A leading creator of cybersecurity technologies to investigate, prevent, and fight digital crime. Combating cybercrime since 2003

Singapore
Attackers hide behind layers of infrastructure. Analysts pivot through it one node at a time. Not anymore. 🎉 Meet the Prevyn AI Graph Agent for Group-IB Threat Intelligence. Ask a question in plain language, like "investigate this indicator," and it builds the graph, maps related infrastructure, and returns analyst-ready findings with threat actor attribution. Hours of manual pivoting, done in minutes. One prompt to a complete, attributed graph. The future of #ThreatIntelligence is conversational. 👉 Book a no-strings-attached demo: group-ib.com/prevyn-ai/
3
4
364
Cisco’s Secure Firewall Management Center has a 10.0. CVE-2026-20079. Auth bypass. No creds needed. You get root. CISA put it in KEV, feds had until Sept 12 to patch. That deadline is gone. If you run FMC, check your version now. Not Monday. Now.
1
3
4
727
Citrix NetScaler CVE-2026-19490 is getting hit too. Honeypots saw 56 attempts since early Sept. 36 on Sept 8 alone. Auth bypass in ADC/Gateway when it’s set up as AAA vserver or Gateway. CVSS 9.3. If that’s your config, don’t sit on it.
1
2
6
948
Fortinet CVE-2025-25249 is being used to drop PivotC2 RAT. Hits FortiOS, FortiSwitchManager, FortiSASE. 3,000+ IPs targeted, 178 devices infected, mostly US. The annoying part? These are firewalls and gateways. The stuff you buy to keep attackers out is the way in. Patch and hunt. #infosec
2
1
5
307
Reflecting on an incredible gathering at Group-IB Partner Universe 2026 in Dubai! 🇦🇪 Bringing our community together under one roof was the perfect opportunity to align on our 2026 vision, exchange valuable best practices, and lay out our roadmap for the future. Most importantly, it gave us the chance to celebrate our phenomenal partners who continue to drive results and scale new heights with us. Massive congratulations to all our valued partners across the UAE, KSA, Egypt, Jordan, Tunisia, Libya, Qatar, Oman, and Kuwait for a fantastic FY25! Thank you for your unwavering trust and partnership. Here’s to setting new benchmarks together in the coming year! #GroupIB #PartnerUniverse #DubaiEvents #CybersecurityPartners #Innovation #FightAgainstCybercrime
3
2
342
88% of organizations now rank browser security a top-five priority (Omdia, 2026). Our #BrowserAgent closes #phishing pages before a password is typed and blocks them company-wide: link.group-ib.com/4rqHe6e
3
5
311
Cybersecurity increasingly depends on the ability to connect global #threatintelligence with local context. Group-IB and HUB201 have announced a strategic partnership to strengthen #cybersecurity resilience and accelerate cybersecurity innovation across Serbia and the wider Southeast Europe and Western Balkans region. Through the partnership, the two organizations will: 🔹 Deliver cybersecurity education, professional training and awareness initiatives 🔹 Bring Group-IB’s global Threat Intelligence and real-world threat insights to HUB201 startups and corporate partners 🔹 Support founders in validating their solutions against real industry challenges 🔹 Help corporate members strengthen their cyber resilience and regulatory readiness 🔹 Expand collaboration between the public sector, private sector, academia and the startup community The partnership will build on HUB201’s existing programs, including its Cyber Alliance membership community and NIS2 Officer Training Program. It will support the expansion of joint educational initiatives, executive roundtables and industry challenge formats over the first year, with further details to be announced as individual programs are confirmed. Read the full announcement to learn more about the partnership and what it means for cybersecurity innovation in the region: link.group-ib.com/4hgf4Gs
2
5
374
🏦 A new #Androidbanking trojan is targeting financial institutions across Western Europe, the Middle East, and Canada. Group-IB researchers have uncovered #RemControl, a previously undocumented Android banking trojan operating as Malware-as-a-Service (MaaS). First observed in July 2026, RemControl abuses Android’s Accessibility Service to inject #phishing overlays over legitimate #bankingapplications, capture sensitive credentials, stream the victim’s screen, log interactions, and remotely control the device. The threat goes beyond credential theft. Its infrastructure includes an exposed operator panel for managing bots, overlay templates, stolen credentials, remote sessions, and affiliate-specific APK builds. The #malware also uses a local VPN to interfere with Google Play Protect during installation and retrieves its command-and-control address through an encrypted Telegram dead-drop mechanism. Researchers also identified evidence of AI-assisted development, including an AI-generated response accidentally left inside a live phishing page. Read the full blog: link.group-ib.com/4jjBhG8
7
12
841
Most security teams treat cryptomining as a low-risk nuisance. But in a covert Linux campaign we investigated, the mining payload was never the real objective. It was the cover. Attackers abused the Pluggable Authentication Module (PAM), a core Linux authentication component, to maintain trusted access and make forensic investigation harder. The campaign also used self-unlinking payloads that disappeared from disk after execution, removing key evidence before responders could analyze it. The bigger issue is trusted access abuse. Unlike a vulnerability, it can't simply be patched. Teams have to identify when legitimate administrative pathways are being misused. If your incident response playbook treats cryptomining alerts as low priority, you could be closing the ticket just when the real investigation should begin. Read the full technical breakdown of the PAM abuse, forensic evasion, and self-unlinking payloads: bit.ly/4rniuvP #Cybersecurity #ThreatIntelligence #LinuxSecurity #Cryptomining #CyberThreats
2
3
356
Earlier this month, our Global Head of Pre-Sales, Maximilian Bode, spoke on the panel "AI and Cyber Risk: The View from the Inside" at Tech Race Summit in Warsaw. The conversation dug into how AI is reshaping the threat landscape and what security teams need to prioritize as risks evolve faster than ever. Thank you to @softswiss for organising a great event and bringing together such a strong lineup of speakers and attendees. #TechRaceSummit #CyberSecurity #AI
4
326
On the final day of #GISEC2026, we were proudly recognized as Group-IB's Outstanding Partner of the Year. 🏆 The award was presented by H.E. Dr. Mohamed Al-Kuwaiti, Head of Cybersecurity for the UAE Government and Chairman of the UAE Cyber Security Council (@cscgovae). It's a real honor to be acknowledged by such a leader in the field. The event was a great chance to connect with partners and peers from across the #cybersecurity community, and a sincere thank you to everyone who stopped by our booth throughout the week. Those conversations are what make GISEC worth it every year. We're looking forward to building on these relationships. See you all at the next one!
