Connect with us

Technology

Group-IB reveals Hi-Tech Crime Trends 23/24: surge in ransomware against backdrop of growing AI, macOS threats

Published

on

SINGAPORE, Feb. 29, 2024 /PRNewswire/ — Group-IB, a leading creator of cybersecurity technologies to investigate, prevent, and fight digital crime, is proud to announce the launch of its new report Hi-Tech Crime Trends 2023/2024, the latest edition of the company’s annual round-up of the most pressing global cyber threats to organizations and individuals. In the research, Group-IB analysts reveal how the unholy alliance between ransomware groups and Initial Access Brokers (IABs) is still the powerful engine for cybercriminal industry, evidenced by the 74% year-on-year increase in the number of companies that had their data uploaded on dedicated leak sites (DLS). Global threat actors also demonstrated increased interest in Apple platforms, exemplified by the fivefold increase in underground sales related to macOS information stealers.

The growing appetite of nation-state sponsored threat actors, also known as advanced persistent threat (APT) groups, has shown that no region is immune to cyber threats. Group-IB experts discovered a 70% increase in the number of public posts offering zero-day exploits for sale, and also identified cybercriminals’ malicious use of legitimate services and artificial intelligence (AI) infused technologies as the main cyber risks for 2024.

The first edition of Hi-Tech Crime Trends was launched 12 years ago, and the information contained in the report enables businesses, NGOs, governments, and law enforcement agencies around the world to fight cybercrime and help potential victims. For the first time, Hi-Tech Crime Trends includes a section outlining the intricate relationship between artificial intelligence (AI) and cybersecurity threats, outlining how this new technology is being leveraged by cybercriminals, including the misuse of large language models (LLM) such as ChatGPT, and the potential risks to corporate data through AI integration.

Nothing artificial about this threat

Threat actors have already shown how AI can help them develop malware only with a limited knowledge of programming languages, brainstorm new TTPs, compose convincing text to be used in social engineering attacks, and also increase their operational productivity.

Large language models (LLM) such as ChatGPT remain in widespread use, and Group-IB analysts have observed continued interest on underground forums in ChatGPT jailbreaking and specialized generative pre-trained transformer (GPT) development, looking for ways to bypass ChatGPT’s security controls. Group-IB experts have also noticed how, since mid-2023, four ChatGPT-style tools have been developed for the purpose of assisting cybercriminal activity: WolfGPT, DarkBARD, FraudGPT, and WormGPT – all with different functionalities.

FraudGPT and WormGPT are highly discussed tools on underground forums and Telegram channels, tailored for social engineering and phishing. Conversely, tools like WolfGPT, focusing on code or exploits, are less popular due to training complexities and usability issues. Yet, their advancement poses risks for sophisticated attacks.

Group-IB’s Hi-Tech Crime Trends 2023/2024 also highlighted the sale of compromised ChatGPT credentials on the dark web, building upon past research. With more employees relying on ChatGPT for work optimization and its storage of past interactions, compromised logins could expose sensitive information, posing significant security risks for businesses.

From January 2023 to October 2023, Group-IB detected more than 225,000 logs up for sale on the dark web containing compromised ChatGPT credentials. Group-IB’s Threat Intelligence platform found these compromised credentials within the logs of information-stealing malware traded on illicit dark web marketplaces.

Notably, the number of compromised hosts with access to ChatGPT detected by Threat Intelligence between June 2023 and October 2023 was more than 130,000, an increase of 36% compared to the preceding five-month period (January-May 2023). The number of available logs containing ChatGPT logs peaked in the final month of the study – in October 2023 – when 33,080 were registered. Group-IB’s analysis found that the majority of the logs containing ChatGPT accounts were breached by the LummaC2 information stealer.

Double trouble: ransomware gangs and initial access brokers wreak havoc

Group-IB’s Threat Intelligence unit constantly monitors all ransomware activity and detected 4,583 companies that had their information, files, and data published on ransomware DLSs in 2023. This marks a growth of 74% compared to the previous year, when 2,629 such posts were made. Group-IB researchers note that the number of total ransomware attacks worldwide is likely to be much larger, with probable instances of organizations paying the ransom or groups deciding not to go ahead with their threat of publishing data on a DLS.

