Connect with us

Technology

Group-IB reveals Hi-Tech Crime Trends 23/24: surge in ransomware against backdrop of growing AI, macOS threats

Published

on

SINGAPORE, Feb. 29, 2024 /PRNewswire/ — Group-IB, a leading creator of cybersecurity technologies to investigate, prevent, and fight digital crime, is proud to announce the launch of its new report Hi-Tech Crime Trends 2023/2024, the latest edition of the company’s annual round-up of the most pressing global cyber threats to organizations and individuals. In the research, Group-IB analysts reveal how the unholy alliance between ransomware groups and Initial Access Brokers (IABs) is still the powerful engine for cybercriminal industry, evidenced by the 74% year-on-year increase in the number of companies that had their data uploaded on dedicated leak sites (DLS). Global threat actors also demonstrated increased interest in Apple platforms, exemplified by the fivefold increase in underground sales related to macOS information stealers.

The growing appetite of nation-state sponsored threat actors, also known as advanced persistent threat (APT) groups, has shown that no region is immune to cyber threats. Group-IB experts discovered a 70% increase in the number of public posts offering zero-day exploits for sale, and also identified cybercriminals’ malicious use of legitimate services and artificial intelligence (AI) infused technologies as the main cyber risks for 2024.

The first edition of Hi-Tech Crime Trends was launched 12 years ago, and the information contained in the report enables businesses, NGOs, governments, and law enforcement agencies around the world to fight cybercrime and help potential victims. For the first time, Hi-Tech Crime Trends includes a section outlining the intricate relationship between artificial intelligence (AI) and cybersecurity threats, outlining how this new technology is being leveraged by cybercriminals, including the misuse of large language models (LLM) such as ChatGPT, and the potential risks to corporate data through AI integration.

Nothing artificial about this threat

Threat actors have already shown how AI can help them develop malware only with a limited knowledge of programming languages, brainstorm new TTPs, compose convincing text to be used in social engineering attacks, and also increase their operational productivity.

Large language models (LLM) such as ChatGPT remain in widespread use, and Group-IB analysts have observed continued interest on underground forums in ChatGPT jailbreaking and specialized generative pre-trained transformer (GPT) development, looking for ways to bypass ChatGPT’s security controls. Group-IB experts have also noticed how, since mid-2023, four ChatGPT-style tools have been developed for the purpose of assisting cybercriminal activity: WolfGPT, DarkBARD, FraudGPT, and WormGPT – all with different functionalities.

FraudGPT and WormGPT are highly discussed tools on underground forums and Telegram channels, tailored for social engineering and phishing. Conversely, tools like WolfGPT, focusing on code or exploits, are less popular due to training complexities and usability issues. Yet, their advancement poses risks for sophisticated attacks.

Group-IB’s Hi-Tech Crime Trends 2023/2024 also highlighted the sale of compromised ChatGPT credentials on the dark web, building upon past research. With more employees relying on ChatGPT for work optimization and its storage of past interactions, compromised logins could expose sensitive information, posing significant security risks for businesses.

From January 2023 to October 2023, Group-IB detected more than 225,000 logs up for sale on the dark web containing compromised ChatGPT credentials. Group-IB’s Threat Intelligence platform found these compromised credentials within the logs of information-stealing malware traded on illicit dark web marketplaces.

Notably, the number of compromised hosts with access to ChatGPT detected by Threat Intelligence between June 2023 and October 2023 was more than 130,000, an increase of 36% compared to the preceding five-month period (January-May 2023). The number of available logs containing ChatGPT logs peaked in the final month of the study – in October 2023 – when 33,080 were registered. Group-IB’s analysis found that the majority of the logs containing ChatGPT accounts were breached by the LummaC2 information stealer.

Double trouble: ransomware gangs and initial access brokers wreak havoc

Group-IB’s Threat Intelligence unit constantly monitors all ransomware activity and detected 4,583 companies that had their information, files, and data published on ransomware DLSs in 2023. This marks a growth of 74% compared to the previous year, when 2,629 such posts were made. Group-IB researchers note that the number of total ransomware attacks worldwide is likely to be much larger, with probable instances of organizations paying the ransom or groups deciding not to go ahead with their threat of publishing data on a DLS.

Companies based in North America most commonly appeared in the DLS posts of ransomware groups, accounting for 2,487 (or 54%) of the annual total, and more than double the corresponding figure in 2022 (1,192 companies). Roughly 26% of posts on ransomware DLSs related to companies from Europe (1,186, up 52% YoY) and 10% were from the APAC region (463, up 39% YoY).

The United States was the most common target for ransomware groups, as 1,060 US-based companies were the subject of ransomware DLS posts in 2023. The next most affected countries were Germany (129), Canada (115), France (103), and Italy (100). 

