Connect with us

Technology

Group-IB reveals Hi-Tech Crime Trends 23/24: surge in ransomware against backdrop of growing AI, macOS threats

Published

on

SINGAPORE, Feb. 29, 2024 /PRNewswire/ — Group-IB, a leading creator of cybersecurity technologies to investigate, prevent, and fight digital crime, is proud to announce the launch of its new report Hi-Tech Crime Trends 2023/2024, the latest edition of the company’s annual round-up of the most pressing global cyber threats to organizations and individuals. In the research, Group-IB analysts reveal how the unholy alliance between ransomware groups and Initial Access Brokers (IABs) is still the powerful engine for cybercriminal industry, evidenced by the 74% year-on-year increase in the number of companies that had their data uploaded on dedicated leak sites (DLS). Global threat actors also demonstrated increased interest in Apple platforms, exemplified by the fivefold increase in underground sales related to macOS information stealers.

The growing appetite of nation-state sponsored threat actors, also known as advanced persistent threat (APT) groups, has shown that no region is immune to cyber threats. Group-IB experts discovered a 70% increase in the number of public posts offering zero-day exploits for sale, and also identified cybercriminals’ malicious use of legitimate services and artificial intelligence (AI) infused technologies as the main cyber risks for 2024.

The first edition of Hi-Tech Crime Trends was launched 12 years ago, and the information contained in the report enables businesses, NGOs, governments, and law enforcement agencies around the world to fight cybercrime and help potential victims. For the first time, Hi-Tech Crime Trends includes a section outlining the intricate relationship between artificial intelligence (AI) and cybersecurity threats, outlining how this new technology is being leveraged by cybercriminals, including the misuse of large language models (LLM) such as ChatGPT, and the potential risks to corporate data through AI integration.

Nothing artificial about this threat

Threat actors have already shown how AI can help them develop malware only with a limited knowledge of programming languages, brainstorm new TTPs, compose convincing text to be used in social engineering attacks, and also increase their operational productivity.

Large language models (LLM) such as ChatGPT remain in widespread use, and Group-IB analysts have observed continued interest on underground forums in ChatGPT jailbreaking and specialized generative pre-trained transformer (GPT) development, looking for ways to bypass ChatGPT’s security controls. Group-IB experts have also noticed how, since mid-2023, four ChatGPT-style tools have been developed for the purpose of assisting cybercriminal activity: WolfGPT, DarkBARD, FraudGPT, and WormGPT – all with different functionalities.

FraudGPT and WormGPT are highly discussed tools on underground forums and Telegram channels, tailored for social engineering and phishing. Conversely, tools like WolfGPT, focusing on code or exploits, are less popular due to training complexities and usability issues. Yet, their advancement poses risks for sophisticated attacks.

Group-IB’s Hi-Tech Crime Trends 2023/2024 also highlighted the sale of compromised ChatGPT credentials on the dark web, building upon past research. With more employees relying on ChatGPT for work optimization and its storage of past interactions, compromised logins could expose sensitive information, posing significant security risks for businesses.

From January 2023 to October 2023, Group-IB detected more than 225,000 logs up for sale on the dark web containing compromised ChatGPT credentials. Group-IB’s Threat Intelligence platform found these compromised credentials within the logs of information-stealing malware traded on illicit dark web marketplaces.

Notably, the number of compromised hosts with access to ChatGPT detected by Threat Intelligence between June 2023 and October 2023 was more than 130,000, an increase of 36% compared to the preceding five-month period (January-May 2023). The number of available logs containing ChatGPT logs peaked in the final month of the study – in October 2023 – when 33,080 were registered. Group-IB’s analysis found that the majority of the logs containing ChatGPT accounts were breached by the LummaC2 information stealer.

Double trouble: ransomware gangs and initial access brokers wreak havoc

Group-IB’s Threat Intelligence unit constantly monitors all ransomware activity and detected 4,583 companies that had their information, files, and data published on ransomware DLSs in 2023. This marks a growth of 74% compared to the previous year, when 2,629 such posts were made. Group-IB researchers note that the number of total ransomware attacks worldwide is likely to be much larger, with probable instances of organizations paying the ransom or groups deciding not to go ahead with their threat of publishing data on a DLS.

Companies based in North America most commonly appeared in the DLS posts of ransomware groups, accounting for 2,487 (or 54%) of the annual total, and more than double the corresponding figure in 2022 (1,192 companies). Roughly 26% of posts on ransomware DLSs related to companies from Europe (1,186, up 52% YoY) and 10% were from the APAC region (463, up 39% YoY).

