Group-IB – Telegram
Group-IB
2.21K subscribers
745 photos
26 videos
2 files
531 links
Your daily source of cybersecurity news brought to you by Group-IB, one of the global industry leaders.
Download Telegram
#CyberCrimeCon21 #report #cybercrime #HTCT

Access brokers: regional profiles 🌎

Let's take a closer look at the situation with the sales of access to corporate networks in various regions.

🔹In APAC alone, the total cost of all the accesses to the region’s companies available in the underground totaled $3.3 million. Most of the accesses on the sale belonged to organizations from Australia, India and China.

🔹European companies were among frequent targets of access brokers as well. The total cost of all the accesses to the region’s companies offered for sale in the #underground totaled $590,095 in the review period. French companies were the most popular lot for sellers of access to compromised networks, followed by the UK and Italy.

🔹In the Middle East, the total cost of all the accesses to the region’s companies available in the underground accounted for $247,836. Most of the accesses on the sale belonged to organizations from the UAE, followed by Israel and Turkey.

Download the report for more details -> https://bit.ly/3pjvxPc
This media is not supported in your browser
VIEW IN TELEGRAM
Today, at #CyberCrimeCon, Group-IB Head of Digital Forensics and Malware Analysis Lab Oleg Skulkin revealed his findings about the recent developments in the #ransomware market.

The full session's recording will soon be available at ▶️ https://cybercrimecon.com
#report #cybercrime #HTCT #ransomware

Group-IB presents the second volume of its Hi-Tech Crime Trends 2021/2022 report “Corporansom: threat number one⚡️⚡️⚡️

In the first 11 months of 2021, more than 60% of all the incidents investigated by Group-IB concerned ransomware. This number is expected to grow, with the number of public affiliate programs growing by 23% in H2 2020 – H1 2021 compared to the corresponding period a year earlier.

Over the review period, RaaS gangs increased the conversion by posting compromised data online on their Data Leak Sites (DLS). It has become very popular, with the number of victims whose data has been published on DLSs having grown by 935% in H2 2020 – H1 2021.

The report represents the first attempt to provide a retrospective analysis of how the ransomware cyber empire evolved and shed light on how businesses worldwide lose millions of dollars to cybercriminals. In this report, we look into how and why the ransomware industry has developed, provide in-depth analyses of certain affiliate programs from within, and share statistics on the countries and industries that are attacked most often.

Download link -> https://bit.ly/31NMsRX
#report #cybercrime #HTCT #ransomware

Let's take a look at the “Corporansom: threat number one” highlights⬇️

🔹According to data leak sites, in 2021, the most active #ransomware groups were #Conti, #Lockbit and #Avaddon.

🔹Almost half of the companies whose data was released on DLS in 2021 originate from the US🇺🇸, followed by Canada🇨🇦 and France🇫🇷.

🔹According to the DLS data, the main industries targeted in 2021 were #manufacturing, real estate, and #transportation. In 2020, the situation was almost the same, which suggests that attackers mainly target the same types of companies that they believe to be the most profitable.

🔹In H2 2020 – H1 2021, #RaaS gangs increased the conversion by posting compromised data online on their Data Leak Sites (#DLS). It has become very popular, with the number of victims whose data has been published on DLSs having grown by 935%.

🔹SoftPerfect Network Scanner, Cobalt Strike Beacon, and ADFind were the top 3 most popular tools encountered by Group-IB experts in their response to #ransomware attacks.

Download the report now for more insights -> https://bit.ly/31NMsRX
#blog #ransomware #Hive

Inside the Hive: deep dive into the Hive RaaS, analysis of latest samples

🔹In July 2021,the REvil ransomware operators demanded a record-breaking ransom of $70 million from meat giant JBS in exchange for providing the decryption key. The record didn't stand long. It took the ransomware empire less than half a year to grow this ransom demand 3-fold to $240 million. Such a ransom demand received Europe's largest consumer electronics retailer Media Markt that fell prey to a ransomware attack in November. It turned out that the perpetrator behind the incident was Hive, which used to take a back seat. Just as REvil, the Hive gang worked under the Ransomware-as-a-Service (RaaS) model and frequently pressured their victims by releasing data on them on their DLS (data leak sites, where the data belonging to companies that refuse to pay a ransom is published).

🔹Hive affiliates have been busy as bees: the actual number of their victims is in the hundreds despite the fact that the affiliate program has been active less than half a year. Group-IB Threat Intelligence analysts have managed to determine that as of October 16, 2021 alone, at least 355 companies fell victim to the threat actor.

⚠️Taking into account that Hive targets organizations from various economic sectors from all around the world and their attacks are manually controlled by the affiliates, it's crucial to closely monitor the changes in TTPs of these ransomware operators. Group-IB Digital Forensics and Threat Intelligence teams have analyzed the latest available samples of Hive and for the first time analyzed the affiliate program from the inside, having tracked down it to its creation.

Check it out -> https://bit.ly/3y7OCId
#report #cybercrime #HTCT #ransomware

Group-IB presents the third volume of its Hi-Tech Crime Trends 2021/2022 report “Big money: threats to financial sector⚡️⚡️⚡️

❗️Organizations in the financial sector face a diverse threat landscape, as they are often the preferred targets of financially motivated cybercriminals. In H2 2020 - H1 2021, the cyber threat that stood out as the most damaging to financial sector organizations was ransomware.

🔺In the review period the number of financial organizations whose data was released on DLS increased to 127 compared to 50 a year earlier. Group-IB identified at least 24 groups attacking companies in the financial sector. The most prolific among them were #REvil, #Conti, and #Avaddon.

🔺The market for access to corporate networks has grown significantly. Compared to the previous period, the number of initial access brokers (IABs) has increased from 18 to 47 , while the number of known sale incidents went up from 31 to 95.

Download link -> https://bit.ly/3dLL2tJ