In terms of affected industries, attacks as per ransomware DLS on manufacturing (580 instances) and real estate (429) companies rose year-on-year by 125% and 165%, respectively, and these key sectors were the two most targeted worldwide. Notably, Group-IB observed a 88% year-on-year increase in ransomware DLS posts related to healthcare companies, and a 65% rise in posts concerning government and military organizations.

Throughout the reporting period, Group-IB experts uncovered 27 new advertisements for ransomware-as-a-service programs on dark web forums, including well-known groups such as Qilin, as well as other collectives that have yet to be seen in the wild. As was the case in 2022, LockBit was 2023’s most prominent ransomware-as-a-service group with 1,079 posts on its DLS (24% of the annual total). In second place was BlackCat with 427 posts (9% of annual total) and third was Clop (385 posts or 9%).

Researchers also found that Initial Access Brokers (IABs) are continuing to play a significant role in the ransomware market. In 2023, they found 2,675 instances of corporate put up for sale – almost an identical figure compared with 2022, when 2,702 offers were found.

Notably, Group-IB data shows that the average price for corporate access in 2023 was $2,470, which represents a 27% reduction compared to the preceding year. Group-IB analysts believe that this drop in average price is due to a rise in the number of new sellers entering the market that have lowered the price of their offers in order to attract buyers.

Companies in the United States (29%), the United Kingdom (4%) and Brazil (4%) were the most commonly featured in IAB offers. Professional services, government and military organizations, financial services, manufacturing, and real estate were the verticals that appeared most frequently.

APTitude test

Group-IB researchers discovered that the Asia-Pacific region was the world’s main battleground for nation-state sponsored threat actors, also known as advanced persistent threat (APT) groups last year. In sum, Group-IB attributed 523 attacks to nation-state actors across the globe in 2023.

Attacks on APAC organizations accounted for 34% of the global total, with Group-IB experts asserting that this may be due to the high level of financial technology development in this global economic hub in addition to geopolitical tensions. Europe was the second-most targeted region, accounting for 22% of all APT attacks, and the Middle East and Africa (MEA) was third (16% of APT attacks in 2023).

Unsurprisingly, government and military entities were the prime target of APT attacks in 2023, accounting for 28% of the annual figure. This strengthens the theory of Group-IB’s Threat Intelligence unit that APT actors are predominantly striving to gain access to strategically important evidence and weaken government entities in their country or region of target. Financial services (6%), telecommunications (5%), manufacturing, IT and media (all 4%) were also heavily affected, Group-IB researchers found.

In the past year, prominent APT groups, including the North Korean collective Lazarus, launched new tactics. Lazarus executed the first-ever double supply chain attack, exploiting a vulnerability in X_TRADER, a software by Trading Technologies. This allowed access to the network of the widely-used 3CX Desktop App for VoIP calls, compromising a wide range of 3CX clients. Group-IB researchers also noted APT groups’ ongoing malicious use of legitimate services like Dropbox, OneDrive, Google Drive, and messengers like Telegram.

Turbulence ahead

In 2023, cyber threats shifted focus from Windows and Android to Apple platforms due to their rising popularity and market share, with iOS becoming increasingly targeted. Malware spread through the App Store, alongside increased use of Apple cloud services, contributed to this trend. By March 6, 2024, Apple is expected to allow third-party app stores for iOS apps in Europe, posing security concerns amidst 1.7 million app rejections in 2022. Threat actors have already adapted Android schemes to iOS, exemplified by GoldFactory and the GoldPickaxe.iOS malware – аctive in Thailand and Vietnam – which prompts victims to record videos of their faces and submit them to the threat actors, which could be used by the latter to gain unauthorized access to the victim’s banking accounts. Additionally, the number of sales posts on the most popular underground forums (xss[.]is and exploit[.]in) for information stealers designed to operate on macOS increased fivefold in 2023, from 8 in 2022 to 49.

Javascript sniffers, also known as malicious JavaScript code implanted in compromised websites designed to intercept payment card details from customers who make online transactions, are also likely to pose a risk to online store owners, consumers, and banks in 2024. Group-IB researchers discovered 5,037 websites compromised with JS-sniffers in 2023, of which 2,474 were unique. A total of 14 new JS-sniffer families were also discovered in 2023, highlighting the continued development of this threat.

“As highlighted by Group-IB’s Hi-Tech Crime Trends 2023/2024 report, the rise of AI in both legitimate businesses and the cybercriminal underworld was a critical trend of 2023. With the increased misuse of ChatGPT and the development of underground LLM tools, the potential for sophisticated attacks has escalated, compounded by the alarming surge in compromised ChatGPT credentials. This along with cybercriminals’ increased interest in malware designed for macOS demonstrates that it is imperative for organizations to recognize and address this evolving threat landscape, safeguarding sensitive information and fortifying cybersecurity measures to mitigate risks posed by AI-driven cybercrime,” Dmitry Volkov, CEO at Group-IB, said.

