logo
The 3 Masked Hackers Behind The World's Most Prolific Cyberattacks

The 3 Masked Hackers Behind The World's Most Prolific Cyberattacks

Forbes13-05-2025
10 masked cybercrime actors revealed.
From ransomware attacks demanding ridiculous payments of $1 trillion, or using insidious methods to watch victims at work, through to hackers stealing billions of passwords and publishing them to the dark web, cybercrime has never been as rife as it is today. Despite the best efforts of everyone from Google, Microsoft, and even the FBI, the attacks continue. But who are the hackers behind the crimes, the threat actors operating in the shadows to deliver these attacks? A newly published report has analyzed more than 1500 separate cybercrime investigations to reveal the most prolific cybercriminal groups, the masked hackers that continue to shape the threatscape.
New threat actors are continually emerging across the criminal landscape, often arising from the ashes of cybercrime groups that have been disrupted by law enforcement or have suffered from internal conflicts that lead to their disbandment. While some of these will gain traction and, in time, become an unwelcome addition to the cybersecurity lexicon, most will fall by the wayside. Those groups that have not only survived but are prospering are among the most prolific criminal actors operating today. 'Cross-border investigations and intelligence sharing are increasingly constrained by jurisdictional divides,' Dmitry Volkov, the Group-IB CEO, said, 'creating gaps that cybercriminals are quick to exploit.' Perhaps that partly explains why these gangs experience such longevity and success.
The May 13 High-Tech Crime Trends Report 2025, has analyzed more than 1,500 cybercrime investigations, enabling Group-IB threat intelligence analysts to identify who these groups are. It may come as something of a surprise, even to those who follow cybercrime reporting religiously, that the vast majority of the names on the list are unfamiliar.
Before we get to that, however, let's take a look at some of the other intelligence that this report has revealed concerning the cybercriminal threat landscape across 2024:
The U.S. hit hardest by ransomware attacks in 2024.
Although the full report is well worth reading, I would be doing a disservice if I didn't highlight the most prolific threat actors called out by the intelligence analysts across one or two important sectors.
There's the intriguingly-named 'NoName057(16)' sitting at the top of the hacktivist groups tree. Pro-Russian, and primarily using Distributed-Denial-of-Service attacks against government and financial institutions, NoName057(16) is said to be driven by 'political motives, particularly against information resources located in Europe.'
When it comes to APT attacks, Dark Pink sits at the top of the list by number of attacks, but Group-IB was unable to attribute these connected campaigns to any specific group. So, for me at least, that puts APT28 at number one — another Russian-speaking group, known to employ the currently highly-exploited ClickFix attack methodology using malicious CAPTCHA dialogs.
OK, let's move on to those three masked actors, the cybercriminal groups that have dominated cyberattacks during the past year, according to Group-IB threat intelligence.
The RansomHub ransomware-as-a-service operators, arising from the ashes of the infamous ALPHV or BlackCat group before it, are the prime cybercriminal gang. Since launching at the start of 2024, RansomHub has 'already surpassed even long-established cybercriminals in attacks,' according to the report, and is now the dominant force in the ransomware threat sector.
RansomHub - the number one most prolific cybercrime gang.
Sitting behind RansomHub, which you may have heard of, is GoldFactory, which you likely haven't. This mobile banking malware group was behind the first iOS banking trojan, which harvested facial recognition data to use in attacks. And in third place, one you will definitely know: Lazarus. This nation-state actor, which is known to keep rising from the dead, hence the original name, although it operates under many a pseudonym to evade detection, is thought to operate under the control of the North Korean intelligence agency, the Reconnaissance General Bureau. One thing is certain: these masked hackers, all of whom are included in the report and featured in an accompanying podcast, are well worth getting to know if you want to stay ahead in your defense efforts against them.
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Trump pauses export controls to bolster China trade deal, FT says
Trump pauses export controls to bolster China trade deal, FT says

Yahoo

time26 minutes ago

  • Yahoo

Trump pauses export controls to bolster China trade deal, FT says

(Reuters) -The U.S. has paused curbs on tech exports to China to avoid disrupting trade talks with Beijing and support President Donald Trump's efforts to secure a meeting with President Xi Jinping this year, the Financial Times said on Monday. The industry and security bureau of the Commerce Department, which oversees export controls, has been told in recent months to avoid tough moves on China, the newspaper said, citing current and former officials. Reuters could not immediately verify the report. The White House and the department did not respond to Reuters' requests for comment outside business hours. Top U.S. and Chinese economic officials are set to resume talks in Stockholm on Monday to tackle longstanding economic disputes at the centre of a trade war between the world's top two economies. Tech giant Nvidia said this month it would resume sales of its H20 graphics processing units (GPU) to China, reversing an export curb the Trump administration imposed in April to keep advanced AI chips out of Chinese hands over national security concerns. The planned resumption was part of U.S. negotiations on rare earths and magnets, Commerce Secretary Howard Lutnick has said. The paper said 20 security experts and former officials, including former deputy US national security adviser Matt Pottinger, will write on Monday to Lutnick to voice concern, however. "This move represents a strategic misstep that endangers the United States' economic and military edge in artificial intelligence," they write in the letter, it added.

