Group-IB A.I CyberSecurity Scoring
Group-IB
Company Information
Website:https://www.group-ib.com
Employees number:566
Number of followers:169,472
NAICS:541514
Industry Type:Computer and Network Security
Homepage:group-ib.com
Group-IB Risk Score (AI oriented)
Between 0 and 549
Group-IBComputer and Network Security
Updated:
02/10/2026
02/10/2026
465/1000
Critical
C
Group-IB Global Score (TPRM)
xxxx
Group-IBComputer and Network Security
Score locked

Group-IBCritical
Current Score
465C (CRITICAL)
01000
5 incidents
-91 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
OCTOBER 2026
622
Ransomware
30 Sep 2026 • Group-IB
VMware, KillSec and Group-IB: Police take down dangerous KillSec ransomware gang — and find out it's being run by a teenager
Operation KillSwitch: Dismantling of KillSec Ransomware Group
464
CRITICAL-158
VMWGRO1790943965
Operation KillSwitch: Europol and Global Partners Dismantle KillSec Ransomware Group
On September 30, a multinational law enforcement operation Operation KillSwitch successfully dismantled the notorious ransomware group KillSec, seizing its infrastructure, cryptocurrency assets, and 110TB of stolen data. Led by German authorities, the operation involved Europol, Eurojust, and agencies from 10 countries, including the U.S., U.K., and several EU nations, alongside cybersecurity firm Group-IB.
KillSec, active since 2024, executed roughly 1,000 attacks worldwide, with at least 50% believed successful. The group primarily targeted healthcare, financial services, government entities, and SMBs, exploiting weak cloud and internet security. While it focused on smaller organizations, it also breached large enterprises and government bodies, including a major insurer, investment firms, and a consumer app with millions of users. Victims were concentrated in the U.S. (35%), followed by India (17%), Brazil, the U.K., Australia, and Colombia.
Investigators identified at least four core members: a 16-year-old ringleader (identity undisclosed), a developer (who turned 18 but committed crimes as a minor), a negotiator, and an affiliate. The group’s size may have been larger, as the investigation remains ongoing. Three arrests were made during the operation, though the ringleader was not among them. Authorities conducted eight house searches across Spain, Greece, Romania, and the U.K., seizing five central servers, multiple domains, and cryptocurrency proceeds from extortion.
KillSec initially targeted Windows systems but later expanded to VMware ESXi hosts with its KillSec 2.0 affiliate platform, released in late 2024. The platform enabled affiliates to shut down virtual machines, delete snapshots, and erase logs, while the group took a 20% cut of ransom payments. By early 2025, KillSec was openly recruiting skilled penetration testers, requiring either a forum reputation or a $1,000 deposit.
The takedown marks a significant blow to one of 2025’s most active ransomware operations, particularly in Asia-Pacific, Latin America, and the Middle East. While infrastructure can be rebuilt, law enforcement’s focus on identifying and prosecuting key members aims to prevent a rapid resurgence. The operation underscores the growing collaboration between global agencies and private cybersecurity firms in combating cybercrime.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
SEPTEMBER 2026
620
AUGUST 2026
617
JULY 2026
616
JUNE 2026
613
MAY 2026
612
Vulnerability
08 May 2026 • Group-IB
Group-IB: Pam Backdoor Targets Linux Systems to Steal SSH Credentials
New Linux Backdoor 'PamDOORa' Exploits PAM to Steal SSH Credentials
608
LOW-4
GRO1778250579
New Linux Backdoor "PamDOORa" Exploits PAM to Steal SSH Credentials
Security researchers from Group-IB’s DFIR team have identified a novel Linux backdoor technique, dubbed PamDOORa, that abuses Pluggable Authentication Modules (PAM) to harvest SSH credentials and maintain stealthy persistence on compromised systems.
PAM, a modular authentication framework introduced in Linux in 1991, allows administrators to customize authentication workflows for applications like sshd, login, and su. While its flexibility enhances security, it also creates attack surfaces when misconfigured. The pam_exec module, designed to execute external commands during authentication, is being weaponized in this campaign.
