⤷ Title: UNC2891: Raspberry Pi, Custom Rootkit CAKETAP Fuel Sophisticated ATM Fraud Campaign
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 03:08:45 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ATM Fraud #CAKETAP #Financial Security #Group_IB #money mules #Raspberry Pi #rootkit #STEELCORGI #UNC2891
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 24 Nov 2025 03:08:45 +0000
════════════════════════
⌗ Tags: #Cybercriminals #ATM Fraud #CAKETAP #Financial Security #Group_IB #money mules #Raspberry Pi #rootkit #STEELCORGI #UNC2891
Penetration Testing Tools
UNC2891: Raspberry Pi, Custom Rootkit CAKETAP Fuel Sophisticated ATM Fraud Campaign
The UNC2891 campaign against Indonesian banks used a Raspberry Pi and the CAKETAP rootkit to bypass ATM verification protocols, orchestrating cash-outs via a mule network.
⤷ Title: Bloody Wolf Hackers Impersonate Government Agencies to Deploy NetSupport RAT in Central Asia
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 29 Nov 2025 02:43:41 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Bloody Wolf #Central Asia #Cyber Espionage #Government Impersonation #Group_IB #Kyrgyzstan #NetSupport RAT #phishing #Uzbekistan
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 29 Nov 2025 02:43:41 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Bloody Wolf #Central Asia #Cyber Espionage #Government Impersonation #Group_IB #Kyrgyzstan #NetSupport RAT #phishing #Uzbekistan
Penetration Testing Tools
Bloody Wolf Hackers Impersonate Government Agencies to Deploy NetSupport RAT in Central Asia
The “Bloody Wolf” group is expanding its targeted campaign across Central Asia, deploying NetSupport RAT and impersonating government
⤷ Title: GoldFactory Malware Injects FriHook/SkyHook into Banking Apps to Exploit 11K SE Asia Users
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 03:55:06 +0000
════════════════════════
⌗ Tags: #Malware #Accessibility Abuse #Android #FriHook #Gigabud #GoldFactory #Group_IB #Mobile Banking Malware #phishing #SkyHook #Southeast Asia
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 05 Dec 2025 03:55:06 +0000
════════════════════════
⌗ Tags: #Malware #Accessibility Abuse #Android #FriHook #Gigabud #GoldFactory #Group_IB #Mobile Banking Malware #phishing #SkyHook #Southeast Asia
Penetration Testing Tools
GoldFactory Malware Injects FriHook/SkyHook into Banking Apps to Exploit 11K SE Asia Users
The GoldFactory group has launched a new wave of attacks targeting mobile-banking users across Southeast Asia. Disguising themselves
❤1
⤷ Title: Wonderland Unleashed: New Android “Dropper” Malware Hijacks Telegram to Drain Bank Accounts
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:11:27 +0000
════════════════════════
⌗ Tags: #Malware #Android security #Banking Trojan #Cybercrime #Dropper Malware #Group_IB #mobile security #SMS Stealer #Telegram bot #Uzbekistan #Wonderland Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 23 Dec 2025 00:11:27 +0000
════════════════════════
⌗ Tags: #Malware #Android security #Banking Trojan #Cybercrime #Dropper Malware #Group_IB #mobile security #SMS Stealer #Telegram bot #Uzbekistan #Wonderland Malware
Daily CyberSecurity
Wonderland Unleashed: New Android “Dropper” Malware Hijacks Telegram to Drain Bank Accounts
A sophisticated wave of mobile malware is sweeping through Central Asia, marking a dangerous evolution in how cybercriminals target Android users. A new in-depth analysis by Group-IB reveals that …
⤷ Title: The Gig Trap: Group-IB Exposes 1,500+ Fake Job Ads Draining MENA Wallets
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 30 Dec 2025 03:01:42 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cybercrime 2025 #Fraud Prevention #Group_IB #Job Scam #MENA #Middle East #phishing #remote work #Social Engineering #Telegram
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 30 Dec 2025 03:01:42 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cybercrime 2025 #Fraud Prevention #Group_IB #Job Scam #MENA #Middle East #phishing #remote work #Social Engineering #Telegram
Penetration Testing Tools
The Gig Trap: Group-IB Exposes 1,500+ Fake Job Ads Draining MENA Wallets
Fraudulent job advertisements promising easy income and remote work continue to flood social media platforms, particularly across the
⤷ Title: “Ghost Tap” Rising: New Wave of Android Malware Turns Phones into Digital Pickpockets
