Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Group-IB

Group-IB Vendor Cyber Rating & Cyber Score

group-ib.com

Founded in 2003 and headquartered in Singapore, Group-IB is a leading creator of cybersecurity technologies to investigate, prevent, and fight digital crime. Combating cybercrime is in the company’s DNA, shaping its technological capabilities to defend businesses, citizens, and support law enforcement operations. Group-IB’s Digital Crime Resistance Centers (DCRCs) are located in the Middle East, Europe, and Asia-Pacific to help critically analyze and promptly mitigate regional and country-specific threats. These mission-critical units help Group-IB strengthen its contribution to global cybercrime prevention and continually expand its threat-hunting capabilities. Group-IB’s decentralized and autonomous operational structure helps it offer


Group-IB A.I CyberSecurity Scoring

Group-IB
Company Information
Website:https://www.group-ib.com
Employees number:475
Number of followers:131,374
NAICS:541514
Industry Type:Computer and Network Security
Homepage:group-ib.com
Group-IB Risk Score (AI oriented)
Between 600 and 649
logo
Group-IBComputer and Network Security
Updated:
08/05/2026
624/1000
Poor
Caa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Group-IB Global Score (TPRM)
xxxx
logo
Group-IBComputer and Network Security
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Group-IB
Group-IBPoor
Current Score
624Caa (POOR)
01000
3 incidents
-56.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
632Before Incident
JULY 2026
631Before Incident
JUNE 2026
629Before Incident
MAY 2026
629Before Incident
Vulnerability
08 May 2026Group-IB
Group-IB: Pam Backdoor Targets Linux Systems to Steal SSH Credentials

New Linux Backdoor 'PamDOORa' Exploits PAM to Steal SSH Credentials

624After Incident
LOW-5
GRO1778250579
New Linux Backdoor "PamDOORa" Exploits PAM to Steal SSH Credentials Security researchers from Group-IB’s DFIR team have identified a novel Linux backdoor technique, dubbed PamDOORa, that abuses Pluggable Authentication Modules (PAM) to harvest SSH credentials and maintain stealthy persistence on compromised systems. PAM, a modular authentication framework introduced in Linux in 1991, allows administrators to customize authentication workflows for applications like sshd, login, and su. While its flexibility enhances security, it also creates attack surfaces when misconfigured. The pam_exec module, designed to execute external commands during authentication, is being weaponized in this campaign. In the PamDOORa attack, threat actors modify PAM configuration files (e.g., `/etc/pam.d/sshd`) to inject a malicious script that triggers during SSH login attempts. The script captures usernames, timestamps, and environment variables (e.g., `PAM_USER`, `PAM_RHOST`) and exfiltrates them to a remote command-and-control (C2) server via tools like netcat (nc). The attack leverages the optional control flag in PAM, ensuring the malicious execution does not disrupt authentication or raise alarms even if login attempts fail. A key concern is its stealth: PAM’s internal handling of authentication means the credential theft leaves minimal traces in system logs, complicating detection. Traditional monitoring may only flag failed logins, masking the underlying data exfiltration. The technique underscores how legitimate Linux features can be repurposed for covert attacks. Organizations running Linux servers particularly those exposed to external networks are advised to audit PAM configurations, monitor unauthorized changes, and enforce stricter logging and execution controls. The discovery highlights the risks of trusted frameworks when misconfigured, as Linux’s dominance in enterprise and cloud environments makes it an attractive target.
INCIDENT DETAILS -
TYPE
Backdoor
IMPACT
Data Compromised: SSH credentials (usernames, timestamps, environment variables)Systems Affected: Linux servers with PAM configurations (e.g., /etc/pam.d/sshd)Operational Impact: Potential unauthorized access to systems via stolen SSH credentialsIdentity Theft Risk: High (stolen SSH credentials could lead to further compromise)
DATA BREACH
Type Of Data Compromised: SSH credentials (usernames, timestamps, environment variables)Sensitivity Of Data: High (could enable further system compromise)Data Exfiltration: Yes (to remote C2 server via netcat)
APRIL 2026
735Before Incident
Ransomware
12 Apr 2026Group-IB
RansomHub: 0APT ransomware gang extorts Krybit amid doxxing threat

