Anastasia Tikhonova

Global Threat Research Lead

Anastasia brings over 10 years of experience in researching financially motivated cybercrime. Specializing in tracking and analyzing APT activities by nation-state hackers, Anastasia leads her team in uncovering evolving tactics, techniques, and procedures (TTPs), exploring C&C infrastructures, and conducting in-depth malware analysis. Besides her research, Anastasia is an active participant in the APAC cybersecurity community, contributing to various interviews, webinars, and conferences, including the OT-ISAC Summit, Asia Pacific FS-ISAC Summit, and Govware. Her blend of technical expertise and community engagement makes her a notable figure in the field of cyber intelligence.

Awards and recognitions

Anastasia holds multiple Group-IB achievement coins for her outstanding contributions to threat research and product development:

PR-MAchine achievement

PR MACHINE challenge coin

Comrade

Comrade Fest 2021 challenge coin

Blog posts by Anastasia Tikhonova

Threat Landscape Overview
March 13, 2026
Six Supply Chain Attack Groups to Watch Out for in 2026
Who's attacking your vendors? Read about the six main supply chain attack groups who are driving SaaS, open-source, and MSP compromise in 2026. Learn how npm supply chain attacks threaten your security today, based on threat intelligence collected by Group-IB.
DocuSign Impersonation Wave
Email Protection Spotlight
January 5, 2026
The DocuSign Impersonation Wave with Real-Time Customizable LogoKit
Learn how Group-IB’s Business Email Protection stops the growing wave of DocuSign impersonation before users are exposed, and protects them from credential-capturing websites built with real-time customizable LogoKit.
Email Protection Spotlight
October 31, 2025
Detecting the NPM Supply Chain Compromise Before It Spread
Discover how Group-IB’s Business Email Protection (BEP) could prevent an NPM supply chain compromise by detecting the initial phishing email that led to the developer’s infection.
Advanced Persistent Threats
February 13, 2023
Nice Try Tonto Team
How a nation-state APT attempted to attack Group-IB
Threat Intelligence
June 16, 2022
Thousands of IDs exposed in yet another data breach in Brazil
Unsecured public-facing database allowed anyone to access ID selfies for months
Advanced Persistent Threats
August 3, 2021
The Art of Cyberwarfare
Chinese APTs attack Russia
Threat Intelligence
November 5, 2019
RDoS attacks by fake Fancy Bear hit banks in multiple locations
Group-IB experts have detected a massive email campaign spreading similar ransom demands sent to banks and financial organizations across the word.
Threat Intelligence
May 29, 2019
Catching fish in muddy waters
How the hacker group MuddyWater attacked a Turkish manufacturer of military electronics