Connect with us

Technology

Group-IB reveals Hi-Tech Crime Trends 23/24: surge in ransomware against backdrop of growing AI, macOS threats

Published

on

SINGAPORE, Feb. 29, 2024 /PRNewswire/ — Group-IB, a leading creator of cybersecurity technologies to investigate, prevent, and fight digital crime, is proud to announce the launch of its new report Hi-Tech Crime Trends 2023/2024, the latest edition of the company’s annual round-up of the most pressing global cyber threats to organizations and individuals. In the research, Group-IB analysts reveal how the unholy alliance between ransomware groups and Initial Access Brokers (IABs) is still the powerful engine for cybercriminal industry, evidenced by the 74% year-on-year increase in the number of companies that had their data uploaded on dedicated leak sites (DLS). Global threat actors also demonstrated increased interest in Apple platforms, exemplified by the fivefold increase in underground sales related to macOS information stealers.

The growing appetite of nation-state sponsored threat actors, also known as advanced persistent threat (APT) groups, has shown that no region is immune to cyber threats. Group-IB experts discovered a 70% increase in the number of public posts offering zero-day exploits for sale, and also identified cybercriminals’ malicious use of legitimate services and artificial intelligence (AI) infused technologies as the main cyber risks for 2024.

The first edition of Hi-Tech Crime Trends was launched 12 years ago, and the information contained in the report enables businesses, NGOs, governments, and law enforcement agencies around the world to fight cybercrime and help potential victims. For the first time, Hi-Tech Crime Trends includes a section outlining the intricate relationship between artificial intelligence (AI) and cybersecurity threats, outlining how this new technology is being leveraged by cybercriminals, including the misuse of large language models (LLM) such as ChatGPT, and the potential risks to corporate data through AI integration.

Nothing artificial about this threat

Threat actors have already shown how AI can help them develop malware only with a limited knowledge of programming languages, brainstorm new TTPs, compose convincing text to be used in social engineering attacks, and also increase their operational productivity.

Large language models (LLM) such as ChatGPT remain in widespread use, and Group-IB analysts have observed continued interest on underground forums in ChatGPT jailbreaking and specialized generative pre-trained transformer (GPT) development, looking for ways to bypass ChatGPT’s security controls. Group-IB experts have also noticed how, since mid-2023, four ChatGPT-style tools have been developed for the purpose of assisting cybercriminal activity: WolfGPT, DarkBARD, FraudGPT, and WormGPT – all with different functionalities.

FraudGPT and WormGPT are highly discussed tools on underground forums and Telegram channels, tailored for social engineering and phishing. Conversely, tools like WolfGPT, focusing on code or exploits, are less popular due to training complexities and usability issues. Yet, their advancement poses risks for sophisticated attacks.

Group-IB’s Hi-Tech Crime Trends 2023/2024 also highlighted the sale of compromised ChatGPT credentials on the dark web, building upon past research. With more employees relying on ChatGPT for work optimization and its storage of past interactions, compromised logins could expose sensitive information, posing significant security risks for businesses.

From January 2023 to October 2023, Group-IB detected more than 225,000 logs up for sale on the dark web containing compromised ChatGPT credentials. Group-IB’s Threat Intelligence platform found these compromised credentials within the logs of information-stealing malware traded on illicit dark web marketplaces.

Notably, the number of compromised hosts with access to ChatGPT detected by Threat Intelligence between June 2023 and October 2023 was more than 130,000, an increase of 36% compared to the preceding five-month period (January-May 2023). The number of available logs containing ChatGPT logs peaked in the final month of the study – in October 2023 – when 33,080 were registered. Group-IB’s analysis found that the majority of the logs containing ChatGPT accounts were breached by the LummaC2 information stealer.

