Group-IB - Experts & Thought Leaders

Latest Group-IB news & announcements

Group-IB Unveils Operation KillSwitch Details

Group-IB, a creator of predictive cybersecurity technologies to investigate, prevent, and fight digital crime, announces its contribution to Operation KillSwitch, an international investigation led by the Hamburg State Criminal Police Office (Landeskriminalamt Hamburg) and the Hamburg Public Prosecutor's Office, with the support of Europol and Eurojust, into KillSec, a ransomware-as-a-service (RaaS) group linked to around 1,000 suspected attacks worldwide. On 30 September 2026, law enforcement took control of KillSec's leak site, securing at least 110 terabytes of stolen data, while three suspects were provisionally arrested and eight properties searched in Greece, Romania, Spain, and the United Kingdom. Investigators identified a 16-year-old as the group's suspected main operator. Group-IB supported the investigation with intelligence on the group's operations, infrastructure, and key enablers. Law enforcement seizure notice Authorities from Belgium, Finland, Germany, Greece, the Netherlands, Romania, Spain, Switzerland, the United Kingdom, and the United States took part in the investigation. Over its course, five central servers used to manage the group's activities and store data taken from victims were brought under police control, and KillSec's domains were redirected to a law enforcement seizure notice. Investigators identified suspects believed to hold different roles within the group, including an administrator, a developer, a negotiator, and an affiliate. Around 500 of the suspected attacks have so far been identified as successful, a figure that may change as investigators examine the evidence seized. Public Telegram channels KillSec, also tracked as Kill Security and k1llsec, is a financially motivated Ransomware-as-a-Service (RaaS) group that Group-IB first identified in 2024. Operating a dark web leak site and public Telegram channels, the group recruited affiliates to carry out attacks using its platform in exchange for a share of each ransom. Group-IB's High-Tech Crime Trends Report 2026 ranked KillSec among the ten most active ransomware groups of 2025 in Asia-Pacific, Latin America, and the Middle East. By monitoring KillSec's leak site and Telegram channels, Group-IB identified 274 organizations publicly claimed as victims on the group’s leak site. Organizations in the United States accounted for around 35% of identified victims, followed by India at 17%, with Brazil, the United Kingdom, Australia, and Colombia each accounting for around 3%. By region, North America accounted for around 35% of victims and Asia-Pacific for 30%, followed by Europe -14% and the MEA at around 10%. Most affected sectors Financial services and healthcare were the most affected sectors, while the victim list also included government bodies and large enterprises, among them a major insurer, investment firms, and a consumer app with millions of users. Although KillSec declared hospitals off-limits in a January 2025 recruitment post, from late 2025 the group shifted its focus toward healthcare software and IT service providers, where a single compromise can expose the patient records of every clinic using the platform. Encryption was not a precondition for a KillSec listing. The group also sold stolen data outright, with asking prices ranging from USD 5,000 for a single company's records to USD 500,000 for the data it claimed to have taken from the global insurer, making KillSec as much a data broker as a ransomware operator. Shutting down virtual machines In October 2024, Group-IB researchers analyzed the KillSec 2.0 affiliate platform, a Tor-based panel used to manage victims, ransom negotiations, and payload configuration. At the time, the group's locker was a Windows-only encryptor, offered to affiliates for a USD 250 entry fee and a 12% share of each ransom. Unusually, affiliates could not generate builds on demand: each one required approval from the group's administrators. The restriction pointed to a small core team guarding its payload, and it carried over into every version Group-IB observed. The upgrades came quickly. In November 2024, KillSec announced a locker for VMware ESXi virtualisation hosts, capable of shutting down virtual machines, deleting snapshots, and erasing logs, removing the recovery points victims would otherwise rely on. By January 2025, the group was openly recruiting “skilled pentesters”, requiring a forum reputation or a USD 1,000 deposit, and had raised its share of each ransom to 20%. Identifying potential victims Some KillSec affiliates also worked with other RaaS programs, including LockBit, RansomHub, Qilin, and Bashe. According to Europol, investigators also uncovered how the group used AI to build and maintain its ransomware infrastructure and identify potential victims. Affiliates favored the path of least resistance. Alongside phishing, brute-force attacks on exposed Remote Desktop Protocol (RDP) services, and exploitation of known vulnerabilities in internet-facing applications, a substantial share of claimed victims involved no network intrusion at all: data was taken from cloud storage left publicly accessible through misconfiguration. Supporting law enforcement Security controls stop individual attacks, but KillSec's operations depended on the small core team that developed the locker and approved each build. Group-IB's support to the investigation focused on providing intelligence on the group's operations, infrastructure, and key enablers. “KillSec's affiliates went after the organizations people depend on most: hospitals, government bodies, and financial institutions. Closing the gaps these groups exploit is essential, but it does not end an operation like this. Servers can be replaced in weeks; the people who build the platform and approve every attack cannot. Identifying them and supporting law enforcement in bringing them to justice is what turns a takedown from a pause into an end. We are proud to have contributed to Operation KillSwitch, and will continue to support Europol and our law enforcement partners in the fight against cybercrime,” said Dmitry Volkov, CEO of Group-IB. Prioritise patching of vulnerabilities Group-IB recommends that organizations treat external exposure as a first-order risk: maintain a continuous inventory of internet-facing assets, including cloud storage and remote access services; enforce multi-factor authentication on remote access; prioritise patching of vulnerabilities known to be exploited in the wild; and keep offline, immutable backups, with virtualisation platforms protected as critical systems. The same scrutiny should extend to software and IT service providers that hold sensitive data on an organization's behalf, while monitoring leak sites and underground markets helps organizations learn of an exposure early, rather than from a public listing. Operation KillSwitch is the latest in a series of international operations supported by Group-IB in collaboration with law enforcement agencies including Europol, INTERPOL, and AFRIPOL. To date, Group-IB has contributed to more than 1,600 high-tech crime investigations across 60+ countries.

