True crime meets cybercrime. Discover the people behind the keyboard.
From Ransomware-as-a-Service (RaaS) gangs to global financial crime syndicates, the rise of sophisticated cyber threats is reshaping the world. These aren’t lone hackers — they’re organized groups running multi-million dollar operations in the shadows.
In the Masked Actors podcast, cyber threat expert and former soldier turned hacker Gary Ruddell joins forces with Nick Palmer, a seasoned financial crime fighter, to investigate the top 10 most dangerous cybercriminal groups of 2025 — drawn from Group-IB’s High-Tech Crime Trends Report.
Each episode explores the tactics, motivations, and impact of major cybercrime groups, uncovering their role in the latest cybercrime, RaaS, and financial crime trends. You’ll learn how these actors exploit vulnerabilities, fuel geopolitical tension, and affect businesses and consumers alike.
Tune in to Masked Actors — and stay one step ahead of cybercrime.
Host [Host Name] interviews cybersecurity expert [Guest Name] about the ShinyHunters hacking group's extensive operations and internal conflicts within the criminal underworld.
30 Sept 2026
MuddyWater: Expanding an Espionage Operation
Host [Host Name] interviews cybersecurity expert [Guest Name] about MuddyWater's decade-long evolution into an aggressive, expanding Iranian espionage operation.
10 Sept 2026TRANSCRIPT
Defenders: Two Front Lines - Fraud From the Case File and the Comments Section
Host [Host Name] interviews fraud expert [Guest Name] about the evolving global fraud economy and its psychological tactics.
20 Aug 2026TRANSCRIPT
GoldFactory: Rethinking Digital Identity in the Age of Biometric Theft
Host Alex Thompson interviews cybersecurity expert Dr. Evelyn Reed about how GoldFactory weaponizes biometric data, revealing new threats in digital identity protection.
20 Jul 2026
TX-NFC: Ghost Tap — can your bank catch fraud from a card that never left your pocket?
Send us Fan Mail Contactless payments have become such a routine part of everyday life that we rarely think twice about how they are secured. For decades, every contactless transaction has been built on the assumption that your card needs to be physically present to make the purchase. Now, there is one Chinese-language Fraud-as-a-Service operation that has found a way to break that assumption. First uncovered by Group-IB researchers, TX-NFC relays stolen card data to a fraudster’s devic...
10 Jul 2026
Defenders: The life of a threat researcher
Send us Fan Mail Threat researchers work deep in the digital underground, mapping adversaries, exposing tactics, and turning fragments of intelligence into protection that actively stops attacks. Despite the impact of their work, the reality of what they do remains largely hidden from view. In this episode of Masked Actors, Group-IB’s Gary Ruddell is joined by Anastasia Tikhonova, Global Threat Research Lead at Group-IB and author of the High-Tech Crime Trends report. With over a decade...
30 Jun 2026
Scattered Spider: Could one phone call bring down your whole organization?
Send us Fan Mail Can you recognise every employee in your organisation? Most companies cannot — and attackers know it. A routine IT request comes in from a senior leader locked out of their account. Everything checks out, so access is restored. Except it wasn't them. In that moment, you've handed the keys to Scattered Spider — a group that has spent three years proving that human trust is a more reliable attack surface than any software vulnerability. Group-IB's High-Tech Crime Trends Report ...
23 Jun 2026
Defenders: What does it take to orchestrate international takedowns across borders?
Send us Fan Mail Cybercrime operates at a scale most people never see. A single incident can cost hundreds of millions of pounds, disrupt businesses overnight, or devastate individuals and families. What often follows is a simple question: how do you stop something that moves this fast, across so many borders? The reality is far from straightforward. Building a case against cybercriminals means tracing activity across jurisdictions, piecing together fragments of digital evidence, and turning ...
30 Apr 2026TRANSCRIPT
Team TNT: Could you be unknowingly mining for crypto?
Host Alex Thompson interviews cybersecurity expert Dr. Evelyn Reed about how cybercriminals exploit cryptocurrency for illicit gains and global crime.
30 Mar 2026TRANSCRIPT
Boolka: The evolution of a cybercriminal enterprise
Send us Fan Mail If evolution has taught humanity anything, it’s that adaptation is key to survival. As prey develop camouflage techniques, predators get faster, sturdier, and better at detection. Now this game of cat and mouse is taking over the digital world. All cybergangs are on a cycle of relentless adaptation – but a group that stands out from all the rest is Boolka, innovating near-constantly since it first landed on the cybercriminal scene in 2022. Its primary goal is to steal u...
19 Dec 2025TRANSCRIPT
Brain Cipher: What happens when national infrastructure comes under strike?
Send us a text Indonesia, June 2024 - 210 critical government agencies were crippled in one fell swoop. Immigration services were in disarray; customs officers locked out of critical systems and travellers left stranded in airport and ferry terminals facing delays that would continue for a full week. The culprit? Brain Cipher, a ransomware group barely a week old, which demanded a huge sum of $8M from Indonesia’s National Data Centre, bringing local government services to their knees. The cha...
