Research by: hasherezade Key Points Since early 2025, Check Point Research has been tracking JSCeal, a sophisticated cryptocurrency-focused stealer with broader credential-theft, surveillance, and traffic-interception capabilities, delivered as compiled V8 bytecode (JSC files). The payloads are protected with javascript-obfuscator, using multiple techniques including RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers. Our goal was to recover the code to a…
Two Nigerian men extradited to the U.S. on Thursday have been charged with involvement in sextortion schemes that resulted in the deaths of two minor victims in Mississippi and North Carolina. [...]
Multiple extensions for Google Chrome and Microsoft Edge delivered a malware framework that deployed modules to steal cryptocurrency, sensitive data, and browser history, as well as inject ClickFix lures. [...]
Uživatelé iPhonů se stávají terčem nového podvodu vydávajícího se za technickou podporu, který se je snaží oklamat pomocí falešného upozornění na platbu přes Apple Pay. Na podvodné webové stránce se zobrazí upozornění, které věrohodně napodobuje systémovou notifikaci telefonu a průběh platby přes Apple Pay, včetně údajného ověřování pomocí Face ID a dalších běžných bezpečnostních prvků. Následuje varování o zablokování Apple ID a výzva ke kontaktování falešné podpory Apple. Stránka navíc dokáže…
Recently, we found a listing on BuzzFeed from someone pretending to be Malwarebytes Support. It reminded us why we need to be cautious about content on platforms where anyone can create an entry. Based on the phone number, we suspect the people behind this listing are trying to draw callers into a tech support scam. The scammer may use social engineering to persuade victims to grant remote access to their devices. This is not Malwarebytes’ phone number At first glance, this kind of lure can…
Group-IB expone una operación mexicana de PhaaS dirigida a más de 20 instituciones financieras, con capacidades de phishing en tiempo real, vishing con IA y RAT para dispositivos móviles.
Researchers have uncovered ToxicPanda 2.0, an Android banking Trojan and remote-access tool designed for account takeover and “on-device fraud.” Not only does ToxicPanda 2.0 have a much larger target list of banks and e-wallets, it has also expanded its capabilities by combining banking overlays, remote access, PIN capture, Android accessibility abuse, and attempted Wireless Debugging automation. Together, those functions can help operators turn a compromised phone into a platform for account…
UAT-10147 is a highly capable Chinese-speaking intrusion actor operating a multi-platform post-exploitation ecosystem targeting IIS and Linux servers, combining search engine optimization (SEO) fraud monetization with advanced persistence and defense evasion techniques. The newly identified SPECTRE implant represents a significant evolution in commodity intrusion tooling, integrating cross-platform command-and-control (C2) operations, process injection, credential theft, anti-analysis…
We identified a network of 41 websites impersonating popular games and Windows software, all designed to push visitors towards the same Download Studio installer. The sites advertise everything from Counter-Strike, Half-Life, Fallout, Roblox, PUBG, and The Witcher to VLC, 7-Zip, Paint.NET, VMware, Total Commander, and Foxit PDF. They go to surprising lengths to look convincing, using accurate product information, genuine developer resources, and even real download links. But the link you see…
Scammers are creating fake crypto wallet-checking sites that promise to tell you whether a wallet is linked to suspicious activity. Instead, they try to trick you into giving them access to your crypto. What real AML checking looks like AML stands for anti-money laundering. These are rules that require banks and other regulated businesses to screen customers for ties to crime. It’s designed to prevent cybercriminals from hiding or moving illegally obtained money. In the crypto world, this…
Most wrong-number texts are harmless. Some are the first step in a carefully planned scam. By replying, you may be confirming that your number is active and that you’re willing to engage with strangers, making you a more valuable target for future fraud. Here’s why a polite response can be worth money to cybercriminals. The politeness trap Sunday night. You’re on the couch, half-watching Netflix, when your phone buzzes. “Hey! Are we still on for dinner tomorrow? Don’t forget the wine ” You…
Researchers at Group-IB have discovered a new NFC relay malware family, purpose-built to capture live card data via NFC and forward it in real time to attackers. They dubbed it “WindRelay.” NFC (Near Field Communication) is wireless technology that allows devices such as smartphones, payment cards, and payment terminals to communicate when they’re very close together. So, instead of stealing your physical bank card, the attackers capture NFC activity on an infected mobile phone and relay it in…
Cisco Talos recently identified an undocumented phishing framework, internally branded "JWR" by its developer, built to convincingly impersonate checkout and login pages across major payment and shopping platforms. The client engine of the JWR phishing framework is a real-time, operator-driven system that, rather than merely logging form submissions like a static credential-stealing page, keeps an AES-CTR encrypted WebSocket open to the threat actor so they can steer each victim's session live.…
Questo CSIRT ha recentemente rilevato una campagna di smishing a tema GLS, perpetrata via SMS, volta a carpire dati relativi alla carta di pagamento della potenziale vittima.
