Group-IB - Experts & Thought Leaders

Latest Group-IB news & announcements

Group-IB Leads In Cyberthreat Solutions On AWS

Group-IB, a creator of predictive cybersecurity technologies to investigate, prevent, and fight digital crime, announces that its market-pioneer adversary-centric Threat Intelligence solution, engineered to detect and flag threats early enough to serve as a warning before an attack lands, is now available in AWS Marketplace, a digital catalog with thousands of software listings from independent software vendors that make it easy to find, test, buy, and deploy software that runs on Amazon Web Services (AWS), allowing customers to purchase through their existing AWS procurement and billing relationship. In 2026, Group-IB was named a Leader in the Gartner® Magic Quadrant™ for Cyberthreat Intelligence Technologies. Group-IB was one of only five vendors to achieve Leader status in Gartner’s inaugural Magic Quadrant™ for the threat intelligence market. Adversary-centric intelligence Group-IB Threat Intelligence draws on the company's global network of Digital Crime Resistance Centers, adversary-centric research, and one of the industry's largest cybersecurity data lakes to expose threats at their earliest stage. It covers the full threat spectrum, from compromised credentials and dark web chatter to emerging cybercrime groups and threats, Advanced Persistent Threat (APT) activity, new forms of fraud, potential large-scale attacks, and early indicators of threat actor activity. Delivered through Group-IB's Unified Risk Platform, with data flows centrally controlled through its Incident Management Center, the intelligence has been proven in the field through contributions to more than 1,600 global law enforcement investigations worldwide. It gives security teams verified, attributable, adversary-centric intelligence they can act on quickly, giving them an early warning of an adversary's next move rather than leaving them to respond after the fact. Manual analyst compilation This intelligence is processed with the support of Prevyn AI, which orchestrates a network of specialist research agents to carry out multi-step investigations and return structured, source-backed findings without manual analyst compilation, helping teams detect and share threat signals fast enough to serve as an early warning before an attack escalates. AWS customers will now have access to Group-IB's adversary-centric Threat Intelligence directly within AWS Marketplace. The listing gives security teams a faster path to acquiring Group-IB's threat intelligence, streamlining its purchase and management within their AWS Marketplace account by removing separate procurement cycles and consolidating the purchase into a single AWS invoice. Customers can also apply the purchase toward committed AWS spend, allowing Threat Intelligence to be acquired without additional budget approval outside existing cloud commitments. The listing follows Group-IB's recent achievement of the Amazon Web Services (AWS) Financial Software Competency designation, which recognizes providers that meet AWS's security, quality, and operational standards for the financial services industry. Financial services industry "Attackers are now using AI to speed up reconnaissance, craft convincing lures, and adapt their infrastructure in real time, which compresses the window defenders have to respond," said Dmitry Volkov, CEO, Group-IB. "Waiting for an alert is no longer a viable defense; security teams need intelligence that reaches them fast enough to act before real damage is done. Bringing our Threat Intelligence to AWS Marketplace removes a barrier to getting that intelligence into the hands of teams that need to shift from reactive to proactive defense." Group-IB Threat Intelligence is now generally available in AWS Marketplace, alongside Group-IB's other AWS Marketplace solutions, at the Group-IB seller profile in AWS Marketplace.

