APAC CIOOutlook
About UsConferencePartner With Us
  • Technologies
    • Blockchain
      Data Intelligence and Management
      Digital Transformation
      FinTech
      Generative and Agentic AI
      Low Code No Code
      Mobile Application
      Networking
      Robotics
      Storage
      Wireless
  • Industries
    • Automotive
      Aviation
      Banking
      Construction
      E-Commerce
      Food and Beverages
      Healthcare
      Insurance
      Logistics
      Manufacturing
      Retail
      Supply Chain
      Travel and Hospitality
  • Platforms
    • Microsoft
      Salesforce
      SAP
  • Strategic Solutions
    • Business Intelligence
      Contact Center
      Corporate Finance
      CRM
      Cyber Security
      Data Center
      Enterprise Asset Management
      Enterprise Performance Management
      IT Infrastructure and Services
      Managed Services
      Procurement
      Unified Communication
      Workflow
  • Home
  • CXO Insights
  • Leadership Perspectives
  • Innovation Insights
  • Research
  • News
  • Whitepapers
  • CXO Awards
#

Apac CIOOutlook Weekly Brief

×

Be first to read the latest tech news, Industry Leader's Insights, and CIO interviews of medium and large enterprises exclusively from Apac CIOOutlook

Subscribe

loading

THANK YOU FOR SUBSCRIBING

  • Home
  • News

Quantum leap in cybersecurity: Group-IB brings new type of solution for threat hunting and attack prevention to market

By

Apac CIOOutlook | Thursday, December 03, 2020

Singapore - Group-IB, a global threat hunting and intelligence company, has revealed the results of its yearslong development of proprietary high-tech products for threat hunting and research ” Threat Intelligence & Attribution and Threat Hunting Framework. Altogether the solutions represent a new smart cybersecurity ecosystem uniting Group-IBs patented innovative technologies unveiled by Group-IB at CyberCrimeCon 2020, a global threat hunting and intelligence conference.

Group-IB has become the first company to offer a new type of solution called Threat Intelligence & Attribution. The system is designed to create and customize a cyber threat map for a specific company, correlate individual cybersecurity events in real-time, and attribute attacks to a particular threat actor. The creation of TI&A marks the emergence of a new type of solution for collecting data on threats and attackers relevant for a particular organization with the aim of examination and proactive hunting for threat actors, research, and protection of network infrastructure. Currently, there no analogues to TI&A on the international market.

Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.

Yet another innovation presented by Group-IB is Threat Hunting Framework “ a system for IT and OT networks that protects against unknown threats and targeted attacks, hunts for threats both within and outside the protected organization's perimeter, and helps investigate and respond to cybersecurity incidents and minimize their impact.

According to Hi-Tech Crime Trends 2020-2021, a report that provides an analysis of high-tech crimes worldwide, the merge of various cybercrime segments has led to the appearance of new threats, which resulted in increased damage as a result of attacks. Thus, analysts most conservative estimates suggest that the overall damage to companies in 45 countries caused by known ransomware incidents amounts to over $1 billion. The market for selling access to compromised corporate infrastructures has grown at an explosive pace: in one year it has increased four-fold reaching $6,189,388. The number of sellers has jumped to 63, with both cybercriminals and state-sponsored actors among them. Compared to the previous period, the size of the carding market, which is connected with the theft of bank card data, has grown by 116% nearing $2 billion. In the face of these challenges, public and private sector companies have to reevaluate their cybersecurity strategies and focus on hunting threats, relevant to their specific industry.

Today, Group-IB presented the result of the evolution of its proprietary high-tech crime investigation and cyberattack prevention product line, which includes two innovative solutions: Threat Hunting Framework (THF) and Threat Intelligence & Attribution (TI&A). The complex engineering systems are connected to each other brought together in a single smart ecosystem capable of automatically halting targeted attacks against organizations. The ecosystem provides security teams with tools for linking individual events, attributing threats, analyzing malicious code, and instantly responding to cyber incidents. It is based on the patented technologies developed by Group-IBs analysts and engineering teams.

Group-IB currently has 33 patents (including 6 in the United States, 5 in the Netherlands, 4 in Singapore, and elsewhere). All of them were issued for the technologies lying at the heart of TI&A, THF and the companys other innovative products. In addition, Group-IB has 55 patent applications (14 in the United States, 5 in the Netherlands, 12 in Singapore, and 24 more internationally).

