<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
    <channel>
      <title>Rectifyq</title>
      <link>https://rectifyq.com</link>
      <description>Last 20 notes on Rectifyq</description>
      <generator>Quartz -- quartz.jzhao.xyz</generator>
      <item>
    <title>2026-04-30 Inside Shadow-Earth-053 A China-Aligned Cyberespionage Campaign Against Government and Defense Sectors in Asia</title>
    <link>https://rectifyq.com/MY-Threat-Landscape/threat-lists/327326e7-354a-45ba-b25e-363984f01010</link>
    <guid>https://rectifyq.com/MY-Threat-Landscape/threat-lists/327326e7-354a-45ba-b25e-363984f01010</guid>
    <description><![CDATA[ &lt;p&gt;📃Title: Inside Shadow-Earth-053: A China-Aligned Cyberespionage Campaign Against Government and Defense Sectors in Asia&lt;br&gt;
📅Date: 2026-04-30&lt;br&gt;
🔗References:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.trendmicro.com/en_us/research/26/d/inside-shadow-earth-053.html&quot; class=&quot;external&quot;&gt;https://www.trendmicro.com/en_us/research/26/d/inside-shadow-earth-053.html&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;🔖Rectifyq Taxonomies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;relevancy: 🔴 Highly Relevant&lt;/li&gt;
&lt;li&gt;category: &lt;a href=&quot;../.././../tags/⚔Threat&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/⚔Threat&quot;&gt;⚔Threat&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;sub-category: &lt;a href=&quot;../.././../tags/campaign-analysis&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/campaign-analysis&quot;&gt;campaign-analysis&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;target: &lt;a href=&quot;../.././../tags/broad-based&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/broad-based&quot;&gt;broad-based&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;MY-relevancy: &lt;a href=&quot;../.././../tags/relevant&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/relevant&quot;&gt;relevant&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;🔖MISP Galaxies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;producer= &lt;a href=&quot;../.././../tags/Trend-Micro&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/Trend-Micro&quot;&gt;Trend-Micro&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;country=“china”&lt;/li&gt;
&lt;li&gt;malpedia=“ShadowPad”&lt;/li&gt;
&lt;li&gt;target-information=“India”&lt;/li&gt;
&lt;li&gt;target-information=“Malaysia”&lt;/li&gt;
&lt;li&gt;target-information=“Myanmar”&lt;/li&gt;
&lt;li&gt;target-information=“Pakistan”&lt;/li&gt;
&lt;li&gt;target-information=“Sri Lanka”&lt;/li&gt;
&lt;li&gt;target-information=“Taiwan”&lt;/li&gt;
&lt;li&gt;target-information=“Thailand”&lt;/li&gt;
&lt;li&gt;malpedia=“iox”&lt;/li&gt;
&lt;li&gt;malpedia=“Vshell”&lt;/li&gt;
&lt;li&gt;malpedia=“Nood RAT”&lt;/li&gt;
