organization · 10 records
Group-IB

Iranian Hacktivists Linked to Heavygram Telegram Surveillance Backdoor
Researchers link the Iran-affiliated Handala Hack group to HEAVYGRAM, a Telegram-based backdoor used to target dissidents and steal passwords.

Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks
The Gigabud banking trojan uses a tool called Vwork to create Android work profiles to evade security checks on infected devices.

Google Play Early Access Abused to Push Thousands of Deceptive Android Apps
Threat actors are abusing the Google Play Early Access program to distribute deceptive applications for ad revenue and fraudulent schemes.

BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory
Researchers identified BraZetsu, a Python-based Windows malware framework used by Initial Access Brokers to facilitate the sale of compromised system access on an underground marketplace.

Cybersecurity reports highlight phishing campaigns and data theft incidents
This bulletin summarizes several cybersecurity incidents and trends, including phishing campaigns, ransomware, data theft, and AI-related security risks.

Linux kernel update addresses vulnerability in action lifecycle management
CVE-2026-53264 disclosed: In the Linux kernel, the following vulnerability has been resolved: net/sched: act_api: use RCU with deferred freeing for action lifecycle When NEWTFILTER and DELFILTER are run concurrently it is po

Iranian hacking group deploys new malware against targets in South Asia
The Iranian state-backed hacking group Nimbus Manticore deployed the new NightLedger backdoor and tunneling tools against targets across the Middle East, Africa, and South Asia.

China-linked group targets global organizations with new malware loader
Group-IB analysis of an exposed Alibaba Cloud server revealed a China-nexus operation named JadeProx using the TriBack Loader to attack government, healthcare, and education organizations across Asia and Latin America.

Researchers identify new malware using Microsoft 365 calendar for covert communications
Group-IB researchers identified a new HollowGraph malware module that abuses Microsoft 365 calendar features as a covert command-and-control channel, likely linked to an Iranian threat actor targeting Israeli organizations.

New macOS ClickLock malware forces users to reveal passwords by closing apps
The ClickLock macOS infostealer uses a 210-millisecond process-killing loop to coerce victims into providing their login password, enabling the exfiltration of Keychain data, browser credentials, and crypto wallets, while evading recent Apple mitigations for malicious Terminal paste activity.