27 Nov 2025TRANSCRIPT
Ajina: Can you really trust that app?
Send us a text Cyber criminals are masters at exploiting human vulnerability and trust. In Uzbek folklore, there's a creature known for causing chaos, preying on humans, lurking in the dark and changing its face to trick its victims before it pounces. In December 2023, it lent its name to a sophisticated Android malware campaign using the same tactics that emerged in the digital underworld. The banking malware masqueraded as legitimate applications, leaving users confused – like its fo...
28 Oct 2025TRANSCRIPT
MuddyWater & OilRig: The cyber espionage playbook
Send us a text As digital infrastructure becomes the backbone of global economies, cyber espionage has quietly evolved into one of the most powerful tools in modern statecraft. Behind the scenes, nation-backed threat groups like MuddyWater and OilRig operate sophisticated campaigns that blend malware, phishing, and social engineering to infiltrate governments, defence contractors, and critical industries. But these Advanced Persistent Threat groups aren’t motivated by fame or by fortune...
23 Sept 2025TRANSCRIPT
Joystick to Jailbreak: Exploring the Youth Cybercrime Pandemic
Send us a text Forget everything you think you know about hackers. Today’s cybercriminals aren’t lurking in shadowy basements - they’re teenagers mastering cheat codes on Roblox, swapping tips on Discord, and using AI to launch attacks from their bedrooms. Join Group-IB’s Gary Ruddell and Nick Palmer as they sit down with Fergus Hay, CEO and co-founder of The Hacking Games, to explore how cybercrime is becoming more accessible than ever. They dive into the rise of Ransomware-as-a-Service (Raa...
27 Aug 2025
RansomHub: From RaaS Kingpin to Cartel Mystery
When RansomHub, one of the most prolific ransomware groups, vanished overnight back in April, it sent shockwaves through the cybercriminal underworld. With over 600 global attacks and millions extorted, their sudden disappearance left affiliates scrambling and researchers asking: what happened? Join Group-IB’s Gary Ruddell and Nick Palmer as they speak with Pietro Albuquerque, a threat intelligence analyst at Group-IB and a leading expert on RansomHub, to unpack the rise and fall of this rans...
29 Jul 2025
DragonForce: The Cyber Cartel Helping Hackers Hit the High Street
Empty shelves, lost customers, and hundreds of millions of pounds in lost profit are just some of the outcomes that retailers have faced in the wake of recent ransomware attacks. From the Co-operative to M&S, the recent cyber attacks on UK retail giants have dominated headlines and wreaked havoc that’s been felt by customers, staff, and government officials alike. The culprits behind it? A highly organised group of ransomware specialists, codename: DragonForce. Join Group-IB’s...
11 Jun 2025
Lazarus: Is your best IT worker really a North Korean hacker?
Geoff White discusses the Lazarus Group, a North Korean hacking collective, and their increasing cyberattacks on companies, in an interview with hosts Gary Ruddell and Nick Palmer.
13 May 2025
GoldFactory: The cybercriminals who want to steal your face
If a cybercriminal steals your password, you can change it. But what happens if they steal your face? Former soldier turned hacker, Gary Ruddell and financial crime veteran, Nick Palmer, explore the actors behind GoldFactory - a cybercriminal group stealing users' facial recognition data to clean out victims bank accounts. Joined by Craig Jones, who spent five years at Interpol as the director of cybercrime, Gary and Nick explore how masked actors are exploiting AI and Deepfakes for fin...
9 May 2025
Cybercriminals Exposed: Welcome to Masked Actors
Welcome to Masked Actors — a true crime-inspired podcast from Group-IB that brings you face to face with the people orchestrating some of the most sophisticated cyberattacks on the planet. Join hosts Gary Ruddell — former soldier turned hacker and cyber threat expert — and Nick Palmer, a financial crime veteran, for the gripping new series which uncovers the tactics, motivations and real-world impact of the top 10 most prolific cybercriminal organizations of 2025. By understanding who t...
Inside a recent episode
Defenders: Two Front Lines - Fraud From the Case File and the Comments Section
Published 10 Sept 2026 · Transcript excerpt
[…] There is a company called Take Nine. It's a nonprofit and it's basically take nine seconds to kind of get remove yourself from the situation. It's such an amazing like I love I talk about it all the time, but remove yourself from this situation. And sometimes I always say it's actually easier sometimes if you get a buddy. Right. So my mom is my my buddy and my mom, anytime she gets a message, she just doesn't click on it and she just knows to screenshot it and send it to me. Because that gives you obviously more than nine seconds and it gives you a second perspective. Right. So you're not in it by yourself. […]
Pod Engine is an independent podcast discovery and analytics service and is not affiliated with or endorsed by this podcast. Artwork and show content belong to their owners. Full legal notice.
Explore this show Podcast research with Pod Engine