⤷ Title: The Ghost in the Terminal: How “Ghost Tap” Malware Hijacks Your NFC Card
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 12 Jan 2026 08:07:46 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Android malware #Contactless Fraud #Cybercrime 2026 #Ghost Tap #Group_IB #mobile security #NFC Relay #NFU Pay #Point of Sale #TX_NFC
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 12 Jan 2026 08:07:46 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Android malware #Contactless Fraud #Cybercrime 2026 #Ghost Tap #Group_IB #mobile security #NFC Relay #NFU Pay #Point of Sale #TX_NFC
Information Security News
The Ghost in the Terminal: How “Ghost Tap” Malware Hijacks Your NFC Card
Group-IB researchers have identified a burgeoning proliferation of Android malware within subterranean marketplaces designed to exploit Near Field Communication (NFC) technology for fraudulent con…
⤷ Title: The Blockchain Ghost: DeadLock Ransomware Uses Smart Contracts to Defy Bans
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 16 Jan 2026 03:26:22 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BYOVD #Cisco Talos #Cyber Security 2026 #DeadLock #EtherHiding #Group_IB #Infosec News #Polygon Blockchain #ransomware #Session App #smart contracts
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 16 Jan 2026 03:26:22 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BYOVD #Cisco Talos #Cyber Security 2026 #DeadLock #EtherHiding #Group_IB #Infosec News #Polygon Blockchain #ransomware #Session App #smart contracts
Penetration Testing Tools
The Blockchain Ghost: DeadLock Ransomware Uses Smart Contracts to Defy Bans
The DeadLock syndicate, which emerged within the cyber threat landscape during the summer of 2025, persists as one
⤷ Title: DeadLock Ransomware: New Strain Hides C2 in Polygon Smart Contracts
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 16 Jan 2026 02:10:20 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Blockchain security #C2 Infrastructure #Cyber Security #DeadLock #EtherHiding #Group_IB #Polygon Network #ransomware #Session Messenger #smart contracts
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 16 Jan 2026 02:10:20 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Blockchain security #C2 Infrastructure #Cyber Security #DeadLock #EtherHiding #Group_IB #Polygon Network #ransomware #Session Messenger #smart contracts
Daily CyberSecurity
DeadLock Ransomware: New Strain Hides C2 in Polygon Smart Contracts
A new ransomware family is turning the decentralized dream of blockchain into a cybersecurity nightmare. Analysts at Group-IB have uncovered DeadLock, a ransomware strain discovered in July 2025 t…
⤷ Title: The Invisible Landlord: ShadowSyndicate Rotates Keys to Hide Infrastructure
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 06 Feb 2026 00:42:35 +0000
════════════════════════
⌗ Tags: #Cybercriminals #bulletproof hosting #C2 Servers #Cobalt Strike #Cybercrime #Group_IB #initial access broker #Ransomware Infrastructure #ShadowSyndicate #SSH Key Rotation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 06 Feb 2026 00:42:35 +0000
════════════════════════
⌗ Tags: #Cybercriminals #bulletproof hosting #C2 Servers #Cobalt Strike #Cybercrime #Group_IB #initial access broker #Ransomware Infrastructure #ShadowSyndicate #SSH Key Rotation
Daily CyberSecurity
The Invisible Landlord: ShadowSyndicate Rotates Keys to Hide Infrastructure
Group-IB reveals ShadowSyndicate is evolving. The cybercrime cluster now rotates SSH keys to hide its infrastructure. Is it a BPH or IAB?
⤷ Title: Industrialized Theft: GoldFactory Malware Hijacks Tax Season via Fake ‘Coretax’ Apps
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 23 Feb 2026 00:06:26 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Coretax Fraud #Gigabud.RAT #GoldFactory #Group_IB #MaaS #Malware_as_a_Service #MMRat #Mobile Banking Fraud #social engineering #Vishing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 23 Feb 2026 00:06:26 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Coretax Fraud #Gigabud.RAT #GoldFactory #Group_IB #MaaS #Malware_as_a_Service #MMRat #Mobile Banking Fraud #social engineering #Vishing
Daily CyberSecurity
Industrialized Theft: GoldFactory Malware Hijacks Tax Season via Fake 'Coretax' Apps
Group-IB exposes an industrialized mobile banking fraud campaign in Indonesia. GoldFactory hackers use fake Coretax apps and Gigabud.RAT to drain accounts.
