Connect with us

Technology

Group-IB reveals Hi-Tech Crime Trends 23/24: surge in ransomware against backdrop of growing AI, macOS threats

Published

on

SINGAPORE, Feb. 29, 2024 /PRNewswire/ — Group-IB, a leading creator of cybersecurity technologies to investigate, prevent, and fight digital crime, is proud to announce the launch of its new report Hi-Tech Crime Trends 2023/2024, the latest edition of the company’s annual round-up of the most pressing global cyber threats to organizations and individuals. In the research, Group-IB analysts reveal how the unholy alliance between ransomware groups and Initial Access Brokers (IABs) is still the powerful engine for cybercriminal industry, evidenced by the 74% year-on-year increase in the number of companies that had their data uploaded on dedicated leak sites (DLS). Global threat actors also demonstrated increased interest in Apple platforms, exemplified by the fivefold increase in underground sales related to macOS information stealers.

The growing appetite of nation-state sponsored threat actors, also known as advanced persistent threat (APT) groups, has shown that no region is immune to cyber threats. Group-IB experts discovered a 70% increase in the number of public posts offering zero-day exploits for sale, and also identified cybercriminals’ malicious use of legitimate services and artificial intelligence (AI) infused technologies as the main cyber risks for 2024.

The first edition of Hi-Tech Crime Trends was launched 12 years ago, and the information contained in the report enables businesses, NGOs, governments, and law enforcement agencies around the world to fight cybercrime and help potential victims. For the first time, Hi-Tech Crime Trends includes a section outlining the intricate relationship between artificial intelligence (AI) and cybersecurity threats, outlining how this new technology is being leveraged by cybercriminals, including the misuse of large language models (LLM) such as ChatGPT, and the potential risks to corporate data through AI integration.

Nothing artificial about this threat

Threat actors have already shown how AI can help them develop malware only with a limited knowledge of programming languages, brainstorm new TTPs, compose convincing text to be used in social engineering attacks, and also increase their operational productivity.

Large language models (LLM) such as ChatGPT remain in widespread use, and Group-IB analysts have observed continued interest on underground forums in ChatGPT jailbreaking and specialized generative pre-trained transformer (GPT) development, looking for ways to bypass ChatGPT’s security controls. Group-IB experts have also noticed how, since mid-2023, four ChatGPT-style tools have been developed for the purpose of assisting cybercriminal activity: WolfGPT, DarkBARD, FraudGPT, and WormGPT – all with different functionalities.

FraudGPT and WormGPT are highly discussed tools on underground forums and Telegram channels, tailored for social engineering and phishing. Conversely, tools like WolfGPT, focusing on code or exploits, are less popular due to training complexities and usability issues. Yet, their advancement poses risks for sophisticated attacks.

Group-IB’s Hi-Tech Crime Trends 2023/2024 also highlighted the sale of compromised ChatGPT credentials on the dark web, building upon past research. With more employees relying on ChatGPT for work optimization and its storage of past interactions, compromised logins could expose sensitive information, posing significant security risks for businesses.

From January 2023 to October 2023, Group-IB detected more than 225,000 logs up for sale on the dark web containing compromised ChatGPT credentials. Group-IB’s Threat Intelligence platform found these compromised credentials within the logs of information-stealing malware traded on illicit dark web marketplaces.

Notably, the number of compromised hosts with access to ChatGPT detected by Threat Intelligence between June 2023 and October 2023 was more than 130,000, an increase of 36% compared to the preceding five-month period (January-May 2023). The number of available logs containing ChatGPT logs peaked in the final month of the study – in October 2023 – when 33,080 were registered. Group-IB’s analysis found that the majority of the logs containing ChatGPT accounts were breached by the LummaC2 information stealer.

Double trouble: ransomware gangs and initial access brokers wreak havoc

Group-IB’s Threat Intelligence unit constantly monitors all ransomware activity and detected 4,583 companies that had their information, files, and data published on ransomware DLSs in 2023. This marks a growth of 74% compared to the previous year, when 2,629 such posts were made. Group-IB researchers note that the number of total ransomware attacks worldwide is likely to be much larger, with probable instances of organizations paying the ransom or groups deciding not to go ahead with their threat of publishing data on a DLS.