Companies based in North America most commonly appeared in the DLS posts of ransomware groups, accounting for 2,487 (or 54%) of the annual total, and more than double the corresponding figure in 2022 (1,192 companies). Roughly 26% of posts on ransomware DLSs related to companies from Europe (1,186, up 52% YoY) and 10% were from the APAC region (463, up 39% YoY).

The United States was the most common target for ransomware groups, as 1,060 US-based companies were the subject of ransomware DLS posts in 2023. The next most affected countries were Germany (129), Canada (115), France (103), and Italy (100). 

In terms of affected industries, attacks as per ransomware DLS on manufacturing (580 instances) and real estate (429) companies rose year-on-year by 125% and 165%, respectively, and these key sectors were the two most targeted worldwide. Notably, Group-IB observed a 88% year-on-year increase in ransomware DLS posts related to healthcare companies, and a 65% rise in posts concerning government and military organizations.

Throughout the reporting period, Group-IB experts uncovered 27 new advertisements for ransomware-as-a-service programs on dark web forums, including well-known groups such as Qilin, as well as other collectives that have yet to be seen in the wild. As was the case in 2022, LockBit was 2023’s most prominent ransomware-as-a-service group with 1,079 posts on its DLS (24% of the annual total). In second place was BlackCat with 427 posts (9% of annual total) and third was Clop (385 posts or 9%).

Researchers also found that Initial Access Brokers (IABs) are continuing to play a significant role in the ransomware market. In 2023, they found 2,675 instances of corporate put up for sale – almost an identical figure compared with 2022, when 2,702 offers were found.

Notably, Group-IB data shows that the average price for corporate access in 2023 was $2,470, which represents a 27% reduction compared to the preceding year. Group-IB analysts believe that this drop in average price is due to a rise in the number of new sellers entering the market that have lowered the price of their offers in order to attract buyers.

Companies in the United States (29%), the United Kingdom (4%) and Brazil (4%) were the most commonly featured in IAB offers. Professional services, government and military organizations, financial services, manufacturing, and real estate were the verticals that appeared most frequently.

APTitude test

Group-IB researchers discovered that the Asia-Pacific region was the world’s main battleground for nation-state sponsored threat actors, also known as advanced persistent threat (APT) groups last year. In sum, Group-IB attributed 523 attacks to nation-state actors across the globe in 2023.

Attacks on APAC organizations accounted for 34% of the global total, with Group-IB experts asserting that this may be due to the high level of financial technology development in this global economic hub in addition to geopolitical tensions. Europe was the second-most targeted region, accounting for 22% of all APT attacks, and the Middle East and Africa (MEA) was third (16% of APT attacks in 2023).

Unsurprisingly, government and military entities were the prime target of APT attacks in 2023, accounting for 28% of the annual figure. This strengthens the theory of Group-IB’s Threat Intelligence unit that APT actors are predominantly striving to gain access to strategically important evidence and weaken government entities in their country or region of target. Financial services (6%), telecommunications (5%), manufacturing, IT and media (all 4%) were also heavily affected, Group-IB researchers found.

In the past year, prominent APT groups, including the North Korean collective Lazarus, launched new tactics. Lazarus executed the first-ever double supply chain attack, exploiting a vulnerability in X_TRADER, a software by Trading Technologies. This allowed access to the network of the widely-used 3CX Desktop App for VoIP calls, compromising a wide range of 3CX clients. Group-IB researchers also noted APT groups’ ongoing malicious use of legitimate services like Dropbox, OneDrive, Google Drive, and messengers like Telegram.

Turbulence ahead

In 2023, cyber threats shifted focus from Windows and Android to Apple platforms due to their rising popularity and market share, with iOS becoming increasingly targeted. Malware spread through the App Store, alongside increased use of Apple cloud services, contributed to this trend. By March 6, 2024, Apple is expected to allow third-party app stores for iOS apps in Europe, posing security concerns amidst 1.7 million app rejections in 2022. Threat actors have already adapted Android schemes to iOS, exemplified by GoldFactory and the GoldPickaxe.iOS malware – аctive in Thailand and Vietnam – which prompts victims to record videos of their faces and submit them to the threat actors, which could be used by the latter to gain unauthorized access to the victim’s banking accounts. Additionally, the number of sales posts on the most popular underground forums (xss[.]is and exploit[.]in) for information stealers designed to operate on macOS increased fivefold in 2023, from 8 in 2022 to 49.

