Tech News
← Home  ·  All topics

Group Ib

2 GoKawiil briefs on this topic

Group-IB uncovers RemControl Android malware spreading via fake TVTap app

Group-IB researchers identified a new Android malware-as-a-service platform called RemControl, active since May and first sampled in July, that uses over 30 phishing overlays to steal banking credentials. The malware spreads via malvertising campaigns impersonating the TVTap IPTV app, using fake Google Play pages and Meta Pixel tracking, and targets users in Italy, France, Spain, Poland, Portugal, Canada, and parts of the Middle East.

GoldFactory's Gigabud Trojan Exploits Android Work Profiles in Indonesia Bank Fraud

Group-IB researchers found that the Chinese-speaking threat group GoldFactory has been abusing Google's Work Profile feature to clone victims' banking apps into isolated, hidden environments where fraud-detection tools can't reach. The campaign, powered by the Gigabud Android Trojan and a cloning tool called Vwork, compromised roughly 1,469 devices and 1,281 logins in Indonesia between February and July, causing nearly $1 million in losses.