2024-11-21 09:33 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Following the arrest in May 2024 of more than 20 individuals behind Facebook infostealers campaigns in Vietnam, we have compared the tactics of operators behind VietCredCare and DuckTail stealers. These 2 malware families have been active before the arrest in Vietnam and are believed to be controlled by Vietnamese threat actors. Based on the research, we decided that the groups operate in a different way and the arrest probably affected the VietCredCare operators.
P0
2024-11-12 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Explore the highlights of Huntress Capture the Flag 2024, where teams cracked complex cyber challenges in a month-long journey of reverse engineering and malware analysis.
P0
2024-10-29 08:25 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Stop fraud, RATs, and malware with Group-IB's Fraud Protection AI. Our advanced behavioral analysis uses AI to detect and prevent threats in real-time, safeguarding your business and users.
P0
2024-09-25 07:00 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
In this blog, we look at the DragonForce ransomware group, which poses a severe threat with two variants—a LockBit fork and a customized Conti fork with advanced features and SystemBC malware.
P15
2024-09-20 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Tracking various indicators associated with different attacks, Huntress analysts have been able to identify specific indicators (threat actor workstation names, passwords associated with new user account creation or current account modification, CloudFlare tunnel tokens) that are associated with Akira ransomware infections. By detecting these indicators much earlier in the attack chain, organizations can inhibit or even obviate file encryption malware deployment.
P15
2024-09-12 04:53 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Discovered by Group-IB in May 2024, the Ajina.Banker malware is a major cyber threat in the Central Asia region, disguising itself as legitimate apps to steal banking information and intercept 2FA messages.
P0
2024-09-04 06:52 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Explore the growing threats posed by the Lazarus Group's financially-driven campaign against developers. We will examine their recent Python scripts, including the CivetQ and BeaverTail malware variants, along with their updated versions in Windows and Python releases. Additionally, we will analyze their tactics, techniques, and indicators of compromise.
P0
2024-07-31 06:51 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
CraxsRAT is a notorious Android malware family known for its Remote Administration Tools (RAT), which include remote device control and advanced spyware functions like keylogging, gesture manipulation, and recording of cameras, screens, and calls.
P0
2024-07-25 05:58 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Specializing in AI-powered phishing-as-a-service and Android malware capable of intercepting OTP codes, the GXC Team targets Spanish bank users and 30 institutions worldwide
P0
2024-07-23 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Hackers cloned a legitimate medical image viewer site to distribute malware, but thanks to Huntress, the threat was detected in time. Dive into the incident and see how we uncovered the deception and averted disaster.
P0
2024-07-17 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress has observed new behaviors in conjunction with the malware SocGholish. Read on to understand the implications of this threat and how you can better protect yourself.
P0
2024-07-16 18:33 UTC
Other
Black Lantern Security · Adeem Mawani · indexed 2026-09-07 17:30 UTC
Evasion Techniques and Detection Strategies for Memory-Resident Malware
P0
2024-07-16 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
The AWS Client VPN service was found to be affected by two vulnerabilities which could potentially allow malicious actors with access to a user’s device to execute arbitrary commands with elevated privileges, including escalating to root access. Both vulnerabilities stem from buffer overflow issues, a common programming error that can be exploited to overwrite memory and gain unauthorized control over a system. The impact of these vulnerabilities is severe, as successful exploitation could lead…
P0
2024-06-26 06:37 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
The scam schemes enabled by Craxs Rat malware provide complete remote control of the victims’ devices. Defend yourself from being next.
P0
2024-06-21 05:25 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Uncovering the operations of threat actor Boolka, driven by the creation of malicious scripts, malware trojans, sophisticated malware delivery platforms, and more.
P0
2024-06-05 09:01 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Learn how to protect your devices against evolving iOS threats
P0
2024-04-25 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
There's a new variant of LightSpy malware targeting macOS. Here, Huntress' macOS researchers dive into the macOS variant of the LightSpy malware, after gaps in recent reports stating that the LightSpy malware strictly targets iOS.
P0
2024-02-21 07:58 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB discovers new information stealer targeting Vietnam with rare functionality to filter out Facebook accounts with advertising credits
P0
2024-02-15 08:02 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB uncovers the first iOS Trojan harvesting facial recognition data used for unauthorized access to bank accounts. The GoldDigger family grows
P0
2024-01-16 07:58 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Inferno Drainer may have shut down in November 2023, but users of the devastating scam-as-a-service platform still pose a risk as they look for other avenues.
P0
2023-12-07 05:56 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
This piece of malware has an insatiable appetite. Group-IB's Threat Intelligence unit offers their insights on the new RAT used in attacks against Thai companies.
P0
2023-11-30 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
A look inside the evolving landscape of macOS malware. Dive into the current state of macOS threats and learn from a glossary of essential macOS terms.
P0
2023-10-05 06:55 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Delve into the tactics of the GoldDigger Trojan and discover ways to safeguard your customers
P0
2023-09-21 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Dive into the fundamentals of reverse engineering malware and understanding how malicious software works.
P0
2023-09-07 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
A deep dive into the USB-borne Raspberry Robin malware and how Huntress Managed EDR and Managed Antivirus can detect and mitigate this threat.
P0
2023-08-30 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
With the FBI's takedown of Qakbot malware, we're sharing how the Huntress team developed our own Qakbot vaccine and our commitment to defend forward.
P0
2023-08-29 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Dive into the basics of threat hunting and tactical malware analysis, and learn how these two practices go hand in hand in cybersecurity.
P0
2023-08-14 07:59 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Uncover the disruptive nature of Gigabud malware and take proactive measures to mitigate the associated risks
P0
2023-06-28 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Do you need third-party security for macOS? Discover if Apple’s malware prevention products, XProtect and XProtect Remediator, are good enough solutions to keep users safe.
P0
2023-05-02 08:59 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
New and modified malware detonation capabilities in Group-IB’s Managed XDR and Business Email Protection solutions for precise threat detection and analysis
P0