2026-02-19 17:00 UTC
Vendor Research
Google Online Security Blog · Edward Fernandez · indexed 2026-08-15 14:33 UTC
Posted by Vijaya Kaza, VP and GM, App & Ecosystem Trust The Android ecosystem is a thriving global community built on trust, giving billions of users the confidence to download the latest apps. In order to maintain that trust, we’re focused on ensuring that apps do not cause real-world harm, such as malware, financial fraud, hidden subscriptions, and privacy invasions. As bad actors leverage AI to change their tactics and launch increasingly sophisticated attacks, we’ve deepened our investments…
P0
2026-02-19 10:29 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
It’s tax season in Indonesia and fraudsters are observed to be ramping up the fraud campaign involving fake Coretax apps, but behind it lies an industrialized MaaS infrastructure ready to strike anywhere.
P0
2026-01-27 16:59 UTC
Vendor Research
Google Online Security Blog · Edward Fernandez · indexed 2026-08-15 14:33 UTC
Posted by Nataliya Stanetsky, Fabricio Ferracioli, Elliot Sisteron, Irene Ang of the Android Security Team Phone theft is more than just losing a device; it's a form of financial fraud that can leave you suddenly vulnerable to personal data and financial theft. That’s why we're committed to providing multi-layered defenses that help protect you before, during, and after a theft attempt. Today, we're announcing a powerful set of theft protection feature updates that build on our existing protect…
P0
2026-01-21 06:56 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
A deep dive into loan phishing scams in Peru and Latin America. Discover how scammers lure victims with fake loan offers, harvest sensitive banking credentials, and leverage advanced scripts to maximize fraud at scale.
P0
2026-01-13 10:00 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
If your data is on the dark web, it’s probably only a matter of time before it’s abused for fraud or account hijacking. Here’s what to do.
P0
2026-01-13 06:39 UTC
Other
Red Hunt Labs · Lohit · indexed 2026-09-07 17:30 UTC
Modern payment integrations are fast, flexible, and increasingly complex. APIs talk to gateways, webhooks trigger state changes, third parties handle fraud, retries, refunds, and orchestration layers quietly sit in between. In most teams, the signal that things are “working” is simple: transactions go through. That signal is misleading. At RedHunt Labs, we found that the real-world payment pentests reveal the common mistake of treating PCI DSS as a finish line instead of a baseline. This blog r…
P0
2026-01-07 07:00 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB researchers detail the inner workings of Chinese tap-to-pay schemes on Telegram and examine the NFC-enabled Android apps fraudsters are using to steal money from victim’s bank cards and mobile wallets remotely.
P0
2025-12-23 10:00 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
Have you ever received a package you never ordered? It could be a warning sign that your data has been compromised, with more fraud to follow.
P0
2025-12-22 11:40 UTC
Other
Red Hunt Labs · Lohit · indexed 2026-09-07 17:30 UTC
Payment gateways are built to move money reliably. Attackers view them as systems built on trust, timing, and assumptions. A gateway that works consistently is not a sign of safety. It is a stable environment to study, probe, and eventually abuse. This blog examines payment gateways from an attacker’s perspective, grounded in real exploitation patterns and reinforced with direct insights from industry experts. These patterns are documented extensively in the RedHunt Labs Payment Gateway Integra…
P0
2025-12-19 07:53 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB analyzes the evolution of Android malware in Uzbekistan, revealing advanced droppers, encrypted payload delivery, anti-analysis techniques, and Wonderland’s bidirectional SMS-stealing capabilities driving large-scale financial fraud.
P0
2025-12-11 07:32 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Comprehensive insights into Uzbekistan’s credit fraud trends, the methods used by fraudsters, and the practical security controls financial institutions are fighting back with.
P0
2025-12-10 20:00 UTC
Vendor Research
Google Online Security Blog · Google · indexed 2026-08-15 14:33 UTC
Posted by Chrome Root Program Team Secure connections are the backbone of the modern web, but a certificate is only as trustworthy as the validation process and issuance practices behind it. Recently, the Chrome Root Program and the CA/Browser Forum have taken decisive steps toward a more secure internet by adopting new security requirements for HTTPS certificate issuers. These initiatives, driven by Ballots SC-080, SC-090, and SC-091, will sunset 11 legacy methods for Domain Control Validation…
P0
2025-12-10 07:45 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Stranger things are happening in the upside-down world of cybercrime. Group-IB’s CEO, Dmitry Volkov, shares his cyber predictions for 2026 — what’s coming next, and what we must collectively fight against.
P0
2025-12-03 16:59 UTC
Vendor Research
Google Online Security Blog · Edward Fernandez · indexed 2026-08-15 14:33 UTC
Posted by Aden Haussmann, Associate Product Manager and Sumeet Sharma, Play Partnerships Trust & Safety Lead Android uses the best of Google AI and our advanced security expertise to tackle mobile scams from every angle. Over the last few years, we’ve launched industry-leading features to detect scams and protect users across phone calls, text messages and messaging app chat notifications. These efforts are making a real difference in the lives of Android users. According to a recent YouGov sur…
P0
2025-12-03 15:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn what the dark web looks like with an exploration of the far reaches of the internet, how you can get there, and what you might find… from a safe distance.
