Andrey Polovinkin

Team Lead Reverse Research, APAC

Andrey is a cybersecurity expert with a talent for exploring the depths of malware. Based in our Thailand office, Andrey analyzes advanced threat groups and hunts for active malware families. His notable achievements include discovering iOS malware attributed to GoldFactory and identifying the WinRAR vulnerability CVE-2023-38831. Before he joined Group-IB in 2018, Andrey worked as a C/C++ software engineer and developed various solutions. Andrey holds a Master’s degree in Security and Network Engineering.

Awards and recognitions

Andrey holds multiple Group-IB achievement coins for his outstanding contributions to threat research and product development:

RedCurl challenge coin - For contributing to the report on the hacker group RedCurl

RedCurl challenge coin – For contributing to the report on the hacker group RedCurl

GIB Star Achievement coin

GIB STAR challenge coin – For significant achievements, large-scale projects, and developing new lines of business throughout the year

Conti Armada challenge coin - For contributing to the report on the ransomware group Conti

Conti Armada challenge coin – For contributing to the report on the ransomware group Conti

OldGremlin challenge coin – For investigating incidents, carrying out threat intelligence, and contributing to the OldGremlin report

Threat Intelligence & Attribution challenge coin – For helping develop Group-IB Threat Intelligence

Blog posts by Andrey Polovinkin

Gold factory
Malware Analysis
December 3, 2025
Hook for Gold: Inside GoldFactory’s Сampaign That Turns Apps Into Goldmines
A deep dive into GoldFactory’s evolving mobile fraud campaigns across APAC, including modified banking apps, new malware variants such as Gigaflower, shared criminal infrastructure, and insights from the Group-IB Fraud Matrix, with recommendations for organizations and end users.
Pig Butchering Blog Banner
Scam & Phishing
October 2, 2024
Pig Butchering Alert: Fraudulent Trading App targeted iOS and Android users
In this article, Group-IB specialists uncovered a large-scale fraud campaign involving fake trading apps targeting Apple iOS and Android users across multiple regions through the UniApp framework, and distributed through official app stores and phishing sites.
GoldDigger family
Malware Analysis
February 15, 2024
Face Off: Group-IB identifies first iOS trojan stealing facial recognition data
Group-IB uncovers the first iOS Trojan harvesting facial recognition data used for unauthorized access to bank accounts. The GoldDigger family grows
Threat Intelligence
August 23, 2023
Traders’ dollars in danger: CVE-2023-38831 zero-day vulnerability in WinRAR exploited by cybercriminals to target traders
Spoof extensions help cybercriminals target users on trading forums as 130 devices still infected at time of writing
Advanced Persistent Threats
May 31, 2023
Dark Pink. Episode 2
APT Dark Pink is back with 5 victims in new countries.
Advanced Persistent Threats
January 11, 2023
Dark Pink
New APT hitting Asia-Pacific, Europe that goes deeper and darker