The United States was the most common target for ransomware groups, as 1,060 US-based companies were the subject of ransomware DLS posts in 2023. The next most affected countries were Germany (129), Canada (115), France (103), and Italy (100). 

In terms of affected industries, attacks as per ransomware DLS on manufacturing (580 instances) and real estate (429) companies rose year-on-year by 125% and 165%, respectively, and these key sectors were the two most targeted worldwide. Notably, Group-IB observed a 88% year-on-year increase in ransomware DLS posts related to healthcare companies, and a 65% rise in posts concerning government and military organizations.

Throughout the reporting period, Group-IB experts uncovered 27 new advertisements for ransomware-as-a-service programs on dark web forums, including well-known groups such as Qilin, as well as other collectives that have yet to be seen in the wild. As was the case in 2022, LockBit was 2023’s most prominent ransomware-as-a-service group with 1,079 posts on its DLS (24% of the annual total). In second place was BlackCat with 427 posts (9% of annual total) and third was Clop (385 posts or 9%).

Researchers also found that Initial Access Brokers (IABs) are continuing to play a significant role in the ransomware market. In 2023, they found 2,675 instances of corporate put up for sale – almost an identical figure compared with 2022, when 2,702 offers were found.

Notably, Group-IB data shows that the average price for corporate access in 2023 was $2,470, which represents a 27% reduction compared to the preceding year. Group-IB analysts believe that this drop in average price is due to a rise in the number of new sellers entering the market that have lowered the price of their offers in order to attract buyers.

Companies in the United States (29%), the United Kingdom (4%) and Brazil (4%) were the most commonly featured in IAB offers. Professional services, government and military organizations, financial services, manufacturing, and real estate were the verticals that appeared most frequently.

APTitude test

Group-IB researchers discovered that the Asia-Pacific region was the world’s main battleground for nation-state sponsored threat actors, also known as advanced persistent threat (APT) groups last year. In sum, Group-IB attributed 523 attacks to nation-state actors across the globe in 2023.

Attacks on APAC organizations accounted for 34% of the global total, with Group-IB experts asserting that this may be due to the high level of financial technology development in this global economic hub in addition to geopolitical tensions. Europe was the second-most targeted region, accounting for 22% of all APT attacks, and the Middle East and Africa (MEA) was third (16% of APT attacks in 2023).

Unsurprisingly, government and military entities were the prime target of APT attacks in 2023, accounting for 28% of the annual figure. This strengthens the theory of Group-IB’s Threat Intelligence unit that APT actors are predominantly striving to gain access to strategically important evidence and weaken government entities in their country or region of target. Financial services (6%), telecommunications (5%), manufacturing, IT and media (all 4%) were also heavily affected, Group-IB researchers found.

In the past year, prominent APT groups, including the North Korean collective Lazarus, launched new tactics. Lazarus executed the first-ever double supply chain attack, exploiting a vulnerability in X_TRADER, a software by Trading Technologies. This allowed access to the network of the widely-used 3CX Desktop App for VoIP calls, compromising a wide range of 3CX clients. Group-IB researchers also noted APT groups’ ongoing malicious use of legitimate services like Dropbox, OneDrive, Google Drive, and messengers like Telegram.

Turbulence ahead

In 2023, cyber threats shifted focus from Windows and Android to Apple platforms due to their rising popularity and market share, with iOS becoming increasingly targeted. Malware spread through the App Store, alongside increased use of Apple cloud services, contributed to this trend. By March 6, 2024, Apple is expected to allow third-party app stores for iOS apps in Europe, posing security concerns amidst 1.7 million app rejections in 2022. Threat actors have already adapted Android schemes to iOS, exemplified by GoldFactory and the GoldPickaxe.iOS malware – аctive in Thailand and Vietnam – which prompts victims to record videos of their faces and submit them to the threat actors, which could be used by the latter to gain unauthorized access to the victim’s banking accounts. Additionally, the number of sales posts on the most popular underground forums (xss[.]is and exploit[.]in) for information stealers designed to operate on macOS increased fivefold in 2023, from 8 in 2022 to 49.