⤷ Title: The Taxman’s Shadow: How a $2M Fraud Syndicate Impersonated Indonesia’s Official Coretax Service
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 23 Feb 2026 03:21:39 +0000
════════════════════════
⌗ Tags: #Cybercriminals #accessibility services abuse #Android malware #Coretax Indonesia #DJP Online #Gigabud.RAT #GoldFactory #Group_IB #MMRat #Taotie Trojan #tax fraud 2026 #Vishing
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 23 Feb 2026 03:21:39 +0000
════════════════════════
⌗ Tags: #Cybercriminals #accessibility services abuse #Android malware #Coretax Indonesia #DJP Online #Gigabud.RAT #GoldFactory #Group_IB #MMRat #Taotie Trojan #tax fraud 2026 #Vishing
Penetration Testing Tools
The Taxman’s Shadow: How a $2M Fraud Syndicate Impersonated Indonesia’s Official Coretax Service
In Indonesia, a sophisticated fraudulent enterprise has been unmasked, masquerading as the official Coretax fiscal service. Adversaries orchestrated
⤷ Title: Operation Olalampo: MuddyWater Unleashes AI-Assisted Rust Malware and Telegram C2 in MENA Espionage Surge
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 24 Feb 2026 00:37:38 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #AI_Assisted Malware #CHAR Backdoor #GhostBackDoor #GhostFetch #Group_IB #MENA Cyber Espionage #MuddyWater APT #Operation Olalampo #Telegram C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 24 Feb 2026 00:37:38 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #AI_Assisted Malware #CHAR Backdoor #GhostBackDoor #GhostFetch #Group_IB #MENA Cyber Espionage #MuddyWater APT #Operation Olalampo #Telegram C2
Daily CyberSecurity
Operation Olalampo: MuddyWater Unleashes AI-Assisted Rust Malware and Telegram C2 in MENA Espionage Surge
Group-IB exposes Operation Olalampo: MuddyWater's new MENA campaign using AI-assisted Rust malware (CHAR) and Telegram bots for stealthy C2 communication.
⤷ Title: The GTFire Scheme: How Cybercriminals are Weaponizing Google’s Trusted Services for Global Phishing
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Mar 2026 00:33:13 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Credential Harvesting #Evasion Tactics #Google Firebase #Google Translate #Group_IB #GTFire #infosec #phishing #SaaS Abuse #threat intelligence #web app
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Mar 2026 00:33:13 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Credential Harvesting #Evasion Tactics #Google Firebase #Google Translate #Group_IB #GTFire #infosec #phishing #SaaS Abuse #threat intelligence #web app
Daily CyberSecurity
The GTFire Scheme: How Cybercriminals are Weaponizing Google’s Trusted Services for Global Phishing
Group-IB uncovers "GTFire," a massive credential-harvesting operation abusing Google Firebase and Translate to bypass security filters in 100+ countries.
⤷ Title: The Global Takedown: Interpol’s Operation Synergia III Crushes 45,000 Malicious Servers
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 17 Mar 2026 09:48:21 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cybercrime Crackdown #Global Security #Group_IB #International Law Enforcement #Interpol #IP Takedown #Operation Synergia III #phishing #ransomware #S2W #Trend Micro
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 17 Mar 2026 09:48:21 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cybercrime Crackdown #Global Security #Group_IB #International Law Enforcement #Interpol #IP Takedown #Operation Synergia III #phishing #ransomware #S2W #Trend Micro
Penetration Testing Tools
The Global Takedown: Interpol’s Operation Synergia III Crushes 45,000 Malicious Servers
An international law enforcement crusade against cybercriminality has yielded monumental results. Constabularies spanning dozens of sovereign nations have
⤷ Title: Unmasking the Phoenix System’s Rogue BTS Smishing Empire
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 01 May 2026 08:29:36 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybersecurity #Group_IB #infosec #Live_Phishing #MFA Bypass #Mouse System #OTP Interception #Phishing_as_a_Service #Phoenix System #Rogue BTS #smishing #Telegram fraud
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 01 May 2026 08:29:36 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cybersecurity #Group_IB #infosec #Live_Phishing #MFA Bypass #Mouse System #OTP Interception #Phishing_as_a_Service #Phoenix System #Rogue BTS #smishing #Telegram fraud
Daily CyberSecurity
Unmasking the Phoenix System’s Rogue BTS Smishing Empire
Group-IB unmasks the Phoenix System: a PhaaS platform using rogue cell towers and live-dashboards to bypass MFA across 2,500+ domains. Read the full report.
⤷ Title: Decade-Long SniperDz Phishing Network Disrupted in Operation Ramz
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Thu, 11 Jun 2026 16:18:37 +0000
════════════════════════
⌗ Tags: #Cyber Crime #Phishing Scam #Security #Algeria #Cybersecurity #Group_IB #Interpol #JokerDz #Operation Ramz #Phishing #SniperDz #SpamDz #StormDz
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Thu, 11 Jun 2026 16:18:37 +0000
════════════════════════
⌗ Tags: #Cyber Crime #Phishing Scam #Security #Algeria #Cybersecurity #Group_IB #Interpol #JokerDz #Operation Ramz #Phishing #SniperDz #SpamDz #StormDz
Hackread
Decade-Long SniperDz Phishing Network Disrupted in Operation Ramz
Group-IB, INTERPOL and Algerian Police dismantle decade-old SniperDZ phishing network used to steal credentials, with its alleged developer arrested.
⤷ Title: SilabRAT Malware: The $5,000-a-Month Crypto-Hunting RAT Hiding Behind HijackLoader
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 07:22:05 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #cryptocurrency #Group_IB #HijackLoader #HVNC #Malware_as_a_Service #rat #SilabRAT #SnappyClient
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 17 Jun 2026 07:22:05 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #cryptocurrency #Group_IB #HijackLoader #HVNC #Malware_as_a_Service #rat #SilabRAT #SnappyClient
Daily CyberSecurity
SilabRAT Malware: The $5,000-a-Month Crypto-Hunting RAT Hiding Behind HijackLoader
SilabRAT malware, aka SnappyClient, is a $5K/month MaaS RAT flagged as HijackLoader. It uses HVNC and cracks crypto wallets, per Group-IB.