Group-IB Leads In Cyberthreat Solutions On AWS

Group-IB, a creator of predictive cybersecurity technologies to investigate, prevent, and fight digital crime, announces that its market-pioneer adversary-centric Threat Intelligence solution, engineered to detect and flag threats early enough to serve as a warning before an attack lands, is now available in AWS Marketplace, a digital catalog with thousands of software listings from independent software vendors that make it easy to find, test, buy, and deploy software that runs on Amazon Web Services (AWS), allowing customers to purchase through their existing AWS procurement and billing relationship. In 2026, Group-IB was named a Leader in the Gartner® Magic Quadrant™ for Cyberthreat Intelligence Technologies. Group-IB was one of only five vendors to achieve Leader status in Gartner’s inaugural Magic Quadrant™ for the threat intelligence market. Adversary-centric intelligence Group-IB Threat Intelligence draws on the company's global network of Digital Crime Resistance Centers, adversary-centric research, and one of the industry's largest cybersecurity data lakes to expose threats at their earliest stage. It covers the full threat spectrum, from compromised credentials and dark web chatter to emerging cybercrime groups and threats, Advanced Persistent Threat (APT) activity, new forms of fraud, potential large-scale attacks, and early indicators of threat actor activity. Delivered through Group-IB's Unified Risk Platform, with data flows centrally controlled through its Incident Management Center, the intelligence has been proven in the field through contributions to more than 1,600 global law enforcement investigations worldwide. It gives security teams verified, attributable, adversary-centric intelligence they can act on quickly, giving them an early warning of an adversary's next move rather than leaving them to respond after the fact. Manual analyst compilation This intelligence is processed with the support of Prevyn AI, which orchestrates a network of specialist research agents to carry out multi-step investigations and return structured, source-backed findings without manual analyst compilation, helping teams detect and share threat signals fast enough to serve as an early warning before an attack escalates. AWS customers will now have access to Group-IB's adversary-centric Threat Intelligence directly within AWS Marketplace. The listing gives security teams a faster path to acquiring Group-IB's threat intelligence, streamlining its purchase and management within their AWS Marketplace account by removing separate procurement cycles and consolidating the purchase into a single AWS invoice. Customers can also apply the purchase toward committed AWS spend, allowing Threat Intelligence to be acquired without additional budget approval outside existing cloud commitments. The listing follows Group-IB's recent achievement of the Amazon Web Services (AWS) Financial Software Competency designation, which recognizes providers that meet AWS's security, quality, and operational standards for the financial services industry. Financial services industry "Attackers are now using AI to speed up reconnaissance, craft convincing lures, and adapt their infrastructure in real time, which compresses the window defenders have to respond," said Dmitry Volkov, CEO, Group-IB. "Waiting for an alert is no longer a viable defense; security teams need intelligence that reaches them fast enough to act before real damage is done. Bringing our Threat Intelligence to AWS Marketplace removes a barrier to getting that intelligence into the hands of teams that need to shift from reactive to proactive defense." Group-IB Threat Intelligence is now generally available in AWS Marketplace, alongside Group-IB's other AWS Marketplace solutions, at the Group-IB seller profile in AWS Marketplace.