In the PamDOORa attack, threat actors modify PAM configuration files (e.g., `/etc/pam.d/sshd`) to inject a malicious script that triggers during SSH login attempts. The script captures usernames, timestamps, and environment variables (e.g., `PAM_USER`, `PAM_RHOST`) and exfiltrates them to a remote command-and-control (C2) server via tools like netcat (nc). The attack leverages the optional control flag in PAM, ensuring the malicious execution does not disrupt authentication or raise alarms even if login attempts fail.
A key concern is its stealth: PAM’s internal handling of authentication means the credential theft leaves minimal traces in system logs, complicating detection. Traditional monitoring may only flag failed logins, masking the underlying data exfiltration.
The technique underscores how legitimate Linux features can be repurposed for covert attacks. Organizations running Linux servers particularly those exposed to external networks are advised to audit PAM configurations, monitor unauthorized changes, and enforce stricter logging and execution controls. The discovery highlights the risks of trusted frameworks when misconfigured, as Linux’s dominance in enterprise and cloud environments makes it an attractive target.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
APRIL 2026
721
Ransomware
12 Apr 2026 • Group-IB
RansomHub: 0APT ransomware gang extorts Krybit amid doxxing threat
0APT Threatens to Expose Krybit Ransomware Operatives
610
CRITICAL-111
GRO1776176694
Rival Ransomware Gangs Clash as 0APT Threatens to Expose Krybit Operatives
In an unusual escalation within the cybercriminal underworld, the ransomware group 0APT has targeted a rival outfit, Krybit, threatening to expose its affiliates unless a payment is made. The confrontation, first observed by dark web monitors on Sunday, follows the standard double-extortion playbook leaking a sample of stolen data as leverage but with a twist: the victim is another criminal operation.
0APT, which launched in January 2026, accused Krybit of being a ransomware group that "poses significant risks to cybersecurity and data privacy worldwide," despite engaging in the same illicit activities. The group warned that if Krybit failed to comply, it would release identity photos, names, locations, and other sensitive details of its members. As an added incentive, 0APT offered to unlock data for Krybit’s victims though the practical impact of such an offer remains questionable, given the target’s lack of reputational concerns.
Security researchers at Barricade Cyber Solutions analyzed the leaked data and found plaintext credentials, five cryptocurrency wallet addresses, and no evidence of paid ransoms suggesting Krybit may be a fledgling operation. Meanwhile, Krybit’s website is currently offline, displaying a generic maintenance message.
While 0APT has been labeled a "legitimate threat" with "credible technical depth" by Halcyon’s ransomware research center, its initial victim claims were widely seen as inflated. Krybit, by contrast, remains poorly documented, with dark web tracking platforms indicating it has only been active for a few weeks.
This isn’t the first time cybercriminals have turned on each other. In 2025, DragonForce attacked rivals BlackLock and Mamona, defacing their sites and leaking internal communications. The group later seized control of RansomHub’s operations in April 2025 following a month-long feud, ultimately dismantling the once-dominant ransomware enterprise.
The incident underscores the paranoia and infighting within the ransomware ecosystem, where even criminal groups are not immune to extortion though the effectiveness of such tactics against fellow threat actors remains debatable.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MARCH 2026
720
FEBRUARY 2026
719
JANUARY 2026
718
DECEMBER 2025
717
NOVEMBER 2025
716
OCTOBER 2025
732
Cyber Attack
01 Oct 2025 • Group-IB
Balonx Sistema: Hackers Use AI Voice Calls and Fake Banking Pages to Bypass MFA and Steal Accounts
AI-Powered Phishing Campaign Targets Mexican Banking Customers in Real-Time Fraud Scheme
714
CRITICAL-18
GRO1787156738
AI-Powered Phishing Campaign Targets Mexican Banking Customers in Real-Time Fraud Scheme
A sophisticated phishing-as-a-service (PhaaS) operation, tracked as Balonx Sistema, is combining AI-generated voice calls, live phishing pages, and Android malware to bypass multi-factor authentication (MFA) and hijack customer accounts at over 20 Mexican financial institutions. Since at least October 2025, the campaign has compromised credentials and financial data from more than 1,100 victims, leveraging a subscription-based model to enable large-scale fraud.
