Insurance Trap in Colombia
Over 100 cloned car-insurance websites exploited open data and sleek UX to trick users into giving away banking credentials—highlighting how public infrastructure can be weaponized for fraud.
Ransomware Debris
Group-IB dissects the rise and mysterious disappearance of RansomHub, an offshoot of Knight/Cyclops, which lured ex-LockBit and ALPHV affiliates with a 90/10 profit share—only to vanish by April 1, 2025. Many of its operators have now reportedly joined Qilin.
Defending Against UNC3944 ("Scattered Spider")
Google/Mandiant’s latest threat hardening tips offer a 5-step guide to counter SIM-swapping and ransomware threats—focusing on device health, phishing-proof MFA, and attack detection.
DarkBlinders APT Emerges in Iraq
Group-IB identified DarkBlinders, a new suspected nation-state APT using SHELBY malware. The campaign, uncovered via VirusTotal submissions from Iraq, shows a sophisticated threat with geopolitical undertones.
Download the Full Report
Get exclusive access to detailed analysis, statistics, and expert recommendations.