EnduroSat and WISeSat.Space Partner to Deliver Quantum-Resilient Secure IoT Nanosatellite Infrastructure
EnduroSat and WISeSat.Space Partner to Deliver Quantum-Resilient Secure IoT Nanosatellite Infrastructure

Yahoo

time26 minutes ago

  • Yahoo

EnduroSat and WISeSat.Space Partner to Deliver Quantum-Resilient Secure IoT Nanosatellite Infrastructure

FOR IMMEDIATE RELEASE EnduroSat and Partner to Deliver Quantum-Resilient Secure IoT Nanosatellite Infrastructure Sofia, Bulgaria & Geneva, Switzerland – July 28, 2025 – WISeKey International Holding AG (SIX: WIHN, NASDAQ: WKEY), a leading global cybersecurity, blockchain, and IoT company, via its subsidiary AG, a company that focuses on space technology for secure satellite communication, specifically for IoT applications, and EnduroSat, a leading provider of software-flexible satellites, as part of their strategy to diversify partners in the industry, are pleased to announce the signing of a Memorandum of Understanding (MoU) to establish a framework aimed at achieving a strategic partnership to extend the development and deployment of ultra-secure, quantum-resilient nanosatellite systems for Internet of Things (IoT) applications. The cooperation targets the integration of SEALSQ secure elements, such as the VaultIC292, VaultIC408, and QS7001, into satellite payloads and ground-level endpoints. These components enable strong hardware-based security and digital identity protection, ensuring encrypted communications and trusted authentication across the IoT satellite network. The project aims to implement post-quantum cryptographic (PQC) algorithms, aligned with NIST recommendations such as CRYSTALS-Kyber and CRYSTALS-Dilithium, to safeguard against future quantum computing threats. WISeSat will provide the PQC algorithmic stack and support, while EnduroSat will incorporate these into its satellite and communication platform. EnduroSat brings its expertise in modular satellite design, in-orbit validation, and scalable deployment systems. It will lead the physical integration of SEALSQ secure components into next-generation satellite buses and contribute to the overall mission architecture. WISeSat will support cryptographic integration and field engineering resources, ensuring that each system meets high-security and resilience benchmarks. The partnership further outlines the future integration of post-quantum cryptographic solutions and secure elements into both EnduroSat and WISeSat satellite infrastructures. EnduroSat will also support the design and deployment of WISeSat's future missions, ensuring compliance with defined security and performance requirements. This collaboration builds on WISeSat's successful deployment of its new-generation PQC-ready nanosatellite in December 2025 and EnduroSat's proven record of delivering more than 60+ satellites to orbit for institutional, scientific, and commercial customers. The resulting architecture will offer scalable, tamper-proof IoT connectivity services from Low Earth Orbit (LEO), critical for use-cases in logistics, critical infrastructure, defense, and environmental monitoring. 'This partnership with EnduroSat marks a significant step forward in our mission to deliver quantum-resilient, end-to-end secure satellite infrastructure,' said Carlos Moreira, Founder and CEO of WISeKey. 'By integrating SEALSQ's advanced secure elements into the expanding WISeSat constellation, we are building a tamper-proof communications backbone in space. Together with EnduroSat's modular satellite technology, we are enabling scalable and ultra-secure IoT connectivity services from Low Earth Orbit—critical for securing data and infrastructure in the quantum era.' 'We are excited to initiate this partnership,' said Raycho Raychev, founder & CEO of EnduroSat. 'We hope to accelerate the introduction and establishment of much stronger encryption capabilities into the satellite industry.' About AG is pioneering a transformative approach to IoT connectivity and climate change monitoring through its innovative satellite constellation. By providing cost-effective, secure, and global IoT connectivity, WISeSat is enabling a wide range of applications that support environmental monitoring, disaster management, and sustainable practices. The integration of satellite data with advanced climate models holds great promise for enhancing our understanding of climate change and developing effective strategies to combat its impacts. As the world continues to grapple with the challenges of climate change, initiatives like WISeSat's IoT satellite constellation are essential for creating a more resilient and sustainable future. About WISeKeyWISeKey International Holding Ltd ('WISeKey', SIX: WIHN; Nasdaq: WKEY) is a global leader in cybersecurity, digital identity, and IoT solutions platform. It operates as a Swiss-based holding company through several operational subsidiaries, each dedicated to specific aspects of its technology portfolio. The subsidiaries include (i) SEALSQ Corp (Nasdaq: LAES), which focuses on semiconductors, PKI, and post-quantum technology products, (ii) WISeKey SA which specializes in RoT and PKI solutions for secure authentication and identification in IoT, Blockchain, and AI, (iii) WISeSat AG which focuses on space technology for secure satellite communication, specifically for IoT applications, (iv) Corp which focuses on trusted blockchain NFTs and operates the marketplace for secure NFT transactions, and (v) SEALCOIN AG which focuses on decentralized physical internet with DePIN technology and house the development of the SEALCOIN platform. Each subsidiary contributes to WISeKey's mission of securing the internet while focusing on their respective areas of research and expertise. Their technologies seamlessly integrate into the comprehensive WISeKey platform. WISeKey secures digital identity ecosystems for individuals and objects using Blockchain, AI, and IoT technologies. With over 1.6 billion microchips deployed across various IoT sectors, WISeKey plays a vital role in securing the Internet of Everything. The company's semiconductors generate valuable Big Data that, when analyzed with AI, enable predictive equipment failure prevention. Trusted by the OISTE/WISeKey cryptographic Root of Trust, WISeKey provides secure authentication and identification for IoT, Blockchain, and AI applications. The WISeKey Root of Trust ensures the integrity of online transactions between objects and people. For more information on WISeKey's strategic direction and its subsidiary companies, please visit About EnduroSatEnduroSat is a space infrastructure builder that engineers, builds, and operates exceptional satellites. The company streamlines space missions in LEO and beyond, handling every step from mission design to launch and operations. EnduroSat serves more than 360 customers globally and employs more than 230 space professionals across 6 locations worldwide. For more information, visit DisclaimerThis communication expressly or implicitly contains certain forward-looking statements concerning WISeKey International Holding Ltd and its business. Such statements involve certain known and unknown risks, uncertainties and other factors, which could cause the actual results, financial condition, performance or achievements of WISeKey International Holding Ltd to be materially different from any future results, performance or achievements expressed or implied by such forward-looking statements. WISeKey International Holding Ltd is providing this communication as of this date and does not undertake to update any forward-looking statements contained herein as a result of new information, future events or otherwise. This press release does not constitute an offer to sell, or a solicitation of an offer to buy, any securities, and it does not constitute an offering prospectus within the meaning of the Swiss Financial Services Act ('FinSA'), the FinSa's predecessor legislation or advertising within the meaning of the FinSA. Investors must rely on their own evaluation of WISeKey and its securities, including the merits and risks involved. Nothing contained herein is, or shall be relied on as, a promise or representation as to the future performance of WISeKey. Press and Investor Contacts WISeKey International Holding LtdCompany Contact: Carlos MoreiraChairman & CEOTel: +41 22 594 3000info@ WISeKey Investor Relations (US) The Equity Group CatiTel: +1 212 836-9611 lcati@ ENDUROSAT EADCompany Contact: Raycho RaychevFounder & CEOinfo@

