Group-IB
2.19K subscribers
739 photos
26 videos
2 files
525 links
Your daily source of cybersecurity news brought to you by Group-IB, one of the global industry leaders.
Download Telegram
🚨Android-based financial fraud in Uzbekistan has entered a new stage of operational maturity, with threat actors shifting from simple SMS stealers to sophisticated, multi-stage infection chains built around stealthy droppers, advanced obfuscation, and automated infrastructure.

Key Highlights:
πŸ”ΉOver $2M stolen by a single tracked group since January 2025
πŸ”ΉTwo primary dropper families, MidnightDat and RoundRift, were identified using native decryption and encrypted asset storage.
πŸ”ΉWonderland, a new SMS stealer with bidirectional WebSocket Cβ‚‚, enables real-time command execution, SMS sending, and USSD control.
πŸ”ΉTelegram remains the central distribution channel, fueled by stolen sessions sold on dark web markets.
πŸ”ΉThousands of unique samples generated through automated build pipelines to evade signature-based detection

πŸ”— Read the full analysis here.

#ThreatIntelligence #AndroidMalware
πŸ‘10πŸ”₯3
πŸ’Έ β€œEasy money. Simple tasks. Work from your phone.”

Our latest analysis exposes a coordinated wave of fake online job ads sweeping across the Middle-East and Africa region. These aren't isolated scams, they are a large-scale, organized operation exploiting the demand for remote work to steal personal data and funds.

Key insights from our investigation:
πŸ”Ή Over 1,500 fraudulent job ads identified in 2025, impersonating trusted e-commerce platforms, banks, and even government ministries.
πŸ”Ή Ads are highly localized, using Arabic dialects and regional currencies to appear authentic.
πŸ”Ή Victims are funneled from social media into private Telegram and WhatsApp groups, where sensitive information and upfront β€œdeposits” are collected.
πŸ”ΉThe scam infrastructure includes fake registration portals, cloned branding, and repeat behavioral patterns among attackers.

Read More.

#CyberSecurity #OnlineScams #MENA #Phishing #DigitalRisk #FraudPrevention #ThreatIntelligence
πŸ”₯11❀2πŸ‘2