Vesta Matveeva Group-IB

Vesta Matveeva

Head of High-Tech Crime Investigation Department, APAC

Vesta Matveeva has contributed her expertise in digital forensics, incident response, and cyber investigations in various high-profile cybercrime cases and joint operations with INTERPOL and APAC law enforcement agencies. Her recent cases include identifying threat actors behind Database Leaks sold on the Dark Web, uncovering phishing campaigns, tracking the spread of Android Banking Trojans in the region, investigating Invest Scam activities, and combating Ransomware attacks. Committed to public-private sector collaborations and knowledge sharing.

Vesta holds a scientific degree and her current passion is to leverage her extensive experience in applying ML-techniques to expedite cyber investigations in the Dark Web as well as Anti-fraud initiatives. Vesta also regularly conducts extensive training in cyber investigations for cybersecurity specialists such as SOC and Threat Intelligence teams as well as police agencies.

Her pioneering contributions and innovative work have garnered recognition including a grant from Singapore’s Cybersecurity Agency. Her advocacy for championing women in cybersecurity has earned her ‘Top Women in Security ASEAN ‘ awards multiple times, and affirmed her role in shaping a safer digital world.

Blog posts by Vesta Matveeva

Cyber Investigations
March 20, 2025
The Cybercriminal with Four Faces: Revealing Group-IB’s Investigation into ALTDOS, DESORDEN, GHOSTR and 0mid16B
Following the arrest of the cybercriminal behind the aliases ALTDOS, DESORDEN, GHOSTR, and 0mid16B, Group-IB provides a deep dive into his activities, uncovering striking similarities and unmasking the cybercriminal that breached more than 90 instances of data leaks worldwide over the span of four years in operation.
Tracing the Path of VietCredCare and DuckTail
Cyber Investigations
November 21, 2024
Tracing the Path of VietCredCare and DuckTail: Vietnamese dark market of infostealers’ data
Following the arrest in May 2024 of more than 20 individuals behind Facebook infostealers campaigns in Vietnam, we have compared the tactics of operators behind VietCredCare and DuckTail stealers. These 2 malware families have been active before the arrest in Vietnam and are believed to be controlled by Vietnamese threat actors. Based on the research, we decided that the groups operate in a different way and the arrest probably affected the VietCredCare operators.
Deciphering the Brain Cipher Ransomware blog cover
Ransomware
August 14, 2024
Deciphering the Brain Cipher Ransomware
Deep dive into Brain Cipher ransomware group's activities and techniques, and how they are seemingly linked to other ransomware groups such as EstateRansomware and SenSayQ
Cyber Investigations
February 21, 2024
Extra credit: VietCredCare information stealer takes aim at Vietnamese businesses
Group-IB discovers new information stealer targeting Vietnam with rare functionality to filter out Facebook accounts with advertising credits
Cyber Investigations
January 28, 2022
Shedding light on the dark web
Cybersecurity analyst's guide on how to use machine learning to show cybercriminals' true colors
Threat Intelligence
August 15, 2017
Secrets of Cobalt
How Cobalt hackers bypass your defenses