⤷ Title: ClickLock Stealer Locks macOS Screens Until Victims Hand Over Their Password
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 21 Jul 2026 06:26:00 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #ClickLock Stealer #crypto wallet #Group_IB #GSocket #Infostealer #macOS Malware #Telegram C2
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 21 Jul 2026 06:26:00 +0000
════════════════════════
⌗ Tags: #Malware #ClickFix #ClickLock Stealer #crypto wallet #Group_IB #GSocket #Infostealer #macOS Malware #Telegram C2
Daily CyberSecurity
ClickLock Stealer Locks macOS Screens Until Victims Hand Over Their Password
At a glance Malware family ClickLock Stealer (new, named by Group-IB) Threat actor Unattributed. No actor or group named. Target / victims macOS users, especially crypto holders. At least 100 vict…
⤷ Title: HollowGraph Malware Exploits Microsoft 365 Calendars
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Wed, 22 Jul 2026 14:03:50 +0000
════════════════════════
⌗ Tags: #Malware #APT #Cyber Espionage #Group_IB #HollowGraph #Microsoft 365
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Wed, 22 Jul 2026 14:03:50 +0000
════════════════════════
⌗ Tags: #Malware #APT #Cyber Espionage #Group_IB #HollowGraph #Microsoft 365
Information Security News
HollowGraph Malware Exploits Microsoft 365 Calendars
Unveiling the HollowGraph Threat A cloud calendar can conceal far more than mundane appointments; the HollowGraph malware exploits Microsoft 365 to clandestinely receive commands and transmit pilf…
⤷ Title: JadeProx Exposed: Unveiling TriBack Loader & China-Nexus C2 Infrastructure
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Sun, 26 Jul 2026 13:45:18 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT #Cyber Espionage #Group_IB #JadeProx #TriBack Loader
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Sun, 26 Jul 2026 13:45:18 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT #Cyber Espionage #Group_IB #JadeProx #TriBack Loader
Information Security News
JadeProx Exposed: Unveiling TriBack Loader & China-Nexus C2 Infrastructure
An Unprotected Directory Exposes Espionage Operations A single overlooked server misconfiguration inadvertently exposed the inner workings of an entire China-nexus cyber espionage infrastructure. …
⤷ Title: JadeProx Used TriBack Loader Against a Vietnamese Hospital, Malaysia’s Foreign Ministry, and Hong Kong Schools
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 28 Jul 2026 07:15:27 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AdaptixC2 #Beagle backdoor #China_nexus #DLL Sideloading #Group_IB #JadeProx #TriBack Loader
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 28 Jul 2026 07:15:27 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AdaptixC2 #Beagle backdoor #China_nexus #DLL Sideloading #Group_IB #JadeProx #TriBack Loader
Daily CyberSecurity
JadeProx Used TriBack Loader Against a Vietnamese Hospital, Malaysia’s Foreign Ministry, and Hong Kong Schools
At a Glance Actor or group JadeProx, a China-nexus cluster named by Group-IB; no known group named Activity type Espionage-style intrusions, phishing, credential harvesting, tunnelling Targets A V…
⤷ Title: XMRig Botnet Abuses Linux PAM to Spread Forensic Smokescreen Across User Accounts
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 07:10:58 +0000
════════════════════════
⌗ Tags: #Malware #Cryptomining Botnet #Fileless Malware #Group_IB #Linux Malware #Monero #PAM Abuse #supply chain attack #XMRig
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 07:10:58 +0000
════════════════════════
⌗ Tags: #Malware #Cryptomining Botnet #Fileless Malware #Group_IB #Linux Malware #Monero #PAM Abuse #supply chain attack #XMRig
Daily CyberSecurity
XMRig Botnet Abuses Linux PAM to Spread Forensic Smokescreen Across User Accounts
At a glance Field Detail Malware family Modified XMRig 6.25.0 botnet implant (marked “PRIVATE VERSION FOR BOTNET”), cross-compiled with musl libc Threat actor Unidentified; campaign tr…
⤷ Title: WindRelay and SpyNote RAT Combo Turns Android Into NFC Card Relay for Bank Fraud
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 07:19:09 +0000
════════════════════════
⌗ Tags: #Malware #Android malware #Bank Fraud #Group_IB #NFC Relay #Remote Access Trojan #SpyNote #WindRelay
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Sat, 15 Aug 2026 07:19:09 +0000
════════════════════════
⌗ Tags: #Malware #Android malware #Bank Fraud #Group_IB #NFC Relay #Remote Access Trojan #SpyNote #WindRelay
Information Security News
WindRelay and SpyNote RAT Combo Turns Android Into NFC Card Relay for Bank Fraud
A single phone call with a fraudster can now result, within the same session, in a loan taken out in the victim’s name and unauthorized purchases charged to their bank card. Researchers at G…