Skip to content

Group-IB vulnerabilities

In our reporting, Group-IB primarily appears as a threat intelligence and research entity uncovering new cyber threats. The key themes include the China-nexus JadeProx operation using the TriBack Loader against government and healthcare sectors, the HollowGraph malware abusing Microsoft 365 calendars for command-and-control (C2), and the new WindRelay Android malware relaying NFC payment data to fraudsters in real time. As no CVE explainers are provided, specific vulnerabilities cannot be linked, and defenders should instead focus on monitoring for the tactics, techniques, and procedures (TTPs) associated with these newly discovered malware families. Detection mechanisms should be enhanced for anomalous calendar activities in Microsoft 365 environments, unexpected NFC usage on mobile devices, and the deployment of novel loaders targeting government entities.

Azərbaycanca: Hesabatlarımızda Group-IB ilk növbədə yeni kibertəhdidləri aşkarlayan və adlandıran təhlükəsizlik tədqiqat qrupu kimi görünür. Əsas müşahidə olunan mövzulara Çinlə əlaqəli JadeProx qrupunun TriBack Loader ilə hökumət və səhiyyə sektorlarına hücumları, HollowGraph adlı zərərli proqramın komanda-kanal (C2) üçün Microsoft 365 təqvimindən sui-istifadə etməsi və WindRelay adlı yeni Android zərərli proqramının NFC vasitəsilə real vaxtda ödəniş məlumatlarının oğurlanması daxildir. Bu hesabatlar bağlı CVE məlumatları təqdim olunmadığı üçün konkret zəifliklərə diqqət yetirmək əvəzinə, müdafiəçilər bu yeni zərərli proqramların taktika, texnika və prosedurlarına (TTP) qarşı monitorinq aparmalıdır. Xüsusilə Microsoft 365 mühitlərində anomal təqvim fəaliyyətlərinə, mobil cihazlarda NFC funksiyasının gözlənilməz istifadəsinə və hökumət qurumlarını hədəfləyən yeni yükləyicilərə qarşı deteksiya mexanizmləri gücləndirilməlidir.

This hub is built from skopnix's own reporting on Group-IB: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.