Eurojust says a 16-year-old is the suspected main operator of KillSec, a group it blames for almost 1,000 data-theft extortion attacks since 2024. Both published accounts say its favoured way in was poorly secured access to victims' cloud storage.
Perspective Coverage
14 publishers
- Builder
- Builder 16%
- Operator
- Operator 75%
- Investor
- Investor 9%
Reality
- Evidence78
- Adoption
- Insufficient
- Hype gap+25
- Incentives45
- Confidence76
Investigators say KillSec, tied to about 1,000 suspected attacks, got in through software flaws, weak cloud storage and logins bought on the dark web. Those gaps sit in victims' own systems, beyond the reach of any server seizure.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence40
Group-IB says the RemControl Android banking trojan reaches bank customers in six countries and the Middle East via Meta ads and fake Google Play pages. Its server address sits in a Telegram dead-drop, so the operator can move infrastructure without a new build.
Perspective Coverage
4 publishers
- Builder
- Builder 34%
- Operator
- Operator 59%
- Investor
- Investor 7%
Reality
- Evidence65
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence65
Group-IB says a 13-minute call ended with a loan in the victim's name and card data streaming to a fake merchant terminal, every transaction approved with the victim's own PIN.
Perspective Coverage
3 publishers
- Builder
- Builder 27%
- Operator
- Operator 63%
- Investor
- Investor 10%
Reality
- Evidence62
- Adoption20
- Hype gap+10
- Incentives40
- Confidence65
Group-IB says a second app sets up the work profile within minutes of infection and clones a fake bank app into it, so the malware check inside that app looks at an empty room while the trojan runs in the personal space.
Perspective Coverage
3 publishers
- Builder
- Builder 23%
- Operator
- Operator 67%
- Investor
- Investor 10%
Reality
- Evidence55
- Adoption30
- Hype gap+15
- Incentives50
- Confidence60
Group-IB says the Iran-linked leak-and-brag front Handala Hack runs HEAVYGRAM, a Python implant that takes orders from a Telegram bot, opens the microphone and lifts saved passwords after a loader writes Defender exclusions for it.
Perspective Coverage
9 publishers
- Builder
- Builder 44%
- Operator
- Operator 52%
- Investor
- Investor 4%
Reality
- Evidence82
- Adoption64
- Hype gap+5
- Incentives45
- Confidence80
The malware asks for accessibility, then has a second component build a work profile and copy the bank app into it. Group-IB says the clone registers with the bank as a new device while a black screen hides the transfer.
Reality
- Evidence42
- Adoption38
- Hype gap+12
- Incentives34
- Confidence48
Group-IB puts the Qilin affiliate cut at up to 80 percent, and KELA logged a change that routes victim payments through affiliate wallets first, which says more about the operation's incentives than its thin public tradecraft record does.
Publishers:blog.bushidotoken.net
Reality
- Evidence54
- Adoption63
- Hype gap+14
- Incentives71
- Confidence57
Group-IB says the phishing kit Google sued over in June kept producing pages after the FBI seized its admin servers and wallets, which puts the durable detection signal in the kit's file names rather than its hosts.
Reality
- Evidence44
- Adoption66
- Hype gap+6
- Incentives58
- Confidence46
Group-IB says the Exilware crew built BraZetsu to score compromised Iberian and Latin American machines by value and sell entry to whoever wants to run their own payload, which changes how a stealer alert should be triaged.
Reality
- Evidence55
- Adoption38
- Hype gap+18
- Incentives68
- Confidence48
Sophos CTU reviewed 15 intrusions by GOLD SHERWOOD affiliates and found the same route each time: a working credential on a Fortinet SSL VPN with no MFA, then RDP into domain controllers within hours.
Reality
- Evidence64
- Adoption76
- Hype gap+12
- Incentives70
- Confidence58
Group-IB says it found Tortoiseshell infrastructure on British IPs, plus Belgium, Saudi Arabia and the UAE. It also says the server names alone do not prove who was being targeted.
Perspective Coverage
3 publishers
- Builder
- Builder 38%
- Operator
- Operator 50%
- Investor
- Investor 12%
Reality
- Evidence64
- Adoption42
- Hype gap+16
- Incentives66
- Confidence61
Kaspersky says an Iranian-linked framework now picks its channel per transaction from a DNS record, and can swap the Google relay behind it. Allowlisted SaaS domains carry the traffic.
Reality
- Evidence68
- Adoption62
- Hype gap+8
- Incentives58
- Confidence57