0APT Threatens to Expose Krybit Ransomware Operatives

627After Incident
CRITICAL-108
GRO1776176694
Rival Ransomware Gangs Clash as 0APT Threatens to Expose Krybit Operatives In an unusual escalation within the cybercriminal underworld, the ransomware group 0APT has targeted a rival outfit, Krybit, threatening to expose its affiliates unless a payment is made. The confrontation, first observed by dark web monitors on Sunday, follows the standard double-extortion playbook leaking a sample of stolen data as leverage but with a twist: the victim is another criminal operation. 0APT, which launched in January 2026, accused Krybit of being a ransomware group that "poses significant risks to cybersecurity and data privacy worldwide," despite engaging in the same illicit activities. The group warned that if Krybit failed to comply, it would release identity photos, names, locations, and other sensitive details of its members. As an added incentive, 0APT offered to unlock data for Krybit’s victims though the practical impact of such an offer remains questionable, given the target’s lack of reputational concerns. Security researchers at Barricade Cyber Solutions analyzed the leaked data and found plaintext credentials, five cryptocurrency wallet addresses, and no evidence of paid ransoms suggesting Krybit may be a fledgling operation. Meanwhile, Krybit’s website is currently offline, displaying a generic maintenance message. While 0APT has been labeled a "legitimate threat" with "credible technical depth" by Halcyon’s ransomware research center, its initial victim claims were widely seen as inflated. Krybit, by contrast, remains poorly documented, with dark web tracking platforms indicating it has only been active for a few weeks. This isn’t the first time cybercriminals have turned on each other. In 2025, DragonForce attacked rivals BlackLock and Mamona, defacing their sites and leaking internal communications. The group later seized control of RansomHub’s operations in April 2025 following a month-long feud, ultimately dismantling the once-dominant ransomware enterprise. The incident underscores the paranoia and infighting within the ransomware ecosystem, where even criminal groups are not immune to extortion though the effectiveness of such tactics against fellow threat actors remains debatable.
INCIDENT DETAILS -
TYPE
Ransomware, Cyber Extortion, Data Leak
MOTIVATION
Extortion, Rivalry, Disruption of Competing Cybercriminal Operations
IMPACT
Data Compromised: Identity photos, names, locations, plaintext credentials, cryptocurrency wallet addressesSystems Affected: Krybit's website (offline, displaying maintenance message)Operational Impact: Disruption of Krybit's operationsBrand Reputation Impact: Potential reputational damage to Krybit within the cybercriminal underworldIdentity Theft Risk: High (exposure of personal details of Krybit operatives)Payment Information Risk: High (exposure of cryptocurrency wallet addresses)
DATA BREACH
Personal Identifiable Information (PII)CredentialsCryptocurrency Wallet AddressesSensitivity Of Data: High (identity photos, names, locations, plaintext credentials)Data Exfiltration: Yes (sample leaked as leverage)Personally Identifiable Information: Yes (identity photos, names, locations)
MARCH 2026
735Before Incident
FEBRUARY 2026
734Before Incident
JANUARY 2026
734Before Incident
DECEMBER 2025
734Before Incident
NOVEMBER 2025
733Before Incident
OCTOBER 2025
733Before Incident
SEPTEMBER 2025
732Before Incident
APRIL 2020
757Before Incident
Data Leak
01 Apr 2020Group-IB
Group-IB

Group-IB Data Breach

672After Incident
CRITICAL-85
GRO1837291222
Group-IB, a Singapore-based cybersecurity company, experienced a data breach. It found a dump containing details for nearly 400,000 payment card records uploaded to a popular darknet card shop on April 9. The database was comprised almost entirely of the payment records related to banks and financial organizations in South Korea and the US.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Payment card recordsPayment Information Risk: High
DATA BREACH
Type Of Data Compromised: Payment card recordsNumber Of Records Exposed: 400,000Sensitivity Of Data: High

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Group-IB ?
?
What was Group-IB's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Group-IB's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Group-IB's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Group-IB's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Group-IB's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Group-IB's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Group-IB's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Group-IB's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Group-IB's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Group-IB's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Group-IB's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on Group-IB's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Group-IB ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Group-IB's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?