Between January and June 2026, TrendAI™ tracked more than 35,000 fake sites exploiting the 2026 FIFA World Cup, spanning counterfeit merchandise shops, cloned ticket pages, and bogus free-streaming sites, which together drew roughly 1.48 million visits from Japan.
Key Takeaways Two real-world cloud attacks reached meaningful impact in less than ten minutes despite pursuing entirely different objectives. Both attackers treated the environment as a connected system, using existing permissions and relationships to expand their reach. Reconnaissance increasingly focuses on understanding access and capability rather than discovering vulnerable assets. AI is compressing the gap between discovery, decision-making, and execution for cloud attackers. The interval…
Most business email compromise (BEC) attacks start with stolen credentials, not a malicious email. Group-IB uses threat intelligence to detect compromised accounts before attackers log in — predicting BEC before it starts.
Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025. Talos has discovered that the actor in this campaign delivers a Python-based remote access tool (RAT) that we track as “Starland RAT” and a command-and-control (C2) memory implant known as the “WLDR agent.” The WLDR agent is a sophisticated PowerShell-based C2 memory implant that…
A Mexican banking fraud operation we're tracking as REF6045 doesn't run on autopilot. A human operator is behind the wheel, monitoring infected machines and deciding what happens next. Victims are infected through fake CAPTCHA pages that trick them into running a single command, which installs SCMBANKER, a PowerShell toolkit with components dating back to at least October 2025. Once installed, the operator can see when a victim opens a banking session, lock the screen behind a fake bank warning…
A Mexican banking fraud operation we're tracking as REF6045 doesn't run on autopilot. A human operator is behind the wheel, monitoring infected machines and deciding what happens next. Victims are infected through fake CAPTCHA pages that trick them into running a single command, which installs SCMBANKER, a PowerShell toolkit with components dating back to at least October 2025. Once installed, the operator can see when a victim opens a banking session, lock the screen behind a fake bank warning…
FortiGuard Labs research shows how cybercriminals are exploiting the demand for the FIFA World Cup 2026 through phishing, fake tickets, malware, impersonation, and credential theft.
With the 2026 FIFA World Cup just weeks away, Group-IB researchers have uncovered six distinct fraud schemes, four independent threat actors, and over 4,300 fraudulent domains impersonating FIFA's official web presence — including a sophisticated phishing operation run by the Chinese-speaking threat actor GHOST STADIUM, whose campaign could cause losses reaching billions of dollars.
In this blog entry, researchers from the TrendAI™ MDR team discuss how they mapped the full end-to-end operation of SHADOW-WATER-063’s Banana RAT banking malware by analyzing server-side artifacts and victim-side data.
Executive Summary SentinelLABS has identified PCPJack, a credential theft framework that worms across exposed cloud infrastructure and removes artifacts associated with TeamPCP, a threat actor persona who claimed several high-profile supply chain intrusions throughout early 2026. The toolset harvests credentials from cloud, container, developer, productivity, and financial services, then exfiltrates the data through attacker-controlled infrastructure while attempting to spread to additional…
ESET researchers uncovered fraudulent apps on Google Play that claim to provide the call history “for any number” and had been downloaded more than seven million times before being taken down
Elastic Security Labs identified a new Brazilian banking trojan that we are tracking as TCLBANKER, a malware family we assess is a major update of the MAVERICK/SORVEPOTEL family. The campaign, tracked as REF3076, features a loader with robust anti-analysis capabilities that deploys two embedded .NET Reactor-protected modules: a full-featured banking trojan and a worm module for self-propagation. The banking trojan monitors the victim's browser address bar via UI Automation, targeting 59…
Introduction Elastic Security Labs has been tracking a financially motivated operation, designated REF1695, that has been active since at least late 2023. The operator deploys a combination of RATs, cryptominers, and custom XMRig loaders through fake installer packages. Across all observed campaigns, the infection chains share a consistent packing technique, overlapping C2 infrastructure, and common social engineering patterns, linking them to a single operator. Beyond cryptomining, the threat…
Meet Huntress Reseller Sales Manager Cody Browning. Learn how his grandmother's vishing scam inspired his career and fuels our mission to bring human-led cybersecurity to all businesses.
Huntress’ AI-Centric SOC recently stopped a MacSync infostealer attack on a macOS device. The malware attempted to scrape credentials, browser cookies, and crypto wallets, but Huntress contained the threat before any data was sent to the attacker. Learn how we did it.