Get 24/7 incident response assistance from our global team
- APAC: +65 3159 4398
- EU & NA: +31 20 890 55 59
- MEA: +971 4 540 6400
- LATAM: +56 2 275 473 79
Get 24/7 incident response assistance from our global team
Ransomware spreads quickly across networks, exploiting vulnerabiliti...
Explore solutions
Effectively safeguard your business assets against unseen risks...
Explore solutions
Your guide to AI innovation, adoption, and acceleration in cybersecurity

Modern fraud isn't an event. It's an industrialised campaign that begins weeks before the payment. The transaction is where fraud ends, not where it happens. This paper shows how to disrupt the campaign weeks before the payment, not document it after.
Your guide to AI innovation, adoption, and acceleration in cybersecurity
Learn more
In October 2017, Group-IB’s Threat Intelligence (TI) specialists detected the activity of the threat actor known as Fxmsp, who at the time was starting to sell access to various corporate networks belonging to different companies around the world.
On-Demand
39 min
· July 2, 2020

In just over three years, Fxmsp managed to penetrate networks in more than 44 countries and put access to 135 networks on sale on underground forums. Group-IB estimates that Fxmsp made at least $1.5 million while active. Group-IB’s TI specialists tracked Fxmsp’s movements in the Russian-speaking underground from the moment he registered on the first forum in September 2016 to when he ceased all public activity in 2019.