Companies based in North America most commonly appeared in the DLS posts of ransomware groups, accounting for 2,487 (or 54%) of the annual total, and more than double the corresponding figure in 2022 (1,192 companies). Roughly 26% of posts on ransomware DLSs related to companies from Europe (1,186, up 52% YoY) and 10% were from the APAC region (463, up 39% YoY).

The United States was the most common target for ransomware groups, as 1,060 US-based companies were the subject of ransomware DLS posts in 2023. The next most affected countries were Germany (129), Canada (115), France (103), and Italy (100). 

In terms of affected industries, attacks as per ransomware DLS on manufacturing (580 instances) and real estate (429) companies rose year-on-year by 125% and 165%, respectively, and these key sectors were the two most targeted worldwide. Notably, Group-IB observed a 88% year-on-year increase in ransomware DLS posts related to healthcare companies, and a 65% rise in posts concerning government and military organizations.

Throughout the reporting period, Group-IB experts uncovered 27 new advertisements for ransomware-as-a-service programs on dark web forums, including well-known groups such as Qilin, as well as other collectives that have yet to be seen in the wild. As was the case in 2022, LockBit was 2023’s most prominent ransomware-as-a-service group with 1,079 posts on its DLS (24% of the annual total). In second place was BlackCat with 427 posts (9% of annual total) and third was Clop (385 posts or 9%).

Researchers also found that Initial Access Brokers (IABs) are continuing to play a significant role in the ransomware market. In 2023, they found 2,675 instances of corporate put up for sale – almost an identical figure compared with 2022, when 2,702 offers were found.

Notably, Group-IB data shows that the average price for corporate access in 2023 was $2,470, which represents a 27% reduction compared to the preceding year. Group-IB analysts believe that this drop in average price is due to a rise in the number of new sellers entering the market that have lowered the price of their offers in order to attract buyers.

Companies in the United States (29%), the United Kingdom (4%) and Brazil (4%) were the most commonly featured in IAB offers. Professional services, government and military organizations, financial services, manufacturing, and real estate were the verticals that appeared most frequently.

APTitude test

Group-IB researchers discovered that the Asia-Pacific region was the world’s main battleground for nation-state sponsored threat actors, also known as advanced persistent threat (APT) groups last year. In sum, Group-IB attributed 523 attacks to nation-state actors across the globe in 2023.

Attacks on APAC organizations accounted for 34% of the global total, with Group-IB experts asserting that this may be due to the high level of financial technology development in this global economic hub in addition to geopolitical tensions. Europe was the second-most targeted region, accounting for 22% of all APT attacks, and the Middle East and Africa (MEA) was third (16% of APT attacks in 2023).

Unsurprisingly, government and military entities were the prime target of APT attacks in 2023, accounting for 28% of the annual figure. This strengthens the theory of Group-IB’s Threat Intelligence unit that APT actors are predominantly striving to gain access to strategically important evidence and weaken government entities in their country or region of target. Financial services (6%), telecommunications (5%), manufacturing, IT and media (all 4%) were also heavily affected, Group-IB researchers found.

In the past year, prominent APT groups, including the North Korean collective Lazarus, launched new tactics. Lazarus executed the first-ever double supply chain attack, exploiting a vulnerability in X_TRADER, a software by Trading Technologies. This allowed access to the network of the widely-used 3CX Desktop App for VoIP calls, compromising a wide range of 3CX clients. Group-IB researchers also noted APT groups’ ongoing malicious use of legitimate services like Dropbox, OneDrive, Google Drive, and messengers like Telegram.

