Group-IB
group-ib · B · active
https://www.group-ib.com/blog/
Singapore-headquartered global CTI firm. WebFetch returns HTTP 403 (re-confirmed 2026-05-08); RSS at /blog/feed/ also 403. Bridge fetcher would need www.group-ib.com on its allowlist; not currently allowed because the publisher's WAF was observed to drop the bridge UA too in earlier tests. Surface as coverage gap. Retest periodically; recover to `active` if a CSAF/RSS becomes available. | 2026-06-20 full audit (v2. Remains a coverage gap; WebSearch-only discovery. Do NOT WebFetch or bridge; it will 503. Recover if a CSAF/RSS becomes available. | 2026-07-05 admiralty audit: B, global CTI vendor, original research. RECOVER demoted -> active: the WAF no longer drops the bridge UA (listing + article body both fetch 200; newest post 1 Jul 2026). Operator: change fetch_method blocked -> bridge. | 2026-07-06 jina-fallback recovery: DONE, fetch_method blocked -> bridge. RECIPE: `python3 tools/fetch_source.py url https://www.group-ib.com/blog/` returns 200 (~800 KB real blog, current posts); the `url` command auto-falls-back to the r.jina.ai reader (`jina <URL>`, ~128 KB) if the Cloudflare Managed-Challenge ever returns, so there are two working transports. Removed from source_health TRANSPORT_BLOCKED_UNREACHABLE; probes bridge-ok. RSS at /blog/feed/ still 403, use the `url`/`jina` HTML path, drill per-article /blog/<slug>/. | 2026-08-03 weekly: direct WebFetch still returns HTTP 503, but `python3 tools/fetch_source.py url https://www.group-ib.com/blog/<slug>/` returns the full article body and the blog RSS at /blog/rss.xml lists in-window posts. Recipe confirmed working; contributed a research finding this run. | 2026-08-13: contributed the WindRelay/SpyNote NFC-relay research this run; blog RSS at https://www.group-ib.com/blog/rss.xml parsed cleanly and the article body was reachable via `fetch_source.py url`.
Cited in 6 entries
Citation cadence
Citation days per ISO week (8 weeks of coverage span, total 6).
- Nimbus Manticore (Iranian IRGC-affiliated APT, aka Tortoiseshell/UNC1549/Smoke Sandstorm/Mirage Kitten) deploys a third 2026 toolset refresh (a TWOSTROKE-like backdoor abusing DLL search-order hijacking, paired with a reverse SSH tunneler) with confirmed expansion into the UK, France, Albania and Belarus2026-08-28
- WindRelay, a purpose-built Android NFC-relay malware installed silently by a companion remote-access trojan during the fraud call itself, with per-victim app names carrying the victim's own name2026-08-13
- An intruder used pam_rootok to move between low-privileged identities as a deliberate forensic smokescreen, inverting what a responder infers from the authentication trail2026-08-10
- HOLLOWGRAPH: a Cavern-framework backdoor that turns a compromised Microsoft 365 calendar into a Graph-API dead-drop C22026-07-21
- ClickLock Stealer, a macOS ClickFix infostealer that force-kills every visible app until the victim types their login password2026-07-19
- RedHook Android RAT abuses ADB Wireless Debugging to self-grant shell (uid 2000) privileges without an exploit2026-07-09