Skip to content
The Nexus
DossierENTITY

Group-IB

Coverage of Group-IB in the Nexus archive.

Earliest in view: May 18 · 18:56 UTCMost recent: Aug 13 · 11:34 UTC
Co-mentioned in this coverage
Recent coverage
  • SECURITYAug 13 · 11:34 UTCMALWAREBYTES LABS
    New Android malware lets criminals use your bank card in real time

    Researchers at Group-IB discovered "WindRelay," a new NFC relay malware family designed to capture live card data and forward it in real time to attackers. The attack process involves tricking victims into installing an Android remote access Trojan (RAT) called SpyNote, which then enables the theft of contactless payment details from physical cards. This technology allows criminals to make purchases or withdraw cash remotely using dynamic transaction-specific codes.

  • SECURITYJul 26 · 13:01 UTCFOX NEWS
    ClickLock Mac malware locks apps until you give in

    ClickLock is a Mac malware that tricks users into running a Terminal command, leading to data theft and remote access. Discovered by Group-IB, it has infected over 100 systems across 33 countries by stealing passwords, browser data, and cryptocurrency wallet files.

  • SECURITYJul 21 · 11:59 UTCMALWAREBYTES LABS
    New ClickLock Stealer locks your Mac until you hand over your password

    ClickLock Stealer is a macOS infostealer delivered via phishing pages that locks victims' Macs by terminating processes, stealing passwords, browser data, and cryptocurrency wallets. It employs a GSocket backdoor for persistent remote access and forces users to submit their macOS password via a fake prompt, with a kill loop disabling system functions until compliance.

  • SECURITYJul 20 · 14:33 UTCTHE HACKER NEWS
    HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

    HollowGraph malware, discovered by Group-IB, uses hijacked Microsoft 365 calendars as a command channel, hiding operator instructions and stolen files in calendar events dated 2050. The malware leverages Microsoft Graph API traffic to blend malicious activity with legitimate traffic.

  • SECURITYJun 15 · 06:30 UTCTHE HACKER NEWS
    Sniper Dz Scams Target MENA Users via Fake Facebook Offers and Browser Alerts

    Cybersecurity researchers have identified scams targeting Middle East and North Africa (MENA) users through fake Facebook accounts impersonating politicians, public figures, and trusted organizations. These accounts promoted fraudulent offers, including free mobile internet packages, financial compensation, and government subsidy programs.

  • SECURITYMay 18 · 18:56 UTCCYBERSCOOP
    Interpol leads cybercrime crackdown across 13 countries in Middle East, North Africa

    Interpol led a cybercrime crackdown across 13 countries in the Middle East and North Africa, resulting in 201 arrests and the seizure of 53 servers. The operation, known as Operation Ramz, disrupted multiple cybercrime services and identified 382 suspects. The effort was supported by various countries and private sector partners.