Javascript sniffers, also known as malicious JavaScript code implanted in compromised websites designed to intercept payment card details from customers who make online transactions, are also likely to pose a risk to online store owners, consumers, and banks in 2024. Group-IB researchers discovered 5,037 websites compromised with JS-sniffers in 2023, of which 2,474 were unique. A total of 14 new JS-sniffer families were also discovered in 2023, highlighting the continued development of this threat.

“As highlighted by Group-IB’s Hi-Tech Crime Trends 2023/2024 report, the rise of AI in both legitimate businesses and the cybercriminal underworld was a critical trend of 2023. With the increased misuse of ChatGPT and the development of underground LLM tools, the potential for sophisticated attacks has escalated, compounded by the alarming surge in compromised ChatGPT credentials. This along with cybercriminals’ increased interest in malware designed for macOS demonstrates that it is imperative for organizations to recognize and address this evolving threat landscape, safeguarding sensitive information and fortifying cybersecurity measures to mitigate risks posed by AI-driven cybercrime,” Dmitry Volkov, CEO at Group-IB, said.

A full round-up of the top global threats and invaluable insights from the Group-IB Threat Intelligence unit can be found in the full Hi-Tech Crime Trends 2023/2024 report.

View original content to download multimedia:https://www.prnewswire.com/news-releases/group-ib-reveals-hi-tech-crime-trends-2324-surge-in-ransomware-against-backdrop-of-growing-ai-macos-threats-302075538.html

SOURCE Group-IB

Continue Reading

Technology

Rho Launches Card Payments on Invoices, Letting Businesses Accept Credit Card, Debit Card, and Google Pay

Published

on

By

Rho Invoicing customers can now accept credit card payments on invoices alongside ACH and wire, from the same account they already use for banking, with invoices syncing automatically to QuickBooks Online

NEW YORK, Sept. 4, 2026 /PRNewswire/ — Rho, the all-in-one finance platform for businesses, today announced that Rho Invoicing customers can now accept credit and debit card payments, including Google Pay, directly on their invoices. The feature is rolling out to eligible Rho Invoicing customers and adds to the existing ACH, domestic wire, and international wire options already available on Rho invoices. No separate merchant account, no new dashboard, and no waiting on a wire.

Here is how it works for the payer: your client opens the invoice, enters their card information, and pays in a few clicks. Card payments carry a processing fee of 2.9% plus $0.30 per transaction, paid by the business issuing the invoice and deducted from the payment before depositing into your account. Inbound ACH and wire stay free, and the payer never sees a surcharge at checkout. Card payments cover USD-denominated invoices and have a default daily limit of $10,000 across all of a business’s invoices, which can be raised on request.

An invoice is marked paid once the payout is initiated, and funds follow on card-network timelines rather than instantly. A business’s first card payment can take up to two weeks to deposit while Stripe, which powers Rho’s card payment features, completes its initial review.

Rho Invoicing remains free for all Rho customers, aside from card processing fees, and supports up to 100 line items per invoice with per-line sales tax, recurring billing, payment matching, and a fully white-labeled template that carries the business’s brand rather than Rho’s, with virtual account numbers that keep the business’s actual bank details private. Rho invoices sync into QuickBooks Online as accounts receivable through Rho’s direct integration, so AR aging stays accurate without duplicate entry.

Card payments run through the same Rho account a business already uses for banking, corporate cards, and bill pay. No merchant account. No second dashboard. No new password to add to a growing list. Getting paid should not add another tool to the financial stack.

Availability is limited to eligible Rho Invoicing customers for USD-denominated invoices. Access to and enablement of card payment functionality requires completion of Stripe’s verification process and is subject to third-party underwriting and approval, which is not guaranteed.

To learn more, read how to accept credit card payments with Rho Invoicing.

About Rho

Rho is the modern banking platform built for the AI era. Startups and growth-stage companies can open accounts in minutes, issue cards, manage expenses, pay bills, and close the books – all in one connected platform backed by real human support.

Rho is a fintech company, not a bank or an FDIC-insured depository institution. Checking account and card services provided by Webster Bank, a division of Santander Bank, N.A. Member FDIC.

Card payment features on Rho Invoicing, including credit card, debit card, and Google Pay options, are powered by Stripe, Inc. This content is for informational purposes only. It doesn’t necessarily reflect the views of Rho and should not be construed as legal, tax, benefits, financial, accounting, or other advice. If you need specific advice for your business, please consult with an expert, as rules and regulations change regularly.