Double trouble: ransomware gangs and initial access brokers wreak havoc

Group-IB’s Threat Intelligence unit constantly monitors all ransomware activity and detected 4,583 companies that had their information, files, and data published on ransomware DLSs in 2023. This marks a growth of 74% compared to the previous year, when 2,629 such posts were made. Group-IB researchers note that the number of total ransomware attacks worldwide is likely to be much larger, with probable instances of organizations paying the ransom or groups deciding not to go ahead with their threat of publishing data on a DLS.

Companies based in North America most commonly appeared in the DLS posts of ransomware groups, accounting for 2,487 (or 54%) of the annual total, and more than double the corresponding figure in 2022 (1,192 companies). Roughly 26% of posts on ransomware DLSs related to companies from Europe (1,186, up 52% YoY) and 10% were from the APAC region (463, up 39% YoY).

The United States was the most common target for ransomware groups, as 1,060 US-based companies were the subject of ransomware DLS posts in 2023. The next most affected countries were Germany (129), Canada (115), France (103), and Italy (100). 

In terms of affected industries, attacks as per ransomware DLS on manufacturing (580 instances) and real estate (429) companies rose year-on-year by 125% and 165%, respectively, and these key sectors were the two most targeted worldwide. Notably, Group-IB observed a 88% year-on-year increase in ransomware DLS posts related to healthcare companies, and a 65% rise in posts concerning government and military organizations.

Throughout the reporting period, Group-IB experts uncovered 27 new advertisements for ransomware-as-a-service programs on dark web forums, including well-known groups such as Qilin, as well as other collectives that have yet to be seen in the wild. As was the case in 2022, LockBit was 2023’s most prominent ransomware-as-a-service group with 1,079 posts on its DLS (24% of the annual total). In second place was BlackCat with 427 posts (9% of annual total) and third was Clop (385 posts or 9%).

Researchers also found that Initial Access Brokers (IABs) are continuing to play a significant role in the ransomware market. In 2023, they found 2,675 instances of corporate put up for sale – almost an identical figure compared with 2022, when 2,702 offers were found.

Notably, Group-IB data shows that the average price for corporate access in 2023 was $2,470, which represents a 27% reduction compared to the preceding year. Group-IB analysts believe that this drop in average price is due to a rise in the number of new sellers entering the market that have lowered the price of their offers in order to attract buyers.

Companies in the United States (29%), the United Kingdom (4%) and Brazil (4%) were the most commonly featured in IAB offers. Professional services, government and military organizations, financial services, manufacturing, and real estate were the verticals that appeared most frequently.

APTitude test

Group-IB researchers discovered that the Asia-Pacific region was the world’s main battleground for nation-state sponsored threat actors, also known as advanced persistent threat (APT) groups last year. In sum, Group-IB attributed 523 attacks to nation-state actors across the globe in 2023.

Attacks on APAC organizations accounted for 34% of the global total, with Group-IB experts asserting that this may be due to the high level of financial technology development in this global economic hub in addition to geopolitical tensions. Europe was the second-most targeted region, accounting for 22% of all APT attacks, and the Middle East and Africa (MEA) was third (16% of APT attacks in 2023).

Unsurprisingly, government and military entities were the prime target of APT attacks in 2023, accounting for 28% of the annual figure. This strengthens the theory of Group-IB’s Threat Intelligence unit that APT actors are predominantly striving to gain access to strategically important evidence and weaken government entities in their country or region of target. Financial services (6%), telecommunications (5%), manufacturing, IT and media (all 4%) were also heavily affected, Group-IB researchers found.

In the past year, prominent APT groups, including the North Korean collective Lazarus, launched new tactics. Lazarus executed the first-ever double supply chain attack, exploiting a vulnerability in X_TRADER, a software by Trading Technologies. This allowed access to the network of the widely-used 3CX Desktop App for VoIP calls, compromising a wide range of 3CX clients. Group-IB researchers also noted APT groups’ ongoing malicious use of legitimate services like Dropbox, OneDrive, Google Drive, and messengers like Telegram.