### How the Attack Works
Balonx operates as a real-time phishing platform, using a persistent WebSocket connection to synchronize fraudulent pages with an attacker’s control panel. When a victim enters login details, the operator relays them to the legitimate bank site, triggering an MFA prompt then immediately displays a fake verification screen to capture the code. The platform supports 14 different screen types, allowing attackers to dynamically adapt the scam, requesting SMS codes, ATM PINs, card details, or cardless-withdrawal codes under the guise of a security check.
A separate CallFlow module enhances social engineering by using AI-driven voice synthesis to impersonate a bank representative (e.g., "Carolina"). The system automates outbound calls, making interactions feel personalized while steering victims toward phishing pages. In some cases, attackers push a malicious Android app disguised as a "bank-protection alert," which installs a Spyroid-based remote access trojan (RAT). Once deployed, the malware exfiltrates screen content, keystrokes, SMS messages, and banking app activity, enabling prolonged device control.
### Infrastructure and Evasion Tactics
Balonx’s infrastructure, exposed via leaked GitHub repositories, reveals a rotating domain strategy to evade takedowns. Key indicators include:
- Phishing domains: `aclaraciones-digital[.]online`, `soporte-aclaracion[.]xyz`
- AI vishing portal: `callbalonx[.]info`
- Android RAT C2 server: `196.251.84[.]11:7771/TCP`
- Malicious APK: Package name `sacred.explosion`, delivered via a fake "bank-protection" screen
The platform’s real-time relay technique exploits the gap between legitimate MFA prompts and fraudulent responses, making security checks appear authentic. Financial institutions are advised to monitor for unusual WebSocket activity, suspicious redirect chains, and high-risk MFA requests, while FIDO2 hardware keys offer stronger protection against such attacks.
### Impact and Scope
Balonx lowers the barrier for cybercriminals by offering subscription-based access, including individual and office plans for multiple operators. Its automation and scalability make it a potent tool for large-scale banking fraud, with affiliates targeting customers through urgent calls, fake websites, and malicious apps. The campaign underscores the limitations of SMS-based MFA when attackers can intercept codes in real time. Victims are urged to verify unexpected calls independently and avoid installing apps from unverified sources.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
APRIL 2020
757
Data Leak
01 Apr 2020 • Group-IB
Group-IB
Group-IB Data Breach
672
CRITICAL-85
GRO1837291222
Group-IB, a Singapore-based cybersecurity company, experienced a data breach.
It found a dump containing details for nearly 400,000 payment card records uploaded to a popular darknet card shop on April 9.
The database was comprised almost entirely of the payment records related to banks and financial organizations in South Korea and the US.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Group-IB ??
What was Group-IB's A.I Rankiteo Cyber Score in September 2026 ??
What was Group-IB's A.I Rankiteo Cyber Score in August 2026 ??
What was Group-IB's A.I Rankiteo Cyber Score in July 2026 ??
What was Group-IB's A.I Rankiteo Cyber Score in June 2026 ??
What was Group-IB's A.I Rankiteo Cyber Score in May 2026 ??
What was Group-IB's A.I Rankiteo Cyber Score in April 2026 ??
What was Group-IB's A.I Rankiteo Cyber Score in March 2026 ??
What was Group-IB's A.I Rankiteo Cyber Score in February 2026 ??
What was Group-IB's A.I Rankiteo Cyber Score in January 2026 ??
What was Group-IB's A.I Rankiteo Cyber Score in December 2025 ??
What was Group-IB's A.I Rankiteo Cyber Score in November 2025 ??
What is the average per-incident point impact on Group-IB's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Group-IB ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Group-IB's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?