Media Contact:
Justin Wolz
justin.wolz@rho.co
(919) 306-7084

View original content:https://www.prnewswire.com/news-releases/rho-launches-card-payments-on-invoices-letting-businesses-accept-credit-card-debit-card-and-google-pay-302870490.html

SOURCE Rho

Continue Reading

Technology

Amwell Receives Frost & Sullivan’s 2026 United States Technology Innovation Leadership Recognition for Technology-Enabled Care Platforms

Published

on

By

Amwell® is transforming virtual care delivery through its unified Amwell Platform, combining interoperability, clinical integration, and intelligent orchestration to improve access, efficiency, and outcomes.

SAN ANTONIO, Sept. 4, 2026 /CNW/ — As healthcare organizations move beyond fragmented telehealth solutions toward connected virtual care models, Amwell is helping redefine how digital care is delivered at scale. Frost & Sullivan is pleased to recognize Amwell with the 2026 United States Technology Innovation Leadership Recognition in the Technology-Enabled Care Platforms industry for its ability to address healthcare fragmentation through a unified platform that connects patients, health plan members, clinicians, and partner ecosystems across the care continuum.

Frost & Sullivan evaluates companies through a rigorous benchmarking process across two core dimensions: strategy effectiveness and strategy execution. Amwell excelled in both, demonstrating its ability to align strategic initiatives with evolving healthcare needs while executing with flexibility, scalability, and measurable customer impact. “The combination of reliability, flexibility, and clinically integrated workflows positions the Amwell Platform as a strategic enabler for organizations seeking to reduce fragmentation, improve member engagement with covered programs, expand access to care, and create more connected healthcare experiences,” said Sagar Mukhekar, Industry Analyst, Frost & Sullivan.

Guided by a strategy centered on connected care, interoperability, and continuous, digital innovation, Amwell has positioned the Amwell Platform as an operating layer for next-generation healthcare delivery. Rather than relying on disconnected point solutions, the platform integrates technology, services, and clinical intelligence to orchestrate personalized care experiences across virtual primary care, urgent care, behavioral health, chronic condition management, and specialized digital programs.

Backed by 20 years of technology-enabled care innovation, more than 90 million covered lives, and over 38.7 million virtual visits, Amwell continues to help health plans and healthcare organizations modernize digital care delivery at scale.

“As healthcare becomes more digital, it risks becoming more fragmented. Health plans need more than point solutions. They need enterprise infrastructure, clinical integration, and an open platform that brings partners and programs together. Our vision at Amwell is that technology creates value when it improves access, engagement, quality, and efficiency, and produces measurable clinical and business outcomes. We’re honored by this recognition from Frost & Sullivan,” said Dan Zamansky, Chief Product and Technology Officer at Amwell.

Amwell’s enterprise scale includes supporting the digital transformation of the Defense Health Agency’s Military Health System, serving approximately 9.6 million beneficiaries. The company’s commitment to measurable outcomes is also reflected in a landmark National Institute of Mental Health (NIMH)-funded study, published in Nature Human Behaviour and among the largest studies of its kind. The study found that students offered SilverCloud® by Amwell® engaged in mental healthcare at more than double the rate of traditional care, experienced lower rates of mental health disorders, and generated an estimated $1.18 million in avoided costs for the study population.

The company further differentiates its platform through intelligent orchestration and navigation, helping guide members to appropriate programs while giving clinicians visibility across care plans. Amwell also evaluates integrated third-party programs for clinical effectiveness, scalability, and enterprise readiness.

Frost & Sullivan commends Amwell for setting a high standard in competitive strategy, execution, and technological innovation. The company’s unified approach to digital care is helping reduce fragmentation, improve access, strengthen operational efficiency, and support more equitable and sustainable healthcare delivery.

Each year, Frost & Sullivan presents the Technology Innovation Leadership Recognition to a company that demonstrates outstanding strategy development and implementation, resulting in measurable improvements in market share, customer satisfaction, and competitive positioning. The recognition identifies forward-thinking organizations that are reshaping their industries through innovation and growth excellence.

Frost & Sullivan Best Practices Recognition

Frost & Sullivan’s Best Practices Recognitions honor companies across regional and global markets that exhibit exceptional achievement and consistent excellence in areas such as leadership, technological innovation, customer experience, and strategic product development. Each recognition is the result of a rigorous analytical process in which Frost & Sullivan industry experts benchmark performance through comprehensive interviews, deep-dive analysis, and extensive secondary research. The goal is to identify true best-in-class organizations that are driving transformative growth and setting new industry standards.
Contact us: Start the discussion.