Turbulence ahead

In 2023, cyber threats shifted focus from Windows and Android to Apple platforms due to their rising popularity and market share, with iOS becoming increasingly targeted. Malware spread through the App Store, alongside increased use of Apple cloud services, contributed to this trend. By March 6, 2024, Apple is expected to allow third-party app stores for iOS apps in Europe, posing security concerns amidst 1.7 million app rejections in 2022. Threat actors have already adapted Android schemes to iOS, exemplified by GoldFactory and the GoldPickaxe.iOS malware – аctive in Thailand and Vietnam – which prompts victims to record videos of their faces and submit them to the threat actors, which could be used by the latter to gain unauthorized access to the victim’s banking accounts. Additionally, the number of sales posts on the most popular underground forums (xss[.]is and exploit[.]in) for information stealers designed to operate on macOS increased fivefold in 2023, from 8 in 2022 to 49.

Javascript sniffers, also known as malicious JavaScript code implanted in compromised websites designed to intercept payment card details from customers who make online transactions, are also likely to pose a risk to online store owners, consumers, and banks in 2024. Group-IB researchers discovered 5,037 websites compromised with JS-sniffers in 2023, of which 2,474 were unique. A total of 14 new JS-sniffer families were also discovered in 2023, highlighting the continued development of this threat.

“As highlighted by Group-IB’s Hi-Tech Crime Trends 2023/2024 report, the rise of AI in both legitimate businesses and the cybercriminal underworld was a critical trend of 2023. With the increased misuse of ChatGPT and the development of underground LLM tools, the potential for sophisticated attacks has escalated, compounded by the alarming surge in compromised ChatGPT credentials. This along with cybercriminals’ increased interest in malware designed for macOS demonstrates that it is imperative for organizations to recognize and address this evolving threat landscape, safeguarding sensitive information and fortifying cybersecurity measures to mitigate risks posed by AI-driven cybercrime,” Dmitry Volkov, CEO at Group-IB, said.

A full round-up of the top global threats and invaluable insights from the Group-IB Threat Intelligence unit can be found in the full Hi-Tech Crime Trends 2023/2024 report.

View original content to download multimedia:https://www.prnewswire.com/news-releases/group-ib-reveals-hi-tech-crime-trends-2324-surge-in-ransomware-against-backdrop-of-growing-ai-macos-threats-302075538.html

SOURCE Group-IB

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Technology

AIE Graduates create visual effects for Academy-nominated film

Published

on

By

NAWI, a feature film whose visual effects were created by graduates from the Academy of Interactive Entertainment (AIE), has been officially nominated by Kenya for entry into the 97th Academy Awards in the category of Best International Feature Film. NAWI is a heartfelt story about a young girl’s journey towards empowerment and aims to shed light on a pressing issue that affects countless young women in the Turkana region of Kenya.

CANBERRA, Australia, Sept. 19, 2024 /PRNewswire-PRWeb/ — NAWI, a feature film whose visual effects were created by graduates from the Academy of Interactive Entertainment (AIE), has been officially nominated by Kenya for entry into the 97th Academy Awards in the category of Best International Feature Film. NAWI is a heartfelt story about a young girl’s journey towards empowerment and aims to shed light on a pressing issue that affects countless young women in the Turkana region of Kenya.

“The film has a very important social message to tell so it was rewarding in many ways to be able to contribute to this project. NAWI was a fantastic opportunity for our graduates to put their skills to the test on a full-length feature film,” said Tom Pugh.

AIE graduates and teachers were given the opportunity to work on the film’s visual effects through AIE’s ongoing partnership with Learning Lions, who produced the film with Film Crew & Baobab Pictures. AIE is proud to support Learning Lions non-profit mission to enable young adults in marginalised rural communities of East Africa to become digital creatives by providing game development training and technology.

The visual effects for NAWI were brought to life by AIE teachers and experienced industry professionals, Thomas Magill and Tom Pugh, who were tasked with supervising the visual effects and liaising with the film’s Directors, Apuu Mourine, Kevin Schmutzler, Tobias Schmutzler and Toby Schmutzler. They assembled a team of recent AIE graduates and worked out how to create the effects required to immerse audiences in Nawi’s world.

