Skip to content

organization · 10 records

Group-IB

  • Photo: The Hacker News
    Tech & Cyber

    Iranian Hacktivists Linked to Heavygram Telegram Surveillance Backdoor

    Researchers link the Iran-affiliated Handala Hack group to HEAVYGRAM, a Telegram-based backdoor used to target dissidents and steal passwords.

    1 outlet
  • Photo: The Hacker News
    Tech & Cyber

    Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks

    The Gigabud banking trojan uses a tool called Vwork to create Android work profiles to evade security checks on infected devices.

    1 outlet Markets read
  • Photo: The Hacker News
    Tech & Cyber

    Google Play Early Access Abused to Push Thousands of Deceptive Android Apps

    Threat actors are abusing the Google Play Early Access program to distribute deceptive applications for ad revenue and fraudulent schemes.

    1 outlet
  • Photo: The Hacker News
    Tech & Cyber

    BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory

    Researchers identified BraZetsu, a Python-based Windows malware framework used by Initial Access Brokers to facilitate the sale of compromised system access on an underground marketplace.

    1 outlet Markets read
  • Photo: The Hacker News
    Tech & Cyber

    Cybersecurity reports highlight phishing campaigns and data theft incidents

    This bulletin summarizes several cybersecurity incidents and trends, including phishing campaigns, ransomware, data theft, and AI-related security risks.

    1 outlet
  • Photo: The Hacker News
    Tech & Cyber

    Linux kernel update addresses vulnerability in action lifecycle management

    CVE-2026-53264 disclosed: In the Linux kernel, the following vulnerability has been resolved: net/sched: act_api: use RCU with deferred freeing for action lifecycle When NEWTFILTER and DELFILTER are run concurrently it is po

    2 outlets Cyber read
  • Photo: The Hacker News
    Tech & Cyber

    Iranian hacking group deploys new malware against targets in South Asia

    The Iranian state-backed hacking group Nimbus Manticore deployed the new NightLedger backdoor and tunneling tools against targets across the Middle East, Africa, and South Asia.

    1 outlet
  • Photo: The Hacker News
    Tech & Cyber

    China-linked group targets global organizations with new malware loader

    Group-IB analysis of an exposed Alibaba Cloud server revealed a China-nexus operation named JadeProx using the TriBack Loader to attack government, healthcare, and education organizations across Asia and Latin America.

    1 outlet Cyber read
  • Photo: The Hacker News
    Tech & Cyber

    Researchers identify new malware using Microsoft 365 calendar for covert communications

    Group-IB researchers identified a new HollowGraph malware module that abuses Microsoft 365 calendar features as a covert command-and-control channel, likely linked to an Iranian threat actor targeting Israeli organizations.

    2 outlets
  • Photo: The Hacker News
    Tech & Cyber

    New macOS ClickLock malware forces users to reveal passwords by closing apps

    The ClickLock macOS infostealer uses a 210-millisecond process-killing loop to coerce victims into providing their login password, enabling the exfiltration of Keychain data, browser credentials, and crypto wallets, while evading recent Apple mitigations for malicious Terminal paste activity.

    1 outlet
  • Group-IB — every record | Prism