&lt;li&gt;mitre-attack-pattern=[]&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;MISP event uuid: &lt;a href=&quot;https://mispmy.rectifyq.com/events/view/327326e7-354a-45ba-b25e-363984f01010&quot; class=&quot;external&quot;&gt;327326e7-354a-45ba-b25e-363984f01010&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2 id=&quot;indicator-of-compromise-iocs&quot;&gt;Indicator of Compromise (IoCs)&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#indicator-of-compromise-iocs&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;pre&gt;&lt;code&gt;type,value,comment
md5, efcb90de13a82c10a34e900ab91942c1, &#039;ShadowPad loader — graphics-hook-filter32.dll&#039;
md5, 48370247d5c3c01474f19e172112710a, &#039;ShadowPad loader — imjp14k.dll&#039;
md5, e5b0fd04b03d92d4dfb8e50b9b9b3068, &#039;ShadowPad loader — imjp14k.dll&#039;
md5, 9daba43a4c2495f596555653c6fe88d2, &#039;ShadowPad loader — imjp14k.dll&#039;
md5, 4b7a47b639a2aca7818d111ee7f23b3e, &#039;ShadowPad loader — uxtheme.dll&#039;
md5, c4144edb268001595700b5f27d7d7422, &#039;ShadowPad loader — MPS.dll&#039;
md5, be328739e97303b2e72fe36feae358d5, &#039;IOX Proxy&#039;
md5, 531da3715b1e4fc9baeaa034888ac419, &#039;EVILCREATEDUMP&#039;
md5, a85459a1ec90a52b5c1f2f5a12bb2d10, &#039;SHADOW-EARTH-053 loader — found by infrastructure pivoting&#039;
md5, 29015d3fa89c75ee576b14849133d6d9, &#039;TosBtKbd.dll Custom Registry Loader&#039;
md5, 2616e7ec2d6c4b86a7fa1f4a762ae918, &#039;RingQ.exe&#039;
md5, 7b2590be24290eb4b51bed2af1744b04, &#039;SHADOW-EARTH-054 loader&#039;
md5, 0933fbd16c7a8b70199f5612e147a22c, &#039;GOST tunnel (gost.exe)&#039;
md5, fc751b0416d4dc320eb175cea5a9e4dd, &#039;Wstunnel (wt.exe)&#039;
sha256, f43748a809680a23272ec684a8cce9af071ad165c3b01acdcd7fe501a0949745, &#039;ShadowPad loader — graphics-hook-filter32.dll No sample in VT\r\nLast check:03/05/2026&#039;
sha1, 2dc1ad07b7529af3ba5c11a58519681909971a81, &#039;ShadowPad loader — graphics-hook-filter32.dll No sample in VT\r\nLast check:03/05/2026&#039;
sha256, 0eda83335334d3c877578326a5843d3e2a3b745834de27eac00b694262e2b1ed, &#039;ShadowPad loader — graphics-hook-filter32.dll No sample in VT\r\nLast check:03/05/2026&#039;
sha1, 3229ba46dd54802093c81e6e2123fd1520faf960, &#039;ShadowPad loader — graphics-hook-filter32.dll No sample in VT\r\nLast check:03/05/2026&#039;
sha256, 0fff684fa209cb79ab1104da3cfbbf4c950078e14e54c2564d130abbd4e464a9, &#039;ShadowPad loader — graphics-hook-filter32.dll No sample in VT\r\nLast check:03/05/2026&#039;
sha1, 128f3ad395f86be6569ef2a957d42902a910de6c, &#039;ShadowPad loader — graphics-hook-filter32.dll No sample in VT\r\nLast check:03/05/2026&#039;
sha256, 4f77b4fcfde7abb7e6d0e36104e433abfed3a9d9938bf7fbe0e9d1a0b2ccf265, &#039;ShadowPad loader — graphics-hook-filter32.dll No sample in VT\r\nLast check:03/05/2026&#039;
sha256, a5477ff2b3d6d475558abf03878dff0cca98c20c17aae35a8ad8e99e03293f89, &#039;ShadowPad loader — graphics-hook-filter32.dll No sample in VT\r\nLast check:03/05/2026&#039;
sha256, 83e9f99a377566cf30df0ad71ca8522613b14d45e3e2eaead4a336509d26bef3, &#039;ShadowPad loader — graphics-hook-filter32.dll No sample in VT\r\nLast check:03/05/2026&#039;
sha1, 9a83466f6c34e588ba3e99d6cbfac0102e173cdd, &#039;ShadowPad loader — graphics-hook-filter32.dll No sample in VT\r\nLast check:03/05/2026&#039;
