Group-IB
Coverage of Group-IB in the Nexus archive.
- New Android malware lets criminals use your bank card in real time
Researchers at Group-IB discovered "WindRelay," a new NFC relay malware family designed to capture live card data and forward it in real time to attackers. The attack process involves tricking victims into installing an Android remote access Trojan (RAT) called SpyNote, which then enables the theft of contactless payment details from physical cards. This technology allows criminals to make purchases or withdraw cash remotely using dynamic transaction-specific codes.
- ClickLock Mac malware locks apps until you give in
ClickLock is a Mac malware that tricks users into running a Terminal command, leading to data theft and remote access. Discovered by Group-IB, it has infected over 100 systems across 33 countries by stealing passwords, browser data, and cryptocurrency wallet files.
- New ClickLock Stealer locks your Mac until you hand over your password
ClickLock Stealer is a macOS infostealer delivered via phishing pages that locks victims' Macs by terminating processes, stealing passwords, browser data, and cryptocurrency wallets. It employs a GSocket backdoor for persistent remote access and forces users to submit their macOS password via a fake prompt, with a kill loop disabling system functions until compliance.
- HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
HollowGraph malware, discovered by Group-IB, uses hijacked Microsoft 365 calendars as a command channel, hiding operator instructions and stolen files in calendar events dated 2050. The malware leverages Microsoft Graph API traffic to blend malicious activity with legitimate traffic.
- Sniper Dz Scams Target MENA Users via Fake Facebook Offers and Browser Alerts
Cybersecurity researchers have identified scams targeting Middle East and North Africa (MENA) users through fake Facebook accounts impersonating politicians, public figures, and trusted organizations. These accounts promoted fraudulent offers, including free mobile internet packages, financial compensation, and government subsidy programs.
- Interpol leads cybercrime crackdown across 13 countries in Middle East, North Africa
Interpol led a cybercrime crackdown across 13 countries in the Middle East and North Africa, resulting in 201 arrests and the seizure of 53 servers. The operation, known as Operation Ramz, disrupted multiple cybercrime services and identified 382 suspects. The effort was supported by various countries and private sector partners.