Turbulence ahead

In 2023, cyber threats shifted focus from Windows and Android to Apple platforms due to their rising popularity and market share, with iOS becoming increasingly targeted. Malware spread through the App Store, alongside increased use of Apple cloud services, contributed to this trend. By March 6, 2024, Apple is expected to allow third-party app stores for iOS apps in Europe, posing security concerns amidst 1.7 million app rejections in 2022. Threat actors have already adapted Android schemes to iOS, exemplified by GoldFactory and the GoldPickaxe.iOS malware – аctive in Thailand and Vietnam – which prompts victims to record videos of their faces and submit them to the threat actors, which could be used by the latter to gain unauthorized access to the victim’s banking accounts. Additionally, the number of sales posts on the most popular underground forums (xss[.]is and exploit[.]in) for information stealers designed to operate on macOS increased fivefold in 2023, from 8 in 2022 to 49.

Javascript sniffers, also known as malicious JavaScript code implanted in compromised websites designed to intercept payment card details from customers who make online transactions, are also likely to pose a risk to online store owners, consumers, and banks in 2024. Group-IB researchers discovered 5,037 websites compromised with JS-sniffers in 2023, of which 2,474 were unique. A total of 14 new JS-sniffer families were also discovered in 2023, highlighting the continued development of this threat.

“As highlighted by Group-IB’s Hi-Tech Crime Trends 2023/2024 report, the rise of AI in both legitimate businesses and the cybercriminal underworld was a critical trend of 2023. With the increased misuse of ChatGPT and the development of underground LLM tools, the potential for sophisticated attacks has escalated, compounded by the alarming surge in compromised ChatGPT credentials. This along with cybercriminals’ increased interest in malware designed for macOS demonstrates that it is imperative for organizations to recognize and address this evolving threat landscape, safeguarding sensitive information and fortifying cybersecurity measures to mitigate risks posed by AI-driven cybercrime,” Dmitry Volkov, CEO at Group-IB, said.

A full round-up of the top global threats and invaluable insights from the Group-IB Threat Intelligence unit can be found in the full Hi-Tech Crime Trends 2023/2024 report.

View original content to download multimedia:https://www.prnewswire.com/news-releases/group-ib-reveals-hi-tech-crime-trends-2324-surge-in-ransomware-against-backdrop-of-growing-ai-macos-threats-302075538.html

SOURCE Group-IB

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Technology

The Inner Circle acknowledges Colleen Reilly as a Pinnacle Professional Member Inner Circle of Excellence

Published

on

By

PORT ST. JOE, Fla., April 24, 2026 /PRNewswire/ — Prominently featured in The Inner Circle, Colleen Reilly is honored as a Pinnacle Professional Member Inner Circle of Excellence for her contributions to Transforming Catering and Event Services in Northwest Florida.

Since 2015, Colleen Reilly has served as founder and CEO of Catering Connections, a company that has redefined catering in Northwest Florida’s beach communities through innovation, collaboration, and community focus. Guided by her motto “Just one call feeds them all,” Ms. Reilly established a unique model by partnering with local restaurants to showcase their specialties, fostering unity among businesses while providing clients with one-of-a-kind event experiences.

With over 15 years of industry expertise, Ms. Reilly specializes in coordinating weddings, family reunions, and corporate events, managing every detail from client consultation to menu planning and flawless execution. Her dedication to service has earned Catering Connections multiple recognitions, including the Couples Choice Award from WeddingWire from 2021 to 2025, the Best of Florida Award from 2022 to 2024, and the Lux Life Hospitality and Catering Award in 2023 and 2024.

Ms. Reilly’s career foundation includes an associate degree in paralegal studies, magna cum laude, from Volunteer State College, a reflection of her meticulous approach to detail and commitment to excellence. Beyond her business, she serves her community as a board member of the Historic St. Andrews Waterfront Partnership and as president of Friends of the Governor Stone Inc., a nonprofit dedicated to preserving maritime heritage in Panama City. Her previous civic contributions include serving five years as a guardian ad litem, advocating for children within the legal system, and volunteering as a school chaperone for international student trips.