UBQT Named Official Networking Platform for Step Conference San Francisco
UBQT Named Official Networking Platform for Step Conference San Francisco

Entrepreneur

time27 minutes ago

  • Entrepreneur

UBQT Named Official Networking Platform for Step Conference San Francisco

You're reading Entrepreneur Middle East, an international franchise of Entrepreneur Media. Step Conference, a tech event for emerging markets, has partnered with UBQT, an AI-powered platform enabling real-life catchups within professional communities, as its official networking platform for the upcoming San Francisco edition. UBQT will empower Step San Francisco (Step SF) attendees to plan professional catchups, connect across borders, and deepen relationships throughout the event. UBQT, co-founded by Lara Varjabedian, Jonathan L. Hasson, and I.Q. Sayed, is the tool of choice for community owners, event organisers, and corporates looking to drive engagement and social cohesion through meaningful in-person connections. With features that allow attendees to sync diaries, receive smart nudges when peers are nearby, and streamline spontaneous or planned catchups, UBQT ensures real-life moments are easy and frequent. This partnership reflects Step SF's commitment to building authentic, cross-border collaboration, and UBQT's mission to tech-enable communities to unlock social capital. Finding the 'human' in a digital world Screen fatigue and digital fragmentation has left many of us craving the energy and spontaneity of real-life interaction. UBQT empowers this, allowing organisations to drive high-quality engagement in real life. Attendees and speakers at Step SF will: - Receive smart catchup recommendations when someone from your network is nearby or planning to be nearby soon, - Align calendars and travel plans to coordinate catchups, - Make the most of the event by discovering the most relevant fellow attendees - founders, investors and ecosystem enablers, - Stay connected with the community well beyond the event. "UBQT goes beyond simply enabling great networking at Step SF. It empowers our attendees to connect meaningfully, not just during the event, but well beyond it," said Ray Dargham, co-founder and CEO at Step. "It's not just another event app; it's a true community engagement platform. We're proud to bring this experience to our San Francisco network." Related: Nurturing Connections: UBQT Co-Founders Jonathan L. Hasson And Lara Varjabedian

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store