sha256, 996fb4f7d1b3150490380c4ce9c7c3d60fac33bd6a7c1e3a46487021964cf3bb, &#039;ShadowPad loader — graphics-hook-filter32.dll No sample in VT\r\nLast check:03/05/2026&#039;
sha1, 9244cd99a27a8741a78e0b449cea063fdcfb0090, &#039;ShadowPad loader — graphics-hook-filter32.dll No sample in VT\r\nLast check:03/05/2026&#039;
sha256, 3dffbfcb825a70e477474e88b18679557ef467de37fc26e45ddbe572f520c52a, &#039;ShadowPad loader — graphics-hook-filter32.dll No sample in VT\r\nLast check:03/05/2026&#039;
sha1, 8a5ac2682d70eacff7eb554e242227c82e2baa94, &#039;ShadowPad loader — graphics-hook-filter32.dll No sample in VT\r\nLast check:03/05/2026&#039;
sha256, 2dd93edc8cc64747a7ca94b6827dc4e5b1e385d493ed4450272dd1dfc52a6255, &#039;ShadowPad loader — imjp14k.dll No sample in VT\r\nLast check:03/05/2026&#039;
sha1, 579bc9a640ac939b1f75eda852815f063cebd332, &#039;ShadowPad loader — imjp14k.dll No sample in VT\r\nLast check:03/05/2026&#039;
sha256, 5eb2122c4c645543966b07b94faccb5b4697561163382f21fb3b793b0d5cc9fe, &#039;ShadowPad loader — imjp14k.dll No sample in VT\r\nLast check:03/05/2026&#039;
sha1, ec38a56f9368eac67106a4ad61538e12053f03d1, &#039;ShadowPad loader — imjp14k.dll No sample in VT\r\nLast check:03/05/2026&#039;
sha256, eff699456ed4c5938d53afdb8df0836d7cb953ed933ed1a2899ec43f6f9e540b, &#039;ShadowPad loader — imjp14k.dll No sample in VT\r\nLast check:03/05/2026&#039;
sha256, 75d0d5080afd091114818d082babc418ccb43d545d9fda1fb715af6c129b6e51, &#039;ShadowPad loader — uxtheme.dll No sample in VT\r\nLast check:03/05/2026&#039;
sha1, 35cc0b684b0906aed9d672a1a8635510fe91aa67, &#039;ShadowPad loader — uxtheme.dll No sample in VT\r\nLast check:03/05/2026&#039;
sha256, 3f6382418d0137f6ecbef23bfd981938bb86a935b27203f5b053e3710e835f97, &#039;SHADOW-EARTH-053 — Mdync.exe No sample in VT\r\nLast check:03/05/2026&#039;
sha256, 26f4c7f37448911310adf20e6e74aac60e92b97591f4ac9e5e21cc503be8da16, &#039;Possible RDP Launcher No sample in VT\r\nLast check:03/05/2026&#039;
sha256, 8df8282da75ebe6cf1a535739991e3f298f903974a05966503d7fd2919ecea4e, &#039;Privileged Process Launcher No sample in VT\r\nLast check:03/05/2026&#039;
sha256, 03a89ea5a8604e8bc09a4249211e20404a2c7047adda65a57deeb46abb1fb116, &#039;data.aspx webshell No sample in VT\r\nLast check:03/05/2026&#039;
sha256, d083b6d82765faffe738ebd0678c8eb01c1f1fac8d3c51ffdfe40e34da3ce902, &#039;ExchangeExport.exe No sample in VT\r\nLast check:03/05/2026&#039;
sha256, 0c8c562ed7343d28c76d93a88bd0534440d0e71292ebcee66314d6d5c2f34403, &#039;Newdcsync.exe No sample in VT\r\nLast check:03/05/2026&#039;
sha256, 55e929971a7975c7f9dfa4d677d5ec357af23a4ca208ef8f920804743e9011cd, &#039;SHADOW-EARTH-054 malware No sample in VT\r\nLast check:03/05/2026&#039;
sha1, b8d586d376b342b08b3dd8a77c788480e025ad12, &#039;SHADOW-EARTH-054 malware No sample in VT\r\nLast check:03/05/2026&#039;
sha256, 165cc3a9a40e04c469e5c818943920f38dc48db2c2365f1a71bb52c9582f0ea9, &#039;DomainMachines.exe — Custom discovery tool No sample in VT\r\nLast check:03/05/2026&#039;