A leader who blends innovation with service, Ms. Reilly continues to grow Catering Connections while deepening her commitment to the local community. Looking ahead, she remains dedicated to expanding her company’s impact, bringing people together, and creating meaningful experiences through food and fellowship.

Contact: Katherine Green, 516-825-5634, editorialteam@continentalwhoswho.com

View original content to download multimedia:https://www.prnewswire.com/news-releases/the-inner-circle-acknowledges-colleen-reilly-as-a-pinnacle-professional-member-inner-circle-of-excellence-302753052.html

SOURCE The Inner Circle

Continue Reading

Technology

Media Contributor Kianga Moore to Host Executive Media Roundtable On AI’s Transformational Impact in Retail

Published

on

By

Leaders from AdFury.ai, Vendormint, and New Nexus Group to Explore Real-Time Decision-Making, Resilience, and Growth in a Volatile Market

NEW YORK, April 24, 2026 /PRNewswire/ — As retailers navigate ongoing economic uncertainty, supply chain volatility, and rapidly shifting consumer expectations, the upcoming convening of a high-level roundtable discussion will examine how artificial intelligence is reshaping the retail landscape in real time.

Moderated by Media Contributor Kianga Moore, to be held on Wednesday, April 29 at 11h00am (EST), the roundtable will bring together senior leaders from AdFury.ai, Vendormint and New Nexus Group to discuss how modern enterprise platforms are leveraging AI to drive agility, efficiency, and long-term resilience across the retail ecosystem.

The discussion will additionally focus on how AI is enabling retailers to respond dynamically to changing demand signals, optimize marketing investments, and strengthen interoperability across increasingly complex vendor and marketplace networks.

“Retailers today are operating in a constant state of disruption”, stated Kianga Moore. “This roundtable will explore how AI is not just a tool for efficiency, but a strategic asset for anticipating change and building more resilient, adaptive American enterprise.”

Key discussion topics will include remarks on how, for example, enterprise AI platforms are helping retailers respond instantly to fluctuations in consumer demand, pricing pressures, and external supply chain disruptions and the role of AI in enhancing interoperability across vendors, partners, and marketplaces to create more agile and resilient retail infrastructures in 2026.

Rob Gonda, Chief Technical Officer at Vendormint, stated that, “Interoperability is the backbone of modern retail. AI enables seamless communication between platforms, vendors, and marketplaces—turning fragmented systems into cohesive, responsive ecosystems that can adapt under pressure.”

Discussion topics will also include machine learning’s ability to optimize ad spend, improving personalization, and delivering measurable ROI while maintaining brand trust and regulatory compliance.

Eric Howerton, Co-Founder and Chief Growth Officer of AdFury.ai, added that,”AI is fundamentally changing how brands approach customer acquisition. By leveraging machine learning through fine-tuned, retail-specific agentic flows, we can not only optimize ad spend in real time, but we can also ensure messaging is personalized, compliant, and aligned with evolving consumer expectations.”

And indeed the roundtable will include discussions on how AI-powered predictive analytics can help businesses anticipate economic, technological, and geopolitical disruptions ahead—and plan accordingly.

Cheryl Yarbrough, Vice President of Partnerships at New Nexus Group added that, “Resilience in retail is no longer built in quarterly planning cycles-it’s built in real time. AI gives organizations the ability to identify disruptions before they cascade, pivot strategies before momentum is lost, and maintain continuity when the market moves faster than any human team can react alone.”

The roundtable will be held via Zoom TeleConference, with questions from the press and key stakeholders to follow opening remarks and a 30-minute Q&A between the moderator and the panelists.