Javascript sniffers, also known as malicious JavaScript code implanted in compromised websites designed to intercept payment card details from customers who make online transactions, are also likely to pose a risk to online store owners, consumers, and banks in 2024. Group-IB researchers discovered 5,037 websites compromised with JS-sniffers in 2023, of which 2,474 were unique. A total of 14 new JS-sniffer families were also discovered in 2023, highlighting the continued development of this threat.

“As highlighted by Group-IB’s Hi-Tech Crime Trends 2023/2024 report, the rise of AI in both legitimate businesses and the cybercriminal underworld was a critical trend of 2023. With the increased misuse of ChatGPT and the development of underground LLM tools, the potential for sophisticated attacks has escalated, compounded by the alarming surge in compromised ChatGPT credentials. This along with cybercriminals’ increased interest in malware designed for macOS demonstrates that it is imperative for organizations to recognize and address this evolving threat landscape, safeguarding sensitive information and fortifying cybersecurity measures to mitigate risks posed by AI-driven cybercrime,” Dmitry Volkov, CEO at Group-IB, said.

A full round-up of the top global threats and invaluable insights from the Group-IB Threat Intelligence unit can be found in the full Hi-Tech Crime Trends 2023/2024 report.

View original content to download multimedia:https://www.prnewswire.com/news-releases/group-ib-reveals-hi-tech-crime-trends-2324-surge-in-ransomware-against-backdrop-of-growing-ai-macos-threats-302075538.html

SOURCE Group-IB

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Technology

Baidu Announces Upcoming Inclusion of Its Class A Ordinary Shares in the Shanghai-Hong Kong Stock Connect Program

Published

on

By

BEIJING, Sept. 4, 2026 /PRNewswire/ — Baidu, Inc. (“Baidu” or the “Company”) (Nasdaq: BIDU; HKEX: 9888 (HKD Counter) and 89888 (RMB Counter)), a leading AI company with strong Internet foundation, today announced that the Company’s Class A ordinary shares traded on The Stock Exchange of Hong Kong Limited (the “Hong Kong Stock Exchange”) will be included in the Shanghai-Hong Kong Stock Connect program, effective September 7, 2026.

The inclusion is pursuant to the Notice of the Adjustment of the Eligible Stocks in Hong Kong Stock Connect under the Shanghai-Hong Kong Stock Connect issued by the Shanghai Stock Exchange on September 4, 2026.

Following the inclusion, eligible investors in the Chinese Mainland will have direct access to the trading of Baidu’s Class A ordinary shares through the Shanghai-Hong Kong Stock Connect. The inclusion marks an important step toward expanding the Company’s reach among Chinese Mainland investors and is expected to further diversify its investor base and enhance the liquidity of its shares.

Baidu appreciates the continued support of its shareholders and investors and remains committed to driving sustainable growth and creating long-term value for shareholders.

About the Shanghai-Hong Kong Stock Connect

The Shanghai-Hong Kong Stock Connect established a two-way trading link between the Shanghai Stock Exchange and the Hong Kong Stock Exchange. The stock connect allows qualified Chinese Mainland investors to access eligible Hong Kong shares (Southbound) as well as Hong Kong and overseas investors to trade eligible A-shares (Northbound), subject to a certain amount of daily quota.

About Baidu

Founded in 2000, Baidu’s mission is to make the complicated world simpler through technology. Baidu is a leading AI company with strong Internet foundation, trading on Nasdaq under “BIDU” and HKEX under “9888”. One Baidu ADS represents eight Class A ordinary shares.