“Graduates were able to take the skills they had learnt in class and apply them to cinema-quality footage. There was even a bit of nervous excitement working with professional expectations and deadlines,” said Tom Pugh.

Thomas Magill explained that most of the work involved compositing such as fixing blemishes, removing unwanted folds in clothing, changing pages in a book and removing background actors that were in the wrong place.

“We had a river shot where there was only a sandbank, and we had to create an entire island! There were several shots filmed in a dry riverbed which required us to create floodwater. We had to draw upon various disciplines: not just digital compositing but also visual effects creation and fluid simulations,” said Thomas Magill.

Both teachers enthused that the directors were a pleasure to work with and the collaboration was smooth.

“The film has a very important social message to tell so it was rewarding in many ways to be able to contribute to this project. NAWI was a fantastic opportunity for our graduates to put their skills to the test on a full-length feature film,” said Tom Pugh.

Learning Lions and AIE look forward to seeing NAWI progress through two rounds of voting by members of the Academy of Motion Picture Arts and Sciences to narrow the list of submitted films down to five nominees for the Best International Feature Film.

About Academy of Interactive Entertainment (AIE)

AIE offers practical, career-focused courses delivered by industry-experienced teachers in 3D animation, game development, visual effects and film. Since 2019 AIE has sponsored scholarships to their Certificate and Diploma programs to Learning Lions student. AIE provided laptops and is supporting with opportunities at various gaming companies around the world for paid part-time and full-time work.

https://aie.edu.au/

About Learning Lions

Learning Lions is fighting poverty with digital opportunity. Established in 2015, Learning Lions equips local youth with essential IT and media skills, and empowering them to become entrepreneurs and self-sustaining individuals. By leveraging digital services, these aspiring entrepreneurs not only support themselves but also provide opportunities for others through employment and mentorship.

https://www.learninglions.org/

Media Contact

Neil Boyd, Academy of Interactive Entertainment, 61 434273190, neilb@aie.edu.au, https://aie.edu.au/

Facebook, LinkedIn

View original content to download multimedia:https://www.prweb.com/releases/aie-graduates-create-visual-effects-for-academy-nominated-film-302252825.html

SOURCE Academy of Interactive Entertainment

Continue Reading

Technology

Valhalla MSO Launches Impetus One to Enhance Valhalla Vitality’s Telehealth Platform

Published

on

By

Valhalla MSO launches Impetus One, enabling healthcare providers to expand services, improve patient retention, and boost revenue with no upfront costs

MIAMI, Sept. 19, 2024 /PRNewswire-PRWeb/ — Valhalla MSO is excited to announce the launch of Impetus One (IO), a new software designed to power the Valhalla Vitality Network Provider Program. This initiative aims to expand the reach and capabilities of independent healthcare providers by offering an alternative to the traditional insurance model. With a focus on preventative medicine and wellness therapies, the platform is set to enhance patient care while creating new revenue opportunities for providers.

The Valhalla Vitality Network Provider Program addresses the gap created by insurance companies that often deny coverage for preventative medicine, wellness services, and even weight loss therapies. Insurance typically does not compensate healthcare providers for the time spent improving a patient’s overall health. Impetus One (IO) offers an alternative by providing a cash-pay marketplace where providers are fairly compensated for delivering impactful, life-changing services to their patients.

Key Benefits for Providers

Impetus One Software Integration: The platform integrates seamlessly with Valhalla Vitality, offering an e-commerce marketplace that connects patients with a wide range of health services. Providers can easily adopt the system to deliver therapies and other services, ensuring smooth payment processing and order fulfillment.No Upfront Costs: Providers can join the Network Provider Program without any initial fees. They simply share a unique link with patients, allowing for easy access to services, and payments are processed as orders are placed. Partner pharmacies handle medication shipments directly, creating a hassle-free experience for providers.Boosting Patient Retention: The platform includes a VIP Rewards Program, designed to increase patient retention and loyalty. Patients earn points for discounts and exclusive benefits, which encourages ongoing engagement and care continuity.E-commerce and Wellness Integration: Unlike typical affiliate programs, Valhalla Vitality allows providers to retain full control of their patient relationships. Providers can generate revenue through the integrated e-commerce system without worrying about referral fees or kickbacks, enabling them to focus solely on delivering high-quality patient care.

