Group-IB
group-ib · B · active
https://www.group-ib.com/blog/
Singapore-headquartered global CTI firm. WebFetch returns HTTP 403 (re-confirmed 2026-05-08); RSS at /blog/feed/ also 403. Bridge fetcher would need www.group-ib.com on its allowlist — not currently allowed because the publisher's WAF was observed to drop the bridge UA too in earlier tests. Surface as coverage gap. Retest periodically; recover to `active` if a CSAF/RSS becomes available. | 2026-06-20 full audit (v2. Remains a coverage gap; WebSearch-only discovery. Do NOT WebFetch or bridge — it will 503. Recover if a CSAF/RSS becomes available. | 2026-07-05 admiralty audit: B — global CTI vendor, original research. RECOVER demoted -> active: the WAF no longer drops the bridge UA (listing + article body both fetch 200; newest post 1 Jul 2026). Operator: change fetch_method blocked -> bridge. | 2026-07-06 jina-fallback recovery: DONE — fetch_method blocked -> bridge. RECIPE: `python3 tools/fetch_source.py url https://www.group-ib.com/blog/` returns 200 (~800 KB real blog, current posts); the `url` command auto-falls-back to the r.jina.ai reader (`jina <URL>`, ~128 KB) if the Cloudflare Managed-Challenge ever returns, so there are two working transports. Removed from source_health TRANSPORT_BLOCKED_UNREACHABLE; probes bridge-ok. RSS at /blog/feed/ still 403 — use the `url`/`jina` HTML path, drill per-article /blog/<slug>/. | 2026-08-03 weekly: direct WebFetch still returns HTTP 503, but `python3 tools/fetch_source.py url https://www.group-ib.com/blog/<slug>/` returns the full article body and the blog RSS at /blog/rss.xml lists in-window posts. Recipe confirmed working; contributed a research finding this run.
Cited in 6 entries
Citation cadence
Citation days per ISO week (3 weeks of coverage span, total 5).
- This week's tradecraft converged on hiding command-and-control inside trusted services and native tooling — Graph-API calendars, DNS, the Telegram API, a browser the malware never connects through, and BitLocker instead of a ransomware binary2026-07-26
- HOLLOWGRAPH: a Cavern-framework backdoor that turns a compromised Microsoft 365 calendar into a Graph-API dead-drop C22026-07-21
- ClickFix was the week's universal crimeware delivery vector, and macOS gained a coercion playbook — five families this week converged on paste-into-terminal delivery, local password validation before theft, and decentralized dead-drop C22026-07-19
- ClickLock Stealer — a macOS ClickFix infostealer that force-kills every visible app until the victim types their login password2026-07-19
- Threat-actor developments this week: Group-IB reframes Scattered Spider as a decentralised collective, and China- and Iran-nexus edge/ORB tradecraft advances2026-07-12
- RedHook Android RAT abuses ADB Wireless Debugging to self-grant shell (uid 2000) privileges without an exploit2026-07-09