P0
2025-12-03 06:59 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
A deep dive into GoldFactory’s evolving mobile fraud campaigns across APAC, including modified banking apps, new malware variants such as Gigaflower, shared criminal infrastructure, and insights from the Group-IB Fraud Matrix, with recommendations for organizations and end users.
P0
2025-12-02 03:40 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Discover how real-time fraud intelligence sharing prevents APP fraud before losses. Stop mule accounts already during warm-up with GDPR-compliant technology.
P0
2025-11-26 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress CEO Kyle Hanslovan's live hack demo: modern hacker playbook, with stolen credentials, MFA bypass, and M365 token hijacking. Get defense tips, stay protected.
P0
2025-11-25 10:00 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
Social media influencers can provide reach and trust for scams and malware distribution. Robust account protection is key to stopping the fraudsters.
P0
2025-11-13 07:09 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB researchers uncovered a professional phishing framework that mimics trusted brands with remarkable precision. Using layered evasion, CAPTCHA filtering, and Telegram-based data exfiltration, attackers harvest credentials and bypass automated detection. The findings highlight how phishing-as-a-service operations are scaling through automation, lowering technical barriers for cybercriminals, and industrializing one of the oldest yet most effective forms of digital fraud.
P0
2025-10-30 16:59 UTC
Vendor Research
Google Online Security Blog · Edward Fernandez · indexed 2026-08-15 14:33 UTC
Posted by Lyubov Farafonova, Product Manager, Phone by Google; Alberto Pastor Nieto, Sr. Product Manager Google Messages and RCS Spam and Abuse; Vijay Pareek, Manager, Android Messaging Trust and Safety As Cybersecurity Awareness Month wraps up, we’re focusing on one of today's most pervasive digital threats: mobile scams. In the last 12 months, fraudsters have used advanced AI tools to create more convincing schemes, resulting in over $400 billion in stolen funds globally.¹ For years, Android …
P0
2025-10-28 09:06 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
This blog details online investment scam campaigns, including fraudulent cryptocurrency, forex, and trading platforms, while offering a technical investigation guide for investigators, based on Group-IB’s technical investigation methodology. It outlines the social engineering tactics and victim manipulation models employed, describes the fraud actor structures behind these schemes, and highlights key infrastructure artifacts identified by Group-IB High-Tech Investigations analysts that can be l…
P0
2025-10-21 06:56 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB’s Threat Intelligence Report on a Singapore-Targeted Scam Operation
P0
2025-10-15 07:37 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB’s Suspicious Payment Details module for Threat Intelligence delivers payment identifiers tied to ransomware, illegal casinos, and laundering schemes. Fraud, AML, and compliance teams can now stop money from reaching criminal infrastructure.
P15
2025-09-29 05:58 UTC
Other
Red Hunt Labs · Hariharan M · indexed 2026-09-07 17:30 UTC
In the rapidly evolving digital marketplace, e-commerce brands have become prime targets for cybercriminals. Beyond traditional data breaches, these brands now face sophisticated scams that exploit their reputation, deceive consumers, and erode trust. Drawing from investigations conducted by RedHunt Labs’ threat intelligence team, this blog delves into some of the most prevalent scams targeting e-commerce platforms and highlights how a Digital Risk Protection (DRP) solution can help fortify you…
P0
2025-09-09 05:54 UTC
Other
Red Hunt Labs · Hariharan M · indexed 2026-09-07 17:30 UTC
Introduction A new wave of AI-powered investment scams is targeting Indian users on Facebook and Instagram, luring them with fake celebrity endorsements and deepfake interviews. Ads featuring figures like Nirmala Sitharaman, Sadhguru, and Neha Kakkar promote fraudulent schemes, directing users to counterfeit news websites mimicking The Times of India, IndiaTime, and NDTV. These sites claim celebrities have built fortunes using exclusive investment strategies, persuading victims to deposit ₹21,0…
P0
2025-09-03 07:49 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
AI in cybercrime is evolving fast, fueling AI phishing attacks, AI scam calls, AI voice cloning scams, and even AI deepfake scams. From Dark LLMs to next-gen AI phishing tactics, we break down how criminals exploit AI today and what you can do to stay protected.
P0
2025-08-27 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress researchers take a tour through the dark web, from innovative threat actor marketing techniques to cybercrime drama on BreachForums.
P0
2025-08-20 06:44 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Discover how mule operators evolved in META-region banks—from IP masking to Starlink tactics with advanced GPS spoofing, SIM abuse, and device muling—and how layered fraud detection strategies fought back.
P0
2025-08-13 06:58 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
AI trading scams use deepfake videos, fake reviews, and fraudulent platforms to steal investor money, and learn the signals that expose these online investment scams before you deposit.
P0