Safe Harbor Statement

This announcement contains forward-looking statements. These statements are made under the “safe harbor” provisions of the U.S. Private Securities Litigation Reform Act of 1995. These forward-looking statements can be identified by terminology such as “will,” “expects,” “anticipates,” “future,” “intends,” “plans,” “believes,” “estimates,” “confident” and similar statements. Among other things, Baidu’s and other parties’ strategic and operational plans, contain forward-looking statements. Baidu may also make written or oral forward-looking statements in its periodic reports to the U.S. Securities and Exchange Commission, in announcements made on the website of the Hong Kong Stock Exchange, in its annual report to shareholders, in press releases and other written materials and in oral statements made by its officers, directors or employees to third parties. Statements that are not historical facts, including but not limited to statements about Baidu’s beliefs and expectations, are forward-looking statements. Forward-looking statements involve inherent risks and uncertainties. A number of factors could cause actual results to differ materially from those contained in any forward-looking statement, including but not limited to the following: Baidu’s growth strategies; its future business development, including development of new products and services; its ability to attract and retain users and customers; competition in the Chinese Internet search and newsfeed market; competition for online marketing customers; changes in the Company’s revenues and certain cost or expense items as a percentage of its revenues; the outcome of ongoing, or any future, litigation or arbitration, including those relating to intellectual property rights; the expected growth of the Chinese-language Internet search and newsfeed market and the number of Internet and broadband users in China; Chinese governmental policies relating to the Internet and Internet search providers, and general economic conditions in China and elsewhere. Further information regarding these and other risks is included in the Company’s annual report on Form 20-F and other documents filed with the Securities and Exchange Commission, and announcements on the website of the Hong Kong Stock Exchange. Baidu does not undertake any obligation to update any forward-looking statement, except as required under applicable law. All information provided in this press release and in the attachments is as of the date of the press release, and Baidu undertakes no duty to update such information, except as required under applicable law.

View original content:https://www.prnewswire.com/news-releases/baidu-announces-upcoming-inclusion-of-its-class-a-ordinary-shares-in-the-shanghai-hong-kong-stock-connect-program-302869998.html

SOURCE Baidu, Inc.

Continue Reading

Technology

Italy is participating to the 26th China International Fair for Investment and Trade (CIFIT) which opens in Xiamen from 8-11 Sept.

Published

on

By

ROME and XIAMEN, China, Sept. 4, 2026 /PRNewswire/ — Curated by the Italian Trade Agency (ITA), in collaboration with the Ministry of Enterprises and Made in Italy (MIMIT), the Official Italian Pavilion is being unveiled at CIFIT in Xiamen. Italy is exhibiting at this edition of the main Investment Fair in China under the theme “Italy, a land of opportunities”.

As the world’s eighth-largest economy and the EU’s second-largest manufacturing powerhouse, Italy has solid policy support for FDI attraction, together with a strong industrial base.

This promotion event, aimed not only at Chinese investors, focuses on showcasing Italy’s strategic advantages as a key investment destination in Europe, explaining the Italian government’s one-stop, full-cycle support services for foreign companies, and giving a comprehensive overview of Italy’s investment policies, laws and regulations, incentives, business environment and top investment opportunities.

The exhibition provides an opportunity to highlight Italy’s business policies and free economic zone incentives in areas like automotive, aerospace, green supply chains, circular economy and life science. A comprehensive list of investment opportunities in the Italian real estate sector is available to all interested parties.

High level officials from the STCAIE and UMASI of the Italian Minister of Enterprises and Made in Italy, the governmental program Invest in Italy, including ITA’s FDI Attraction Desks in Beijing and Hong Kong, and senior specialists from Invitalia (the Italian Agency for FDI attraction) will provide one‑stop investment advisory services for enterprises throughout the Fair.

Multiple thematic seminars will be hosted onsite, including “Policies and Opportunities for Foreign Direct Investment in Italy”, scheduled for the afternoon of September 8, with presentations and Q&A sessions for enterprises to learn about Italy’s FDI support system.

Chinese and international companies interested in investing in Italy can collect extensive information on investment procedures, project proposals, incentives and policy benefits.

According to representatives from the Italian Trade Agency, CIFIT offers valuable opportunities for bilateral industrial collaboration. Italy values its economic and trade ties with China. It welcomes Chinese investment in Italy and supports Italian firms in expanding in China. Both sides will leverage industrial complementarities to deepen two‑way investment, technical synergy and industrial‑chain cooperation for win‑win outcomes.

View original content to download multimedia:https://www.prnewswire.com/apac/news-releases/italy-is-participating-to-the-26th-china-international-fair-for-investment-and-trade-cifit-which-opens-in-xiamen-from-8-11-sept-302870001.html

SOURCE Italian Trade Agency

Continue Reading

Technology

Storiad Introduces the Author Marketing OS

Published

on

By

New software category gives authors a unified system to plan, execute and manage book marketing

CHARLESTON, S.C., Sept. 4, 2026 /PRNewswire/ — Storiad today introduced the Author Marketing OS, a new category of software designed to give authors a single system for planning, executing and managing the marketing of their books.

