Skip to content

company

Group-IB

Cybersecurity firm providing threat intelligence, digital forensics, and incident response, tracking cybercrime groups and malware worldwide.

Known aliases

  • Group IB

Relationships

No evidence-backed relationships are recorded.

Current stories

security14 publishers

Investigators say a 16-year-old ran KillSec, an extortion crew that exploited weakly secured cloud storage

Eurojust says a 16-year-old is the suspected main operator of KillSec, a group it blames for almost 1,000 data-theft extortion attacks since 2024. Both published accounts say its favoured way in was poorly secured access to victims' cloud storage.

Perspective Coverage

14 publishers
Builder
Builder 16%
Operator
Operator 75%
Investor
Investor 9%

Reality

Evidence78
Adoption
Insufficient
Hype gap+25
Incentives45
Confidence76
security4 publishers

Meta ads steer Android users to fake Google Play pages carrying the RemControl banking trojan

Group-IB says the RemControl Android banking trojan reaches bank customers in six countries and the Middle East via Meta ads and fake Google Play pages. Its server address sits in a Telegram dead-drop, so the operator can move infrastructure without a new build.

Perspective Coverage

4 publishers
Builder
Builder 34%
Operator
Operator 59%
Investor
Investor 7%

Reality

Evidence65
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence65
security3 publishers

Card-present fraud without the card: WindRelay relays NFC from the victim's own phone

Group-IB says a 13-minute call ended with a loan in the victim's name and card data streaming to a fake merchant terminal, every transaction approved with the victim's own PIN.

Perspective Coverage

3 publishers
Builder
Builder 27%
Operator
Operator 63%
Investor
Investor 10%

Reality

Evidence62
Adoption20
Hype gap+10
Incentives40
Confidence65
security3 publishers

Gigabud creates an Android work profile to put its fake bank app out of the scanner's reach

Group-IB says a second app sets up the work profile within minutes of infection and clones a fake bank app into it, so the malware check inside that app looks at an empty room while the trojan runs in the personal space.

Perspective Coverage

3 publishers
Builder
Builder 23%
Operator
Operator 67%
Investor
Investor 10%

Reality

Evidence55
Adoption30
Hype gap+15
Incentives50
Confidence60
security9 publishers

Group-IB ties the Handala Hack persona to a Telegram-run backdoor that steals saved passwords

Group-IB says the Iran-linked leak-and-brag front Handala Hack runs HEAVYGRAM, a Python implant that takes orders from a Telegram bot, opens the microphone and lifts saved passwords after a loader writes Defender exclusions for it.

Perspective Coverage

9 publishers
Builder
Builder 44%
Operator
Operator 52%
Investor
Investor 4%

Reality

Evidence82
Adoption64
Hype gap+5
Incentives45
Confidence80
security1 publisher

Qilin hands affiliates the ransom wallet before the core team takes its cut

Group-IB puts the Qilin affiliate cut at up to 80 percent, and KELA logged a change that routes victim payments through affiliate wallets first, which says more about the operation's incentives than its thin public tradecraft record does.

Publishers:blog.bushidotoken.net

Reality

Evidence54
Adoption63
Hype gap+14
Incentives71
Confidence57