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 00:11:17 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Android Malware #Cybercrime #financial fraud #Ghost Tap #Group_IB #mobile security #NFC Security #Telegram scams
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 00:11:17 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Android Malware #Cybercrime #financial fraud #Ghost Tap #Group_IB #mobile security #NFC Security #Telegram scams
Daily CyberSecurity
“Ghost Tap” Rising: New Wave of Android Malware Turns Phones into Digital Pickpockets
Your smartphone might be the only accomplice a thief needs to drain your bank account, even if your card never leaves your wallet. A new report from Group-IB reveals a surging underground market f…
⤷ Title: The Ghost in the Terminal: How “Ghost Tap” Malware Hijacks Your NFC Card
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 12 Jan 2026 08:07:46 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Android malware #Contactless Fraud #Cybercrime 2026 #Ghost Tap #Group_IB #mobile security #NFC Relay #NFU Pay #Point of Sale #TX_NFC
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 12 Jan 2026 08:07:46 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Android malware #Contactless Fraud #Cybercrime 2026 #Ghost Tap #Group_IB #mobile security #NFC Relay #NFU Pay #Point of Sale #TX_NFC
Information Security News
The Ghost in the Terminal: How “Ghost Tap” Malware Hijacks Your NFC Card
Group-IB researchers have identified a burgeoning proliferation of Android malware within subterranean marketplaces designed to exploit Near Field Communication (NFC) technology for fraudulent con…
⤷ Title: The Blockchain Ghost: DeadLock Ransomware Uses Smart Contracts to Defy Bans
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 16 Jan 2026 03:26:22 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BYOVD #Cisco Talos #Cyber Security 2026 #DeadLock #EtherHiding #Group_IB #Infosec News #Polygon Blockchain #ransomware #Session App #smart contracts
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 16 Jan 2026 03:26:22 +0000
════════════════════════
⌗ Tags: #Cybercriminals #BYOVD #Cisco Talos #Cyber Security 2026 #DeadLock #EtherHiding #Group_IB #Infosec News #Polygon Blockchain #ransomware #Session App #smart contracts
Penetration Testing Tools
The Blockchain Ghost: DeadLock Ransomware Uses Smart Contracts to Defy Bans
The DeadLock syndicate, which emerged within the cyber threat landscape during the summer of 2025, persists as one
⤷ Title: DeadLock Ransomware: New Strain Hides C2 in Polygon Smart Contracts
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 16 Jan 2026 02:10:20 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Blockchain security #C2 Infrastructure #Cyber Security #DeadLock #EtherHiding #Group_IB #Polygon Network #ransomware #Session Messenger #smart contracts
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 16 Jan 2026 02:10:20 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Blockchain security #C2 Infrastructure #Cyber Security #DeadLock #EtherHiding #Group_IB #Polygon Network #ransomware #Session Messenger #smart contracts
Daily CyberSecurity
DeadLock Ransomware: New Strain Hides C2 in Polygon Smart Contracts
A new ransomware family is turning the decentralized dream of blockchain into a cybersecurity nightmare. Analysts at Group-IB have uncovered DeadLock, a ransomware strain discovered in July 2025 t…
⤷ Title: The Invisible Landlord: ShadowSyndicate Rotates Keys to Hide Infrastructure
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 06 Feb 2026 00:42:35 +0000
════════════════════════
⌗ Tags: #Cybercriminals #bulletproof hosting #C2 Servers #Cobalt Strike #Cybercrime #Group_IB #initial access broker #Ransomware Infrastructure #ShadowSyndicate #SSH Key Rotation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 06 Feb 2026 00:42:35 +0000
════════════════════════
⌗ Tags: #Cybercriminals #bulletproof hosting #C2 Servers #Cobalt Strike #Cybercrime #Group_IB #initial access broker #Ransomware Infrastructure #ShadowSyndicate #SSH Key Rotation
Daily CyberSecurity
The Invisible Landlord: ShadowSyndicate Rotates Keys to Hide Infrastructure
Group-IB reveals ShadowSyndicate is evolving. The cybercrime cluster now rotates SSH keys to hide its infrastructure. Is it a BPH or IAB?