Tag

#group-ib

8 stories taggedgroup-ib.

An Android smartphone interface showing a hidden work profile nested within the phone's settings, with a fake banking app icon visible inside the concealed prof
Threat Intelligence

Gigabud Banking Malware Hides Inside Android Work Profiles to Dodge Security Checks

A new Gigabud variant sets up a separate Android work profile and installs a fake banking app inside it, keeping malicious activity hidden from the phone's normal security scans.

3 min read
A computer terminal displaying encrypted command-line output and network packet traces, with shadowy server rack infrastructure visible in the background sugges
Threat Intelligence

Iran's Nimbus Manticore Adds New Backdoor and SSH Tunneler to Spy Kit

Group-IB says the IRGC-linked hackers have quietly built out fresh infrastructure and custom malware for espionage campaigns in 2026.

3 min read
A smartphone screen showing banking and payment applications, with malware process chains visualized as overlay graphics and fraudulent transaction confirmation
Threat Intelligence

SpyNote and WindRelay: the Android malware combo that empties bank accounts over a single phone call

Group-IB documents a 13-minute attack chain that installs a remote-access tool, takes out a loan, then relays the victim's contactless card to a criminal at a real payment terminal.

4 min read
A server room with rows of cloud infrastructure equipment, one unit's indicator lights glowing with exposed data streaming outward, maps of Asia and Latin Ameri
Threat Intelligence

Leaky Alibaba Cloud Server Exposes China-Linked Spying Kit Aimed at Hospitals and Governments

Researchers at Group-IB stumbled on a misconfigured server in Singapore that revealed a new Windows loader, TriBack, used against targets across Asia and Latin America.

4 min read
A cybercriminal's workspace with multiple monitors displaying calendar applications and email clients, showing how calendar entries contain encoded command inst
Threat Intelligence

HollowGraph Malware Hides Spy Commands Inside Microsoft 365 Calendar Entries

A newly identified piece of malware turns ordinary calendar appointments into a covert messaging system, letting criminals send instructions and steal files without ever touching a suspicious server.

3 min read
Illustration: a dimly lit office desk at night, a laptop screen glowing with a blurred calendar grid showing dates far
Threat Intelligence

HollowGraph Spies Hide Their Orders in Fake Calendar Events Dated 2050

A newly named espionage tool turns Microsoft 365 calendars into a secret mailbox, tucking instructions and stolen files into meetings set decades in the future.

3 min read
A MacBook screen displaying a convincing popup dialog asking for password entry, with the background showing a locked desktop state, while the user's hand hover
Threat Intelligence

ClickLock Stealer Tricks Mac Users Into Handing Over Their Own Passwords

A newly discovered piece of Mac malware skips the usual hacking tricks and simply persuades victims to run it themselves, then locks the screen until they surrender their passwords.

3 min read
Illustration: a modern Android smartphone lying on a dark matte desk
Threat Intelligence

RedHook Android Malware Turns Phones Into Their Own Debugging Tool

A new build of the RedHook trojan tricks Android users into switching on Wireless Debugging, then quietly promotes itself to a privilege level normal apps can never reach.

4 min read
© 2026 Threat Vectr