A full round-up of the top global threats and invaluable insights from the Group-IB Threat Intelligence unit can be found in the full Hi-Tech Crime Trends 2023/2024 report.

View original content to download multimedia:https://www.prnewswire.com/news-releases/group-ib-reveals-hi-tech-crime-trends-2324-surge-in-ransomware-against-backdrop-of-growing-ai-macos-threats-302075538.html

SOURCE Group-IB

Continue Reading

Technology

Bringing Local AI Home: UGREEN Introduces Privacy-First HomeAgent for Smarter Living

Published

on

By

BERLIN, Sept. 5, 2026 /PRNewswire/ — UGREEN, a leading global consumer technology brand, announced two new product lineups at a European launch event. The unveiling of the UGREENHomeAgent series of agentic local AI hubs and a new MagFlow lineup marks UGREEN’s next stage of growth. Building on its established presence in digital accessories and smart storage, the company is now dedicated to a broader spectrum of intelligent consumer electronics designed to enhance everyday life.

UGREEN HomeAgent: Agentic Local AI Hub for Homes

At the center of UGREEN’s broader intelligent consumer electronics vision is UGREEN HomeAgent, a groundbreaking Agentic AI Local Hub unifying local storage, computing, and control into one device. It connects a growing ecosystem of UGREEN AIoT devices, including security cameras, smart speakers, and smart photo frames, as well as third-party devices.

UGOS Pro is UGREEN’s in-house operating system built on a Linux architecture, offering professional storage management, robust data security, easy backup and sync, and extensive expandability.

UGREEN HomeAgent is powered by the all-new UGOS Pro, combining NAS-grade storage and data management with integrated home security features, smart home capabilities, and natural voice interaction to deliver a more complete all-in-one experience.

Traditional surveillance cameras usually only document bad news, and their footage is constantly overwritten, so the moments truly worth keeping quietly disappear. That’s why UGREEN set out to redefine the home camera system, not as a surveillance tool, but as a camera for life.

“HomeAgent proactively recognizes moments that are truly worth remembering and organizes them into a personalized daily briefing for every family. Moments that might otherwise be forgotten can return. We want to help families preserve the precious time they spend together.” – Samuel Zhang, CEO of UGREEN

As an agentic local AI hub integrating on-device intelligence, local storage, AI computing and smart-home control, HomeAgent serves as the AI brain of the connected home. Designed to keep data private and local, it enables intelligent file management, proactive home monitoring, voice-driven automation and unified device control. The ecosystem includes the HomeAgent HA100 and HA100 Pro, the NVIDIA® Jetson Thor™-powered MasterAgent MA100, SynCare smart cameras, the UGREEN Smart Speaker for Uliya, and UGREEN Gallery smart frames, while remaining compatible with third-party Matter-enabled devices. Together, they deliver a private, expandable AI platform that helps users preserve memories, monitor their homes and coordinate devices through natural, context-aware interactions.

MagFlow Pro: Active Heat Dissipation and Sustained Fast Charging

Announced alongside HomeAgent, MagFlow Powerbank is the world’s first liquid-cooled Qi2 25W magnetic power bank, featuring CryoPulse™ micro-pump liquid cooling, active heat dissipation and sustained fast charging.

The launch complements UGREEN’s strong range of charging options, outlining the brand’s commitment to true-rated performance and flagship-quality power.

Availability Timeline

Pre-orders for the UGREEN HomeAgent HA100, HA100 Pro and UGREEN MasterAgent MA100 opened on September 4, 2026, via the UGREEN AIoT Official Store, and remain available until the official Kickstarter crowdfunding campaign launches on October 27, 2026. Other AIoT accessories will be introduced as part of the Kickstarter campaign beginning on October 27. During the pre-order period, customers can place a deposit starting at $50 to reserve the UGREEN HomeAgent HA100, HA100 Pro or UGREEN MasterAgent MA100 and secure 50% off with the Super Early Bird discount.

About UGREEN

UGREEN is a leading global tech brand creating innovative products that make everyday life smarter, easier, and more connected. From smart charging and productivity to smart storage and AIoT, UGREEN designs technology around the needs of modern life.

View original content to download multimedia:https://www.prnewswire.co.uk/news-releases/bringing-local-ai-home-ugreen-introduces-privacy-first-homeagent-for-smarter-living-302870674.html

Continue Reading

Technology

HKC and KOORUI Receive Dual Honors at the 2026 Global Product Technology Innovation Awards

Published

on

By

HKC receives the Advanced Display Technology Brand Award, while KOORUI is honored with the Innovative Monitor Brand Award during IFA 2026.