The dynamic of cybercrime is signaling to the market that companies should be able to prevent most threats automatically, but this is not enough, says Group-IB CTO Dmitry Volkov. Smart threat actors with money and resources will eventually learn to bypass any automated detection system. You need to prepare for that by building your experience in hunting for threats using tools customized to this task. In this fight, blocking will not help: tomorrow you will be attacked based on how you stop the threat today. Hunting for threats is an ongoing process based on the ability to handle huge amounts of internal and external data lakes, ranging from system events and traffic metadata to domains, hosts, and hacker groups' profiles. To be able to work with this data means to be a professional threat hunter. This is the future of cybersecurity.

Group-IBs team of engineers base their development of cybersecurity technologies on several principles. Firstly, detection systems and algorithms have to be adversary-centric; this means that cybersecurity experts should receive alerts with either clear technical justification or full intelligence context on a given threat: who the attackers are, what their motivation is, what their tactic is, and what IOCs and TTPs are expected to be used in further attacks. When possible, a solution has to block threats immediately, but detection and blocking is not enough. This is only the beginning of building effective security systems.

Secondly, the enrichment process has to be fully automated and should provide as much context related to IOCs and TTPs as possible. To achieve that, an analysis engine must go beyond simple threat detection: it is crucial to extract and fully detonate discovered payloads in a safe isolated environment, harvesting indicators of compromise that help in subsequent threat hunting activities. Thirdly, threat hunting is a crucial process of proactive searching for something that could have been missed in the past and potentially might be missed in the future.

Detection is never enough

Group-IB Threat Hunting Framework (THF) is the first all-in-one solution for protection of both IT and OT networks. The fact that Group-IB AI-driven Threat Hunting Framework, the only of its kind, serves as a single cybersecurity solution and unites standards for two different network segments is a quantum leap in cybersecurity market that changes the rules inside the industry.

The new products key goals are the detection of previously unknown threats and targeted attacks, the containing of detected threats and automation of instruments for identifying links between threats both inside and outside of the protected perimeter. The THF has a patented malware detonation technology that goes beyond traditional sandboxing and sets up new industry standards for file analysis solutions and an innovative endpoint module for real-time host protection and malicious behavior detection with a unique patented server-side classifier. Threat Hunting Framework architecture has several main modules, each of which is innovative in its nature and whose functionality goes beyond the existing product categories defining absolutely new type of cybersecurity solutions.

THF Sensor is designed to identify threats at the network level thanks to an in-depth analysis of network traffic. The solution identifies threats and infected hosts by analyzing the network traffic protecting not only IT segment of the network, but also OT network with the help of its Sensor Industrial module. The module ensures that the integrity of ICS software is under control by analyzing industrial protocols and protecting corporate networks comprehensively, detecting threats with the use of its high-performance AI-driven classifier.

Group-IB's another innovation is THF Polygon. This platform is designed to detonate malware. It detects threats by performing behavior analysis of emails, files, and links and runs malware in an isolated environment. It is crucial to fully detonate the discovered payloads and extract all related IOCs and artifacts to be able to attribute the attacks.

Email remains a key system for initial compromise for cybercriminals. This problem affects businesses of any size. In response to this threat, Group-IB for the first time presented its cloud-based solution for the prevention of all types of email attacks ” Atmosphere. Atmosphere aims to make cutting-edge technologies for detecting email threats affordable and easily deployable, while at the same time keeping the technology part of Threat Hunting Framework and offering not only qualitative filtering of emails, but also the rest of THFs advantages: malware detonation, attack attribution and integration with other modules of the ecosystem.

For the first time, Group-IB has introduced a solution for protecting end hosts: Huntpoint. This module creates a complete timeline of events on the host, which is available both in real time and retrospectively, detects abnormal behavior, and blocks malicious files. What is more, it isolates hosts from the network and collects forensic data for further research.

The Huntbox module is responsible for fully automated analysis and correlation of network events. This module provides a full picture of threats within and beyond an organizations network, helping to hunt for threats and identify malicious activity targeting the company. Group-IB Threat Hunting Framework capabilities are enhanced by the Decryptor module, which is designed to decrypt TLS/SSL traffic in the protected infrastructure.

Group-IB provides access to its internal tools for tracking hackers

Threat Intelligence & Attribution, which is one of the most heavily loaded Group-IB systems ” it handles petabytes of data on adversaries and their tools and infrastructure, ” has leaped forward. Today, TI&A marks the creation of a new type of solutions for collecting data on threats and attackers relevant to a specific organization. It helps analyze adversaries and their tools in order to proactively hunt for criminal groups and protect network infrastructure.