Contact:
Ashley Shreve
E: ashley.weinkauf@frost.com 

View original content:https://www.prnewswire.com/news-releases/amwell-receives-frost–sullivans-2026-united-states-technology-innovation-leadership-recognition-for-technology-enabled-care-platforms-302870492.html

SOURCE Frost & Sullivan

Continue Reading

Technology

Midea Brings “Simply ideal” to Life at IFA 2026

Published

on

By

BERLIN, Sept. 4, 2026 /PRNewswire/ — At IFA 2026, Midea brings its “Simply ideal” vision to life through the latest innovations, designed to bring greater intelligence, comfort, efficiency and ease to the home.

The exhibition also highlights Midea’s new five-year partnership with FC Barcelona.

The Midea Suites: Ways to Master the Home

The new SMART MASTER showcases Midea’s AI-powered home ecosystem. The AI Agent enables more natural, intuitive interaction with appliances across daily household scenarios. Midea Robot brings AI into the physical world through cooking, cleaning, laundry, care and whole-home control.

At IFA 2026, Midea unveiled its new AI voice-controlled air conditioner. Cliff Liang, General Manager of Enterprise Commercial for the China Region at Microsoft, joined the Midea event and shared Microsoft’s perspective on the next phase of AI.

AI ECOMASTER coordinates appliances and connected systems through intelligent power management. It learns household routines and adapts to changing needs for greater flexibility and comfort.

For homes where every inch counts, SPACE MASTER delivers more usable capacity within the same external dimensions, as demonstrated by the refrigerator’s expanded storage.

Alongside the MASTER Suites, the BUILT-IN Series includes the Milanese-inspired Ispira Series, combining cohesive design with intelligent functionality for an integrated cooking experience.

The Midea Scenarios: Innovation for Everyday Living

Comfort begins with the air around us. Midea’s R290 Series responds to growing demand for efficient cooling. It combines advanced compressor and safety-sealing technologies with ultra-low-GWP R290 refrigerant, delivering around 10% higher energy efficiency. Residential applications include H-Pack and PortaSplit, with PortaSplit set to adopt R290 in 2027.

In the kitchen, technology simplifies daily routines, from food storage and cooking to after-meal care. The Visionary Series refrigerators make food easier to see and access through GlassVision, hands-free lighting and clear, even illumination.

The InfiniteFit Series hobs feature an ultra-slim design for seamless integration into European kitchens, while OmniFlex enables flexible cookware placement. The PizzaPro built-in oven combines rapid heating with an 81L cavity, balancing speed with capacity.

After the meal, the Tri-GreenApex System brings washing, drying and storage together while using around 50% less energy than required for Europe’s highest A rating.

Laundry brings its own everyday needs. Midea’s family laundry room concept combines multi-drum solutions for different garment-care needs, allowing separate loads to run at the same time. The OMNI SERIES offers flexible combinations to suit different household routines.

Tobin Richardson, President and CEO of the Connectivity Standards Alliance, introduced Matter at Midea’s booth, highlighting its open, secure, interoperable framework and Midea’s role in advancing smart appliance connectivity.

Partnership and Brand Portfolio

At IFA 2026, Midea celebrated its partnership through an immersive FC Barcelona experience at its booth. FC Barcelona legend Carles Puyol made a special appearance, sharing insights from his career on leadership, teamwork and the pursuit of excellence. His presence reflected Midea and FC Barcelona’s shared commitment to world-class performance.

As part of Midea Group’s multi-brand portfolio, TEKA presents its latest innovations under the “Meaningful Experiences Through Technology” concept, including its new coffee machine range, the In-Line Series and Laundry Care solutions, bringing European design and functionality to modern living.

About Midea and Midea Group

Midea is one of over 10 brands within the Smart Home Business of Midea Group.

Founded in 1968, Midea Group is a leading global technology company and one of the world’s largest home appliance manufacturers. As a Fortune Global 500 enterprise, it ranked No. 231 in 2026. The Group has streamlined its core operations into seven high-growth business pillars to drive future growth: Smart Home, Industrial Technologies, Building Technologies, KUKA, New Energy, Midea Healthcare, and ANNTO Logistics.

www.midea-group.com

www.midea.com

View original content to download multimedia:https://www.prnewswire.com/news-releases/midea-brings-simply-ideal-to-life-at-ifa-2026-302870435.html

SOURCE Midea Group

Continue Reading

Trending