By joining the Valhalla Vitality Network Provider Program, healthcare providers gain access to a scalable model that helps increase profits, introduce new services, and enhance patient satisfaction. The VIP Rewards Program also strengthens the bond between patients and providers, making healthcare more accessible and rewarding for all.

Healthcare providers looking to grow their practices and increase revenue can join the Valhalla Vitality Network by visiting http://www.providevitality.com. Valhalla MSO’s new platform is a powerful tool for delivering advanced, patient-centric healthcare with a focus on accessibility and quality.

For more information, visit Valhalla Vitality at http://www.valhallavitality.com.

Media Contact

Chris K., Valhalla Vitality, 888-888-8888, ck@s99agency.com, https://valhallavitality.com/

View original content to download multimedia:https://www.prweb.com/releases/valhalla-mso-launches-impetus-one-to-enhance-valhalla-vitalitys-telehealth-platform-302253701.html

SOURCE Valhalla Vitality

Continue Reading

Technology

Ultima Markets Wins Two Prestigious Awards at Global Forex Awards–Retail 2024!

Published

on

By

LIMASSOL, Cyprus, Sept. 19, 2024  /CNW/ — Ultima Markets, a leading global forex and CFDs brokerage, is thrilled to announce its double success at the prestigious Global Forex Awards – Retail 2024. The company won two distinguished awards: “Best Affiliates Brokerage – Global” and “Best Fund Safety – Global.”

The awards were presented during the event in Limassol, Cyprus, where Jean Philippe, Board Advisor, Corporate Governance and Sustainability at Ultima Markets, accepted the honours.

The Global Forex Awards – Retail has celebrated excellence in trading innovation for seven consecutive years. Ultima Markets’ dual wins reflect its commitment to quality, client-centric strategies, and strong partnerships across the financial services sector.

The “Best Affiliates Brokerage—Global” award recognises Ultima Markets’ exemplary affiliate programme, which has successfully driven its global expansion. It is celebrated for its transparency and competitive rewards tailored to affiliate needs.

Receiving the “Best Fund Safety – Global” award highlights Ultima Markets’ efforts to safeguard client assets. Through its partnership with Willis Towers Watson, the company provides up to USD$1,000,000 in insurance per account, while its Financial Commission membership ensures clients access to up to €20,000 in compensation funds.

These recognitions underscore Ultima Markets’ priority to security and transparency, including segregated accounts and robust risk management practices. The broker also assures affiliate partners of exceptional standards.

Commenting on the awards, Jean Philippe said, “These recognitions reflect the exceptional work of our teams to ensure the safety of traders’ funds and our dedication to creating value for our partners and clients. We will continue to evolve and innovate to meet the market’s demands.”

Ultima Markets is renowned for its extensive range of trading products and personalised customer service, designed to meet clients’ diverse needs worldwide. The dual recognition marks a significant milestone in the company’s global growth and reaffirms its reputation for delivering fund safety and robust affiliate opportunities.

“We are delighted to be recognised with these awards, which reflect our mission to create a secure trading environment and build strong, rewarding partnerships,” said Jack Li, Ultima Markets’ Regional Business Director.

About Ultima Markets

Ultima Markets is a fully licensed, fast-growing broker offering access to 250+ financial instruments. With a team of 2,000+ professionals in 15 global offices, we serve clients in 172 countries. Check out more about our awards on Facebook, X, Instagram, LinkedIn and YouTube.

 

 

View original content to download multimedia:https://www.prnewswire.com/news-releases/ultima-markets-wins-two-prestigious-awards-at-global-forex-awardsretail-2024-302253541.html

SOURCE Ultima Markets

Continue Reading

Trending