣ Card network notification systems (Visa CAMS, Mastercard SAFE) operate issuer-to-issuer only 3️⃣ GDPR and data protection laws block cross-border sharing of personal identifiers The result: Merchants absorb losses from cards that were already confirmed compromised. They just had no way to know. What’s changing: Privacy-preserving Distributed Tokenization enables real-time compromised card checks at authorization, without raw card data or PCI DSS scope expansion. Read the full analysis . #FraudPrevention #EcommerceSecurity #Cybersecurity
6569 июн.
🚨 Group-IB researchers uncovered a sophisticated global smishing operation that has impersonated more than 267 brands across 72 countries and generated over 4,389 phishing domains since the second half of 2025. The campaign combines SMS phishing, geofencing, device fingerprinting, fake Cloudflare error pages, and encrypted WebSocket communications to evade detection and harvest personal and payment card data in real time. Key findings: 🔹 Telecommunications emerged as the most targeted sector with 1,754 domains, followed by financial services with 696 domains and consumer rewards programs with 488 domains. 🔹 Malicious content is revealed only to victims matching specific geographic and mobile device criteria. 🔹 Stolen data is exfiltrated through encrypted WebSocket channels using binary encoded payloads. 🔹 Approximately 30 percent of the infrastructure is hosted on Tencent Cloud and Alibaba origin servers while being fronted by Cloudflare. Read the full technical analysis . #DRP #Smishing
8563 июн.