Group-IB Purple Teaming Boosts Security Resilience

Group-IB, a creator of predictive cybersecurity technologies to investigate, prevent, and fight digital crime, announces the launch of its Purple Teaming service, a collaborative security validation offering that brings offensive and defensive specialists together in real time to test whether an organization's defences, people, and processes can effectively detect and respond to today's most prevalent attack techniques. Unlike traditional penetration testing, which concludes with a report delivered after the fact, Purple Teaming is a live, feedback-driven process. Group-IB's red team executes adversary scenarios while the client's own defenders monitor, respond, and immediately tune their detection rules and response playbooks, creating a continuous improvement loop within a single engagement. Predictive cybersecurity technologies Every exercise is grounded in Group-IB's Threat Intelligence and mapped to the MITRE ATT&CK® framework. Scenarios are tailored to each client's specific environment and can include ransomware simulations, Active Directory attacks, supply chain compromise, and data exfiltration, all conducted safely, without business disruption. The service is delivered over one to eight weeks and is available on-site, remotely, or in a hybrid format to accommodate organizations of all sizes and operational structures. By closing the distance between a security team's theoretical capabilities and their demonstrated performance under realistic conditions, Purple Teaming addresses one of the most persistent challenges in enterprise security: the gap between investment in tools and platforms and actual operational readiness. Clients leave each engagement with measurably improved detection coverage, updated response procedures, and defenders who have practiced under pressure against adversary behavior that mirrors real-world campaigns tracked by Group-IB. Adversary intelligence capabilities The service draws directly on Group-IB's adversary intelligence capabilities, which are built on over 1,600 high-tech cybercrime investigations conducted since the company's founding in 2003. This depth of intelligence allows scenarios to reflect the actual techniques, tactics, and procedures of the threat actors most relevant to a client's industry and geography, not generic attack frameworks applied uniformly. “Organizations today face a fundamental accountability question: they have invested heavily in detection and response capabilities, but many have never tested whether those capabilities actually work when it matters,” said Dmitry Volkov, CEO of Group-IB. “Purple Teaming answers that question honestly. It is not a checkbox exercise; it is a structured, intelligence-driven process that reveals exactly where detection fails, where response breaks down, and where training has not kept pace with the threat. The goal is not to expose weakness for its own sake but to convert that knowledge into a measurable improvement in resilience.” Measurable improvement in resilience “The most important thing we bring to a Purple Teaming engagement is not just about our offensive toolkit, but also the intelligence behind every scenario we run. When we simulate a ransomware intrusion or an Active Directory attack, we are not working from generic playbooks,” said Konstantin Damotsev, Global Head of Group-IB’s Red Teaming Practice. “We are replicating the specific behavior of threat actors Group-IB has tracked, investigated, and attributed across thousands of real incidents. That specificity is what makes the exercise genuinely useful: defenders learn to detect the adversaries that are actually targeting them, not a theoretical composite. The difference shows immediately when a detection rule catches something it has never been tested against before.” Security resilience services Purple Teaming is the latest addition to Group-IB’s portfolio of security resilience services and complements its broader offering across Threat Intelligence, Managed Extended Detection and Response (XDR), and Incident Response. The service is available globally through Group-IB’s network of Digital Crime Resistance Centers across the Asia-Pacific, Europe, the Middle East and Africa, the Americas, and Central Asia.