BERLIN, Sept. 5, 2026 /CNW/ — HKC and its consumer display brand KOORUI received two distinctions at the 2026 Global Product Technology Innovation Awards, presented in Berlin during IFA 2026.

HKC received the Advanced Display Technology Brand Award, recognizing its continued commitment to display technology and integrated display solutions. KOORUI received the Innovative Monitor Brand Award, highlighting the brand’s ongoing efforts in monitor innovation and user experience.

According to the organizer, the Global Product Technology Innovation Awards were established by IDG in 2014 to recognize outstanding brands and products across the global consumer electronics and home appliance industries. Presented annually in Berlin during IFA, the awards highlight notable achievements in technology and product innovation for audiences across Europe and global markets.

As display technologies and applications continue to evolve, users increasingly expect products that combine strong performance, high quality and meaningful visual experiences. With more than 20 years of focus on display technology, HKC has developed into a global provider of integrated display solutions. KOORUI builds on this technological foundation to bring innovative monitor products to a broader range of consumers and usage scenarios.

“We are honored to receive these two awards,” said a representative of HKC Group. “They recognize HKC’s long-term commitment to display technology and KOORUI’s continued focus on product innovation. We will keep developing advanced display solutions that respond to evolving user needs and create high-quality visual experiences worldwide.”

The two honors mark another milestone for HKC and KOORUI as they continue advancing display technologies, improving product experiences and strengthening engagement with global partners and consumers.

About HKC

HKC has focused on the display industry for more than 20 years and provides integrated display solutions for global markets and diverse applications.

About KOORUI

KOORUI is HKC’s consumer display brand, creating innovative monitor products and visual experiences for users worldwide.

View original content:https://www.prnewswire.com/news-releases/hkc-and-koorui-receive-dual-honors-at-the-2026-global-product-technology-innovation-awards-302870688.html

SOURCE HKC

Continue Reading

Technology

ATTACK SHARK Announces Strategic Partnership with Cloud9 Esports’ League of Legends Team

Published

on

By

NEW YORK, Sept. 5, 2026 /PRNewswire/ — High-performance gaming peripheral brand ATTACK SHARK today announced a partnership with leading esports organization Cloud9 Esports. Focused on Cloud9’s League of Legends team, the collaboration will showcase professional gaming insights, esports culture, and competitive gear content across digital, social media, and e-commerce channels.

A Championship Legacy in North American Esports

Founded in 2013, Cloud9 Kia has grown into one of North America’s most iconic esports organizations. Originally established through League of Legends, it has built a global reputation through competitive success, including 6 League Championship Series (LCS) titles, 10 World Championship appearances, the 2018 ELEAGUE Major Boston title, the inaugural Overwatch League championship, and a Rocket League World Championship. Cloud9 Kia remains one of North America’s most influential League of Legends teams.

Deep Collaboration: From Pro Scenes to Player Communities

The partnership will center on professional player training, competitive performance, and player-focused content. ATTACK SHARK will equip the Cloud9 League of Legends team with its latest gaming peripherals to support daily training and competitive preparation.

By combining Cloud9’s professional competitive expertise with ATTACK SHARK’s focus on hardware innovation, the partnership aims to explore the increasing demands placed on gaming equipment in high-level esports environments. Trusted by over 10 million players worldwide, ATTACK SHARK translates professional esports insights into accessible, high-performance gaming peripherals for competitive gamers. 

“At Cloud9 Kia, we believe gaming can unlock the best in everyone. ATTACK SHARK is on a mission to make high-performance mice and keyboards accessible to all gamers, and that’s the same idea from two directions. I’m proud to have them alongside Cloud9 Kia, and excited for all of the amazing peripherals this partnership will put into our fan’s hands,” said Jonathan Tran, President of Cloud9.

“Partnering with Cloud9 Kia is a significant milestone for ATTACK SHARK,” said Gavin Cheng, CEO and Co-Founder of ATTACK SHARK. “Their competitive spirit, professionalism, and relentless pursuit of excellence closely align with the values that have guided ATTACK SHARK from the beginning. This collaboration creates an opportunity to learn from professional competition and share those insights with players around the world.”

The partnership represents a deeper investment by ATTACK SHARK in the global esports ecosystem. Together, ATTACK SHARK and Cloud9 Kia will continue creating new experiences for competitive players and gaming communities worldwide.

For more information, visit https://attackshark.com/ or connect with the brand on social media and Discord.

View original content to download multimedia:https://www.prnewswire.com/news-releases/attack-shark-announces-strategic-partnership-with-cloud9-esports-league-of-legends-team-302870659.html

SOURCE ATTACK SHARK

Continue Reading

Trending