Threat intelligence focusing on Malaysia πŸ‡²πŸ‡Ύ β€” bridging global reporting with local reality. Compiled, tagged, and analyzed for Malaysian defenders, from SOC analysts to CISOs.

Baru di sini? New here?

Head to Start Here β€” a 2-minute guide that routes you to the right section based on your role. Prefer raw data? Jump straight to Feeds & MISP.

200+ Threat entries
MISP-linked, MY-triaged
47+ Threat actors
tracked with MY relevance
80+ Ransomware claims
vs. MY orgs since 2018

What Rectifyq tracks

🎯 Intelligence products

🀝 Community

Everything published maps to our open Intelligence Requirements (PIR) β€” so you always know why an entry exists and who it serves.

The Malaysian landscape at a glance

Ransomware extortion claims vs MY organizations β€” top groups (2018–present)

pie showData 
    "LockBit3" : 21
    "Qilin" : 20
    "The Gentlemen" : 9
    "RansomHub" : 7
    "Direwolf" : 7
    "Akira" : 5
    "Others" : 20

Claims, not confirmations

Figures are based on ransomware group claims or news reporting. Unless the organization confirmed the incident, it remains a claim. Victims are never named on this site.

Most-claimed sectors: Manufacturing Β· Government Β· Engineering Β· Logistics Β· Construction β€” full breakdown in the Ransomware Tracker.

Top techniques observed in MY-relevant intrusions (MISP-MY): T1027 Obfuscated Files Β· T1566 Phishing Β· T1055 Process Injection Β· T1059.001 PowerShell Β· T1190 Exploit Public-Facing App β€” full heatmap in TTPs.

This week in MY cyber πŸ“…

CTF this weekend? Meetup after work? The community calendar has it β€” physical and online, reviewed before publishing.

Subscribe once, never miss an event

Add the Malaysia Cybersecurity Events Calendar to Google or Apple Calendar and every vetted MY cyber event lands in your schedule automatically. Organizing something? Submit it β€” jom turun padang.

How the ecosystem connects

flowchart LR
    RQ(("Rectifyq πŸ‡²πŸ‡Ύ"))

    subgraph Intelligence
        TW["Threat Watch"]
        TA["Actor Profiles"]
        VW["Vulnerability Watch"]
        BW["Breach Watch"]
    end

    subgraph Data["Machine-readable"]
        MISP["MISP-MY"]
        FEEDS["IoC CSV / Feeds"]
    end

    subgraph You["Your stack"]
        SIEM["SIEM / TIP"]
        BRIEF["Board briefings"]
    end

    RQ --> Intelligence
    RQ --> Data
    TW --> MISP
    MISP --> FEEDS
    FEEDS --> SIEM
    BW --> BRIEF
    VW --> SIEM

    click TW "/my-threat-landscape/threats/" _self
    click TA "/my-threat-landscape/threat-actor" _self
    click VW "/my-threat-landscape/vulnerabilities/" _self
    click BW "/my-threat-landscape/breaches/" _self
    click FEEDS "/resources/feeds" _self