TI&A combines unique data sources and experience in investigating high-tech crimes and responding to complex multi-stage attacks worldwide to enrich all other Group-IB products with data for hunting for attackers and threats. The system stores data on threat actors, domains, IPs, and infrastructures collected over the last 15 years, including those that criminals attempted to wipe out. The extensive functionality of the system helps customize it to the threat landscape not only relevant to a particular industry, but also to a specific company in a certain country.

TI&A takes an adversary-centric approach to threat protection. The idea behind the system is that it hunts not only for threats, but also for the adversaries behind them. The data lakes operated by the system help quickly link attacks to specific groups or even individuals. TI&A helps promptly analyze and attribute threats that a company faces, detect leaks, insiders and compromised user accounts. Moreover, it identifies insiders who sell company data on underground resources and detects and thwarts attacks targeting companies and their customers regardless of industry.

The launch of TI&A on the market provides access to Group-IB's internal tools, which were previously used only by Group-IB's DFIR, threat hunting, and cyber threat intelligence teams. Every specialist who uses TI&A now has access to the largest collection of dark web data, an advanced hacker group profiling model, and a fully automated graph analysis tool that helps correlate data and attribute threats to specific criminal groups in seconds.

As such, TI&A makes it possible to detect attacks overlooked by common cyber defense tools. It helps understand how advanced adversaries behave and whether the protected infrastructure can counteract them. This approach helps motivate and improve internal cybersecurity teams as well as enhance their capabilities through an in-depth insight into threats targeting their organizations.

TI&A is a complex engineering system developed by Group-IB and integrated into a smart technological ecosystem that is capable of automatically halting targeted attacks on organisation. The ecosystem provides security teams with tools for linking individual events, attributing threats, analyzing malicious code, and instantly responding to cyber incidents.

More in News

The Strategic Value of Strong Supplier Relationships

...Read more

Quantum Technology: Driving APAC Industrial Transformation

Quantum technology is significantly advancing the fields of computation, communication, and sensing, thereby creating opportunities that were previously considered theoretical. Various organizations and research institutions are engaged in competition to develop more reliable qubits, implement effective error correction techniques, and establish scalable systems capable of addressing challenges that surpass the capabilities of classical computers. Emerging practical applications span a range of areas, including the acceleration of drug discovery, enhancement of cybersecurity measures, and optimization of complex logistical operations. Although challenges such as hardware fragility, environmental sensitivity, and substantial development costs remain, ongoing innovations in materials, cooling systems, and quantum algorithms are progressively mitigating these issues. Consequently, quantum technology is a domain where promise and progress are evolving in tandem. How Does Quantum Technology Benefit Industries Today? Quantum technology is starting to deliver real benefits across several industries by solving problems that were previously too complex or time-consuming for classical systems. In pharmaceuticals, quantum simulations are helping researchers model molecular interactions more accurately, speeding up drug discovery and reducing trial-and-error testing. Finance companies are exploring quantum algorithms to optimize portfolios, manage risk, and detect fraud faster than traditional systems. Even logistics and manufacturing are seeing advantages, with quantum-based optimization improving supply chain efficiency and resource allocation in ways that were once impossible at scale. Beyond computational speed, industries are also benefiting from advances in quantum sensing and communication. Quantum sensors offer unprecedented precision in fields like navigation, energy exploration, and environmental monitoring, while quantum encryption promises highly secure communication channels that could transform data security. By integrating these capabilities, businesses can make smarter decisions, reduce costs, and innovate faster. While adoption is still in early stages, the combination of computation, sensing, and secure communication is already giving forward-looking companies a competitive edge, showing that Quantum technology is moving from theory into tangible industry impact. What Innovations Are Shaping the Future of Quantum Technology? The future of Quantum technology is being driven by innovations that make quantum systems more stable, scalable, and practical for real-world use. Advances in qubit design, materials, and error-correction techniques are improving reliability, while hybrid quantum-classical algorithms allow businesses and researchers to harness quantum capabilities even before fully fault-tolerant machines are ready. This is opening early applications in areas like finance, logistics, and healthcare, where complex problems can be solved faster and more accurately than ever before. Moreover, breakthroughs in quantum communication, sensing, and software are expanding its reach. Quantum networks promise ultra-secure data transfer, while quantum sensors deliver unmatched precision in navigation, energy, and environmental monitoring. Cloud-based platforms are also making quantum tools accessible to smaller organizations, democratizing experimentation and innovation. Together, these advancements are positioning Quantum technology as a transformative force that can reshape industries, accelerate scientific discovery, and unlock entirely new possibilities. ...Read more