Group-IB's 2026 High-Tech Crime Trend Report

Group-IB, a creator of predictive cybersecurity technologies to investigate, prevent, and fight digital crime, today unveils its Top 10 Masked Actors for 2026 – a definitive ranking of the most prolific cybercriminal groups operating globally. The list is drawn from Group-IB's High-Tech Crime Trend Report 2026, which identifies 2026 as the year the supply chain became cybercrime's most exploited attack surface. Across more than 1,550 frontline investigations and extensive monitoring of the criminal underground, Group-IB analysts observed a structural transformation in how attacks are orchestrated: threat actors are no longer targeting victims directly, but embedding themselves into the trusted infrastructure and third-party ecosystems that organizations depend on — amplifying their reach, compressing detection windows, and maximising disruption across entire industries simultaneously. Novelty of technical evolution The 2026 Top 10 Masked Actors ranking is determined through a rigorous, adversary-centric methodology, scoring each group across six dimensions: financial impact, victims, volume of threats during the operational lifespan, novelty of technical evolution, growth of affiliates, and notoriety. The result is an intelligence-led framework that goes beyond listing who the top threat actors are — it explains why they matter, and how their tactics are reshaping the future of cybercrime. Scattered Spider - Linked to some of the most high-profile attacks of the past year, Scattered Spider has risen to global notoriety through a combination of social engineering mastery and unprecedented operational scale. This decentralized cybercriminal community demonstrated the power of the supply chain attack vector in a single 2025 operation that compromised 130+ organizations across the technology sector - showing how loosely affiliated actors can cascade a downstream supply chain and rival the impact of traditional organized crime. Lazarus - A highly sophisticated, state-linked threat actor blending cyber espionage with large-scale financial crime. Lazarus earns its place, primarily for its financial impact, responsible for over $6.5 billion in cryptocurrency theft within its lifespan, and over $2.02 billion in 2025 alone - making it one of the most financially destructive threat actors documented.  MuddyWater - A state-aligned cyber espionage group targeting government, financial services, and logistics sectors, notable for its broad geographic reach across 113 countries. Its defining characteristic, operational tempo: between October 2025 and March 2026, MuddyWater deployed three new malware variants, illustrating the velocity of adversary development cycles that defenders must now anticipate. Tycoon 2FA -The dominant force in Phishing-as-a-Service (PhaaS), Tycoon 2FA controls 89% market share of the adversary-in-the-middle PhaaS segment. It’s SaaS subscription model has commoditised enterprise credential theft at scale - enabling thousands of attacks across cloud environments globally and lowering the barrier for less technically sophisticated actors to execute high-impact campaigns. GoldFactory - First identified by Group-IB in 2024, GoldFactory is a technically advanced threat cluster that has demonstrated a unique capability: stealing biometric data to bypass facial recognition authentication in mobile banking fraud. Operating 15 infections per day across active campaigns, the group has begun to expand beyond its original APAC focus, with new Spanish-language code artefacts signaling deliberate geographic expansion. TX-NFC - A commercialised ecosystem that emulates contactless payment systems on fraudsters' devices, offered via subscriptions from $45 a day to $1,050 per three months. As contactless payments continue to expand globally, TX-NFC’s available attack surface grows with them. The group is expanding into English and Russian-speaking cybercrime ecosystems. Shadow Silk - A financially motivated group specializing in obfuscation and long-duration evasion, Shadow Silk has been observed operating undetected within critical infrastructure and government entities across multiple regions — remaining concealed for over 12 months in one documented instance. Its ability to persist inside high-value environments without triggering detection places it among the most operationally mature actors on this year's list. Bloody Wolf - A persistent threat group prioritising long-term access and surveillance over immediate financial gain. Operating primarily in Central Asia with a focus on government organizations, Bloody Wolf employs geo-fenced delivery infrastructure to maintain a targeted, low-profile foothold — a tradecraft increasingly associated with actors seeking strategic, intelligence-gathering objectives. Teste PHP - In under a year, Teste PHP has built a financial crime operation spanning five Spanish-speaking countries, using malicious browser extensions that silently harvest credentials in real time. Its rapid geographic expansion and aggressive victim acquisition rate illustrate the relentless pace at which new cybercriminal operations can scale in the current ecosystem. DarkBlinders - An emerging threat cluster targeting aviation and telecommunications sectors in the Middle East, DarkBlinders holds the highest TTP evolution score on this year's list — a metric derived from the frequency and breadth of changes to its tactics, techniques and procedures over a 12-month period. Unlike actors operating from a static playbook, DarkBlinders continuously monitors its own exposure and adapts its methods to invalidate existing detection signatures, making it one of the most operationally agile adversaries currently tracked by Group-IB. Commercialisation of attack infrastructure “The supply chain has become cybercrime’s most powerful multiplier. What our investigators documented across more than 1,550 cases last year tells us that attacks are no longer targeting victims in isolation - they are embedding themselves into trusted infrastructure and third-party ecosystems to cascade across entire industries at once.” “A single point of compromise reached over 130 organizations in one operation we tracked. At the same time, the commercialisation of attack infrastructure - phishing platforms with 89% marketshare, NFC fraud sold on subscription - is closing the capability gap between sophisticated and unsophisticated threat actors fast. For defenders, the response has to be adversary-centric: understanding how these specific adversaries evolve, not just what they did last quarter, but predicting through AI driven intelligence what they will do next.” - Dmitry Volkov, Chief Executive Officer, Group-IB. Featuring frontline investigators The top 10 Masked Actors ranking is underpinned by Group-IB’s unique position at the intersection of threat intelligence and global law enforcement collaboration. Group-IB’s intelligence has directly supported operations with INTERPOL, Europol, AFRIPOL and national agencies, resulting in the arrest and prosecution of cybercriminals worldwide, providing it with unmatched visibility into how threat actors operate, adapt, and reconstitute following disruption. This law enforcement cooperation is a core differentiator in the quality and depth of intelligence informing the 2026 ranking. To accompany the ranking, Group-IB will release the second season of its Masked Actors podcast series, launching on 30th June with an in-depth episode on Scattered Spider. The episode, available on all major podcast platforms, will feature special guest Seán Doyle. Lead, Cybercrime Atlas Initiative, at the World Economic Forum, examining how the group exploits a single trusted entry point to cascade across hundreds of downstream organizations. Subsequent episodes will cover each ranked actor in turn, featuring frontline investigators and expert commentary on emerging cybercrime trends.