Group-IB Purple Teaming Boosts Security Resilience

Group-IB, a creator of predictive cybersecurity technologies to investigate, prevent, and fight digital crime, announces the launch of its Purple Teaming service, a collaborative security validation offering that brings offensive and defensive specialists together in real time to test whether an organization's defences, people, and processes can effectively detect and respond to today's most prevalent attack techniques. Unlike traditional penetration testing, which concludes with a report delivered after the fact, Purple Teaming is a live, feedback-driven process. Group-IB's red team executes adversary scenarios while the client's own defenders monitor, respond, and immediately tune their detection rules and response playbooks, creating a continuous improvement loop within a single engagement. Predictive cybersecurity technologies Every exercise is grounded in Group-IB's Threat Intelligence and mapped to the MITRE ATT&CK® framework. Scenarios are tailored to each client's specific environment and can include ransomware simulations, Active Directory attacks, supply chain compromise, and data exfiltration, all conducted safely, without business disruption. The service is delivered over one to eight weeks and is available on-site, remotely, or in a hybrid format to accommodate organizations of all sizes and operational structures. By closing the distance between a security team's theoretical capabilities and their demonstrated performance under realistic conditions, Purple Teaming addresses one of the most persistent challenges in enterprise security: the gap between investment in tools and platforms and actual operational readiness. Clients leave each engagement with measurably improved detection coverage, updated response procedures, and defenders who have practiced under pressure against adversary behavior that mirrors real-world campaigns tracked by Group-IB. Adversary intelligence capabilities The service draws directly on Group-IB's adversary intelligence capabilities, which are built on over 1,600 high-tech cybercrime investigations conducted since the company's founding in 2003. This depth of intelligence allows scenarios to reflect the actual techniques, tactics, and procedures of the threat actors most relevant to a client's industry and geography, not generic attack frameworks applied uniformly. “Organizations today face a fundamental accountability question: they have invested heavily in detection and response capabilities, but many have never tested whether those capabilities actually work when it matters,” said Dmitry Volkov, CEO of Group-IB. “Purple Teaming answers that question honestly. It is not a checkbox exercise; it is a structured, intelligence-driven process that reveals exactly where detection fails, where response breaks down, and where training has not kept pace with the threat. The goal is not to expose weakness for its own sake but to convert that knowledge into a measurable improvement in resilience.” Measurable improvement in resilience “The most important thing we bring to a Purple Teaming engagement is not just about our offensive toolkit, but also the intelligence behind every scenario we run. When we simulate a ransomware intrusion or an Active Directory attack, we are not working from generic playbooks,” said Konstantin Damotsev, Global Head of Group-IB’s Red Teaming Practice. “We are replicating the specific behavior of threat actors Group-IB has tracked, investigated, and attributed across thousands of real incidents. That specificity is what makes the exercise genuinely useful: defenders learn to detect the adversaries that are actually targeting them, not a theoretical composite. The difference shows immediately when a detection rule catches something it has never been tested against before.” Security resilience services Purple Teaming is the latest addition to Group-IB’s portfolio of security resilience services and complements its broader offering across Threat Intelligence, Managed Extended Detection and Response (XDR), and Incident Response. The service is available globally through Group-IB’s network of Digital Crime Resistance Centers across the Asia-Pacific, Europe, the Middle East and Africa, the Americas, and Central Asia.