Authors have never had more tools available to market their books. They have social media platforms, email services, advertising platforms, AI tools, websites, databases and countless other resources. Yet those tools remain largely disconnected, leaving authors to figure out how to organize the entire job of marketing a book themselves.

Storiad’s premise is simple: authors don’t need more marketing tools. They need a system for using them.

“Authors are expected to market their books like businesses, but they’ve never really had that kind of software businesses use to manage their marketing,” said Ramzi S. Hajj, founder of Storiad. “We’ve had writing software. We’ve had publishing software. We’ve had thousands of individual marketing tools. What we’ve been missing is an operating system for the whole job of marketing a book.”

A New Category for an Old Problem

Marketing a book involves far more than creating a few social media posts or sending emails to a limited list.

Authors need to identify their target readers, establish marketing goals, develop a strategy, create promotional materials, find relevant media and industry contacts, conduct outreach, follow up, maintain visibility and measure what is working.

Those activities have traditionally been handled across multiple tools, documents and services.

Storiad brings them together in a single platform designed specifically around the author’s book marketing workflow.

The company defines an Author Marketing OS as “a unified system that organizes the major functions of book marketing, including strategy, planning, execution and optimization.” Rather than replacing every marketing tool an author may use, the Storiad OS provides the strategic and operational structure that connects those activities.

Storiad is introducing the Author Marketing OS as a new software category built specifically around the job of marketing a book.

From Strategy to Execution

At the center of Storiad’s approach is Book Promotion nMotion™, a proprietary system that helps authors turn a book marketing strategy into an actionable campaign.

Book Promotion nMotion™ organizes promotion around eight core areas:

Promotional Asset CreationMarket ResearchSocial Media ManagementEmailing & Follow-upNetworkingMarketingPublicityBlogging & Newsletter

For each area, authors can develop strategies, planning documents and step-by-step checklists designed to move their campaigns from ideas to action.

“There’s a really big difference between giving an author a marketing plan and giving an author a system they can actually use to run the campaign,” said Hajj. “Our goal is to make book marketing something an author can learn, organize, execute and improve upon over time.”

Built Around the Author’s Book Sales Goal

Storiad begins with a simple question for the author:

How many books do you want to sell?

Its Book Sales Calculator helps authors establish a specific sales target and understand the marketing activities required to pursue it. From there, the platform provides tools and workflows for building and managing a campaign around that book sales goal.

The platform includes CRM-style contact management, a database of more than 52,000 verified book promotion contacts, marketing planning tools such as a Target Reader Profile, email outreach, social media tools, an author website builder, a press room, publicity resources, campaign management and other book marketing capabilities.

Storiad is being used by thousands of authors, giving the company real-time experience developing software around the practical challenges authors face when promoting their books.

AI as Part of the Marketing System

The Author Marketing OS also incorporates StoriA, Storiad’s AI Author Assistant.

StoriA is designed to help authors work through the marketing process, from developing strategies and plans to creating marketing materials and determining what to do next.

“AI is very good at creating things,” said Hajj. “But creating another piece of content isn’t necessarily the answer to an author’s marketing problem. The bigger questions center around who should I reach, what should I say, what should I do next, and how does this fit into my overall campaign? That’s where we think AI can become much more useful to authors.”

Building the Author Marketing OS

The need for an Author Marketing OS comes from a simple reality of today’s publishing environment: authors are increasingly responsible for marketing their own books.

At the same time, the number of tools available to them continues to grow.

Storiad believes the answer is not another standalone marketing tool.

It is a system.

“The ultimate goal is pretty simple,” said Hajj. “We want to help authors take control of their book marketing and sell more books.”

Storiad is making its Author Marketing OS available to authors through its software platform.

For more information, visit www.storiad.com.

About Storiad

Storiad is the first Author Marketing Operating System, designed to help published authors plan, execute and manage their entire book marketing lifecycle in one place. The platform combines marketing strategy, structured workflows, AI-powered assistance, CRM-style contact management, research, outreach and campaign execution.

Storiad’s mission is simple: help authors sell more books.

Media Contact
Ramzi S. Hajj
Founder & CEO, Storiad, Inc.
ramzi@storiad.com
626.676.4142

View original content:https://www.prnewswire.com/news-releases/storiad-introduces-the-author-marketing-os-302869647.html

SOURCE Storiad, Inc.

Continue Reading

Trending