For all media inquiries and to register to attend, please contact: Sam Amsterdam, Amsterdam Group Public Relations Inc. – Sam@AmsterdamGroup.net / +1 (202) 910-8349

Vendormint (https://vendormint.com)New Nexus Group (https://www.newnexusgroup.com)AdFury.ai (https://www.adfury.ai)

Samuel Amsterdam
Communications Counsel
Vendormint
samuelamsterdam@gmail.com

View original content:https://www.prnewswire.com/news-releases/media-contributor-kianga-moore-to-host-executive-media-roundtable-on-ais-transformational-impact-in-retail-302753148.html

SOURCE Vendormint

Continue Reading

Technology

Fairway Home Mortgage Earns Prestigious USA TODAY Top Workplaces Award For 6th Consecutive Year

Published

on

By

Fairway CEO Steve Jacobson Named #1 Leadership Award Winner of Companies With 2500+ Employees

MADISON, Wis., April 24, 2026 /PRNewswire/ — Fairway Home Mortgage announced that it has earned the prestigious 2026 USA TODAY Top Workplaces award. This is the sixth year in a row Fairway achieved this honor.

The award honors organizations with 150 or more employees that have created exceptional, people-first cultures. This year, more than 40,500 organizations were invited to participate. The winners are recognized for their commitment to fostering a workplace environment that values employee listening and engagement. USA TODAY showcased the winners at the National Awards Summit in Nashville. Watch the video of the event here.

“Being recognized with this award reflects Fairway’s commitment to bringing our people together face-to-face,” said Fairway’s CEO and Founder Steve Jacobson. “Companies are better when their people are around each other. People need each other and they learn from each other, and we’re very intentional about creating opportunities for in-person collaboration at Fairway.”

Jacobson demonstrated that in-person collaboration when he traveled to Knoxville this week with Fairway Senior Vice President Dan Richards to spend time with one of Fairway’s branches and their local real estate partners. “We engaged in real conversations about the market, discussed what people are seeing on the ground, and talked about how Fairway keeps showing up for clients,” said Richards. “It’s a reflection of the same hands-on approach that has defined Fairway’s culture for more than two decades.”

“To be named a Top Workplace for six consecutive years speaks to Fairway’s leadership, our mindset, and the empowerment of our staff,” said Fairway’s Chief People and Engagement Officer Julie Fry. “Our strength isn’t just what we offer employees. What sets a top workplace apart is the daily commitment to people—prioritizing connection, valuing contributions, and creating an environment where employees feel energized to serve because they feel valued first.”

The winners are determined by authentic employee feedback captured through a confidential survey conducted by Energage, the HR research and technology company behind the Top Workplaces program since 2006. The results are calculated based on employee responses to statements about Workplace Experience Themes, which are proven indicators of high performance.

“Earning a USA TODAY Top Workplaces award is a testament to an organization’s credibility and commitment to a people-first culture,” said Eric Rubino, CEO of Energage. “This award, driven by real employee feedback, is more than just a recognition — it’s proof that your employees believe in the organization and its leadership. Job seekers and customers look for this trusted badge of credibility and excellence. It signals a company that values its people, and that kind of culture resonates in today’s competitive market”

About Fairway Home Mortgage
Madison, WI- and Carrollton, TX-based Fairway Independent Mortgage Corporation (NMLS #2289) is a full-service mortgage lender licensed in all 50 states. Fairway is the #2 overall retail lender in the U.S.

About Energage
Making the world a better place to work together.™
Energage is a purpose-driven company that helps organizations turn employee feedback into useful business intelligence and credible employer recognition through Top Workplaces. Built on 20 years of culture research and the results from 30 million employees surveyed across more than 80,000 organizations, Energage delivers the most accurate competitive benchmark available. With access to a unique combination of patented analytic tools and expert guidance, Energage customers lead the competition with an engaged workforce and an opportunity to gain recognition for their people-first approach to culture. For more information or to nominate your organization, visit energage.com or topworkplaces.com.

View original content to download multimedia:https://www.prnewswire.com/news-releases/fairway-home-mortgage-earns-prestigious-usa-today-top-workplaces-award-for-6th-consecutive-year-302753183.html

SOURCE Fairway Home Mortgage

Continue Reading

Trending