sha256, 1a5da90175ff7b55ddafcdb816adf574b92a112604019b219d82adab820fb3a2, &#039;IOX (code.exe) No sample in VT\r\nLast check:03/05/2026&#039;
sha256, 4173c218efe31a6b36df714cf4e1073696f3acbe7edd1b7fcba01e4a2d923a27, &#039;Unknown proxy (code.exe / tunnel-core.exe) No sample in VT\r\nLast check:03/05/2026&#039;
hostname, time.microsofttrends.com, &#039;ShadowPad C&amp;#x26;C — TrendAI telemetry&#039;
hostname, erp.kaspersky.icu, &#039;ShadowPad C&amp;#x26;C — TrendAI telemetry&#039;
hostname, dns.dnsmap.icu, &#039;Infrastructure&#039;
hostname, cert.kaspersky.icu, &#039;Infrastructure&#039;
hostname, news.kaspersky.icu, &#039;Infrastructure&#039;
hostname, ns1.kaspersky.icu, &#039;Infrastructure&#039;
hostname, ns2.kaspersky.icu, &#039;Infrastructure&#039;
hostname, www.kaspersky.icu, &#039;Infrastructure&#039;
hostname, dns.dnserver.life, &#039;Infrastructure&#039;
hostname, nslookup.dnserver.life, &#039;Infrastructure&#039;
hostname, router.dnserver.life, &#039;Infrastructure&#039;
hostname, ww12.dnserver.life, &#039;Infrastructure&#039;
hostname, ns1.group-ib.icu, &#039;Infrastructure&#039;
hostname, ns2.group-ib.icu, &#039;Infrastructure&#039;
hostname, www.group-ib.icu, &#039;Infrastructure&#039;
hostname, check.dnsmaps.com, &#039;Infrastructure&#039;
hostname, update.kaspersky.icu, &#039;Infrastructure Hunting — Malware Hosting&#039;
hostname, check.office365-update.com, &#039;NOODLERAT C&amp;#x26;C&#039;
domain, zimbra-beta.info, &#039;SHADOW-EARTH-054 C&amp;#x26;C&#039;
domain, zimbra.life, &#039;SHADOW-EARTH-054 C&amp;#x26;C&#039;
domain, microsi0ft.com, &#039;SHADOW-EARTH-054 C&amp;#x26;C&#039;
ip-dst, 141.164.46.77, &#039;SHADOW-EARTH-053 C&amp;#x26;C&#039;
ip-dst, 96.9.125.227, &#039;SHADOW-EARTH-053 C&amp;#x26;C&#039;
ip-dst, 194.38.11.3, &#039;SHADOW-EARTH-053 Malware Hosting — TrendAI telemetry&#039;
ip-dst, 209.141.40.254, &#039;SHADOW-EARTH-054 VShell C&amp;#x26;C&#039;
ip-dst, 45.61.62.172, &#039;SHADOW-EARTH-054 IOX Proxy&#039;
url, http://209.141.40.254:8443/update, &#039;SHADOW-EARTH-054 VShell C&amp;#x26;C&#039;

&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Full IOCs available in Rectifyq’s &lt;a href=&quot;https://mispmy.rectifyq.com/events/view/327326e7-354a-45ba-b25e-363984f01010&quot; class=&quot;external&quot;&gt;MISP&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt; ]]></description>
    <pubDate>Thu, 30 Apr 2026 00:00:00 GMT</pubDate>
  </item><item>
    <title>2026-04-29 Phoenix Rising Exposing the PhaaS Kit Behind Global Mass Phishing Campaigns</title>
    <link>https://rectifyq.com/MY-Threat-Landscape/threat-lists/5109a940-ef8e-4cf9-a5c8-fdfc684aa6ae</link>
    <guid>https://rectifyq.com/MY-Threat-Landscape/threat-lists/5109a940-ef8e-4cf9-a5c8-fdfc684aa6ae</guid>
    <description><![CDATA[ &lt;p&gt;📃Title: Phoenix Rising: Exposing the PhaaS Kit Behind Global Mass Phishing Campaigns&lt;br&gt;
📅Date: 2026-04-29&lt;br&gt;