1
3
353
🤝 At #GISEC2026, Group-IB and the UAE Cyber Security Council announced a strategic partnership to advance predictive cyber defence through threat intelligence exchange, coordination on incident response and cybersecurity capacity building. The collaboration also includes plans to explore a joint Innovation Center of Excellence in the UAE, bringing together the Council’s national cybersecurity vision and Group-IB’s adversary-centric intelligence. Full announcement: link.group-ib.com/4xA8JLY
2
5
350
🏦 Every bank knows its fraud losses, but few know full fraud exposure. Boards set risk appetite and provisioning on the first number. The second is rarely measured on the same basis. New Group-IB study sets out a method to measure both: link.group-ib.com/4xyzpg4 #FraudPrevention #BankingSecurity #Cybersecurity
1
4
350
Most security teams treat cryptomining as a low-risk nuisance. But in a covert Linux campaign we investigated, the mining payload was never the real objective. It was the cover. Attackers abused the Pluggable Authentication Module (PAM), a core Linux authentication component, to maintain trusted access and make forensic investigation harder. The campaign also used self-unlinking payloads that disappeared from disk after execution, removing key evidence before responders could analyze it. The bigger issue is trusted access abuse. Unlike a vulnerability, it can't simply be patched. Teams have to identify when legitimate administrative pathways are being misused. If your incident response playbook treats cryptomining alerts as low priority, you could be closing the ticket just when the real investigation should begin. Read the full technical breakdown of the PAM abuse, forensic evasion, and self-unlinking payloads: bit.ly/4jck0yx #Cybersecurity #ThreatIntelligence #LinuxSecurity #Cryptomining #CyberThreats
4
7
498
Day 2 at GISEC Global, caught on camera. 🎥 From packed demo pods to sharp conversations across the floor, yesterday was one to remember. Hit play and relive the energy. Today's the final day, and there's still time to catch us. Swing by H5 and let's talk before the doors close. 👋 #GISEC #Meta #Conference #Event #GroupIB #Cybersecurity
1
4
382
The growing demand for AI tools is creating new opportunities for cybercriminals. Threat actors are increasingly exploiting trusted brands, software directories, and user demand to distribute malware disguised as legitimate cryptocurrency trading and gambling tools. As AI adoption accelerates, organizations need visibility beyond traditional indicators of compromise. Group-IB's Threat Intelligence provides actionable insights into emerging malware campaigns, threat actor infrastructure, and evolving attack techniques, helping security teams identify threats before they become incidents. #ThreatIntelligence #CyberSecurity #Malware #ThreatResearch #GroupIB
3
5
353
#Ransomware continues to put organisations across #LatinAmerica under pressure, making timely intelligence and cross-border cooperation more important than ever. From 8–10 September, @INTERPOL_Cyber brought together law enforcement agencies from across the Americas and private-sector experts at its Regional Bureau in Buenos Aires, Argentina, for a working group focused on the ransomware threat facing the region. Representing Group-IB, Asdrubal Veloz shared actionable intelligence on the top ransomware groups targeting Latin America, including insights into their operators and activities. Understanding who is behind these campaigns is critical to helping investigators move from reacting to incidents to identifying and disrupting the actors responsible. Tackling ransomware requires more than individual efforts. Stronger collaboration between law enforcement and the private sector can help turn intelligence into action. Group-IB is proud to contribute its #threatintelligence and expertise to these efforts and support the global #fightagainstcybercrime. We are grateful to #INTERPOL for convening this vital conversation.
1
2
363
A familiar messaging platform can become much more than a communication tool when threat actors turn it into part of their attack infrastructure. Group-IB #ThreatIntelligence uncovered 29 new samples associated with the #HEAVYGRAM and #CRUDEEXCLUDE malware families, providing new insight into activity attributed with moderate confidence to #HandalaHack. Key Highlights: 🔹 HEAVYGRAM is a Windows backdoor capable of remote command execution, screenshot capture, system and process discovery, Telegram session data exfiltration and persistence through Windows autorun registry keys. 🔹 Telegram-based C2 is central to the operation. HEAVYGRAM uses Telegram bots, users and groups to receive commands, exchange files and exfiltrate data. 🔹 Application masquerading is used to deceive victims, with samples posing as legitimate applications including Telegram, KeePass and Pictory. 🔹 CRUDEEXCLUDE supports defense evasion by adding paths to Microsoft Defender exclusions before deploying additional stages. 🔹 Multiple delivery mechanisms were identified, including WSF, VBS, HTA and executables containing embedded archives. 🔹 Much of the identified #Telegram infrastructure continues to remain present on Telegram as of 2026, rather than deleted, although some of the identified accounts have since been taken over by unrelated actors and repurposed for other activity. Read the full technical analysis to understand the infection chain, malware capabilities, infrastructure and defensive recommendations: link.group-ib.com/4hwWtHq
8
8
674