#group-ib
9 stories taggedgroup-ib.

SpyNote and WindRelay: the Android malware combo that empties bank accounts over a single phone call
Group-IB documents a 13-minute attack chain that installs a remote-access tool, takes out a loan, then relays the victim's contactless card to a criminal at a real payment terminal.

Leaky Alibaba Cloud Server Exposes China-Linked Spying Kit Aimed at Hospitals and Governments
Researchers at Group-IB stumbled on a misconfigured server in Singapore that revealed a new Windows loader, TriBack, used against targets across Asia and Latin America.

HollowGraph Malware Hides Spy Commands Inside Microsoft 365 Calendar Entries
A newly identified piece of malware turns ordinary calendar appointments into a covert messaging system, letting criminals send instructions and steal files without ever touching a suspicious server.

HollowGraph: The Spyware That Hides Its Orders in a Fake 2050 Calendar Invite
Researchers at Group-IB link the covert Microsoft 365 tool to Iran-nexus activity targeting Israeli organisations, with medium confidence.

HollowGraph Spies Hide Their Orders in Fake Calendar Events Dated 2050
A newly named espionage tool turns Microsoft 365 calendars into a secret mailbox, tucking instructions and stolen files into meetings set decades in the future.

ClickLock: the Mac malware that locks up your screen until you type your password
A new macOS stealer, tracked by Group-IB, freezes everything on the screen except a password box. It has already hit around 100 machines in 33 countries.

ClickLock Stealer Tricks Mac Users Into Handing Over Their Own Passwords
A newly discovered piece of Mac malware skips the usual hacking tricks and simply persuades victims to run it themselves, then locks the screen until they surrender their passwords.

RedHook Android Malware Turns Phones Into Their Own Debugging Tool
A new build of the RedHook trojan tricks Android users into switching on Wireless Debugging, then quietly promotes itself to a privilege level normal apps can never reach.

Facebook Impersonation Scams Sweep MENA, Pushing Fake Subsidies and 'Free Data' Lures
Group-IB ties the campaign to a broader fraud network using cloned political figures, fake government programs and browser-push alerts to harvest credentials and payment data.