Mastering PPP project analysis, financing, contracts & transaction management techniques

Infocus International is delighted to bring one of their best virtual workshops,  Public-Private Partnership (PPP)  that will be set to commence  17 August 2026 . We need new infrastructure. Roads, airports, schools, hospitals and housing: the list is enormous and growing. Yet severely limited budgets, economic uncertainty caused by volatile commodity prices, and deficits continue to prevent government at all levels from delivering the kinds of structural change that has always been needed. In response, some countries have developed successful PPP programmes. Merely grasping the concepts of PPP does not do justice to our great responsibility of having an ownership in the country’s future. We already know what we need to do, now is the time to really discover HOW. One of our participants from  Electricity Generation Company (Malawi) Ltd  shared that, “ The facilitator was very knowledgeable on the subject matter, very responsive to questions and innovative in the delivery of the PPP training program. The knowledge gained will assist me in productive participation in ongoing and planned PPP Projects in my country.” Another participant from  PNG Ports Corporation  also mentioned that,  “This is an excellent course for anyone involved in PPP. Highly recommended.” Benefits of Attending • Use best practices from international case studies of successful PPP transactions and common practical pitfalls to avoid • Design and manage PPP legal, regulatory & institutional frameworks to attract investors and complete PPP transactions • Apply models for the efficient design and completion of PPP feasibility studies • Understand project financing requirements and evaluate PPP financial models for both affordability and bankability • Evaluate and apply different credit enhancement techniques to ensure PPP bankability, including blended financing, viability gap funding (VGF), partial guarantees, risk insurance products, output-based aid (OBA) and other financial instruments • Design PPP transaction implementation plans and manage & oversee PPP transaction advisors for reaching commercial closure and financial closure • Models for PPP tender documents, including PPP Project Information Memoranda (“InfoMemos”), Requests for Qualifications (RFQs), Requests for Proposals (RFPs) • International models for designing and drafting PPP contracts & agreements • Environmental & social impact mitigation techniques to structure sustainable private investments in public infrastructure • Plans for managing sustainable PPP contracts including ensuring technical performance, quality of service delivery, price review & adjustment regulatory models, legal contract management and alternative dispute resolution (ADR) techniques Want to learn more? Simply email  media@infocusinternational.com  to register your attendance. For more information, please visit  https://www.infocusinternational.com/ppp-online ...Read more

Deploying Big Data Analysis to Develop IoT Solutions

Data from various sources forms the basic foundation of businesses. In the present times, the improvement of connectivity in the IoT space has resulted in the transfer of huge chunks of data. Therefore, there is a need for big data analytics in IoT in order to address the challenges related to management of large-scale, through the data pipeline architecture. To begin with, data pipeline is the process concerned with the movement of data through an organization. Once data enters into an organization, the stage is referred to as data ingestion. Next in the process is the stage of data transportation from the data ingestion stage to the other stage is known as data collector. Followed by this, the data moves through the processing stage wherein appropriate measures are taken to store it. Data storage stage steps up to the data query stage where it is analyzed through interactive queries. The final stage is concerned with valid presentation of data in different forms of business infographics, such as graphs or statistics. Data generated in the IoT space requires a data management system with the following qualities: •  It should be adapted to manage and process a huge number of data sources, keeping pace with the continuous increase of IoT devices. •  The data management system must have a prompt response time in order to notify the concerned segment of the business in case of failures while processing or storing data. •  The system must be able to scale data on multiple parameters such as a number of devices, storage, and messages. •  Diversity and flexibility are required to process use cases and simultaneously accommodate new use cases. •  The data management system should be cost-effective. All the above criteria suggest that IoT requires interacting with big data analytics tools in order to manage such big chunks of data. ...Read more

I agree We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info

APAC CIOOutlook
Follow on LinkedIn

About

  • Home
  • About Us
  • Partner With Us

Stay Connected

  • Subscribe
  • Newsletter
  • Sitemap

Contact Us

  • editor@apacciooutlook.com
  • sales@apacciooutlook.com
  • marketing@apacciooutlook.com

Legal

  • Editorial Policy
  • Privacy Policy
  • Terms of Use

© 2026 APAC CIOOutlook. All rights reserved. Headquarteblue in Fort Lauderdale, FL, USA.

This content is copyright protected

However, if you would like to share the information in this article, you may use the link below:

https://www.apacciooutlook.com/news/quantum-leap-in-cybersecurity-groupib-brings-new-type-of-solution-for-threat-hunting-and-attack-prevention-to-market-pnid-84.html