🔗References:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.group-ib.com/blog/phoenix-phaas-kit-smishing&quot; class=&quot;external&quot;&gt;https://www.group-ib.com/blog/phoenix-phaas-kit-smishing&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;🔖Rectifyq Taxonomies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;relevancy: 🔴 Highly Relevant&lt;/li&gt;
&lt;li&gt;category: &lt;a href=&quot;../.././../tags/⚔Threat&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/⚔Threat&quot;&gt;⚔Threat&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;sub-category: &lt;a href=&quot;../.././../tags/campaign-analysis&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/campaign-analysis&quot;&gt;campaign-analysis&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;target: &lt;a href=&quot;../.././../tags/broad-based&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/broad-based&quot;&gt;broad-based&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;MY-relevancy: &lt;a href=&quot;../.././../tags/relevant&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/relevant&quot;&gt;relevant&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;🔖MISP Galaxies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;producer= &lt;a href=&quot;../.././../tags/Group-IB&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/Group-IB&quot;&gt;Group-IB&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;financial-fraud=“Phishing”&lt;/li&gt;
&lt;li&gt;financial-fraud=“Smishing”&lt;/li&gt;
&lt;li&gt;target-information=“Argentina”&lt;/li&gt;
&lt;li&gt;target-information=“Australia”&lt;/li&gt;
&lt;li&gt;target-information=“Belgium”&lt;/li&gt;
&lt;li&gt;target-information=“Chile”&lt;/li&gt;
&lt;li&gt;target-information=“Costa Rica”&lt;/li&gt;
&lt;li&gt;target-information=“Hong Kong”&lt;/li&gt;
&lt;li&gt;target-information=“India”&lt;/li&gt;
&lt;li&gt;target-information=“Indonesia”&lt;/li&gt;
&lt;li&gt;target-information=“Japan”&lt;/li&gt;
&lt;li&gt;target-information=“Malaysia”&lt;/li&gt;
&lt;li&gt;target-information=“Mexico”&lt;/li&gt;
&lt;li&gt;target-information=“Philippines”&lt;/li&gt;
&lt;li&gt;target-information=“Singapore”&lt;/li&gt;
&lt;li&gt;target-information=“Spain”&lt;/li&gt;
&lt;li&gt;target-information=“Taiwan”&lt;/li&gt;
&lt;li&gt;target-information=“United Kingdom”&lt;/li&gt;
&lt;li&gt;target-information=“United States”&lt;/li&gt;
&lt;li&gt;target-information=“Vietnam”&lt;/li&gt;
&lt;li&gt;sector=“Finance”&lt;/li&gt;
&lt;li&gt;sector=“Logistic”&lt;/li&gt;
&lt;li&gt;sector=“Telecoms”&lt;/li&gt;
&lt;li&gt;mitre-attack-pattern=[‘T1204.001’, ‘T1566.002’, ‘T1539’]&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;MISP event uuid: &lt;a href=&quot;https://mispmy.rectifyq.com/events/view/5109a940-ef8e-4cf9-a5c8-fdfc684aa6ae&quot; class=&quot;external&quot;&gt;5109a940-ef8e-4cf9-a5c8-fdfc684aa6ae&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2 id=&quot;indicator-of-compromise-iocs&quot;&gt;Indicator of Compromise (IoCs)&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#indicator-of-compromise-iocs&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;pre&gt;&lt;code&gt;type,value,comment
ip-dst, 23.95.166.127, &#039;&#039;
ip-dst, 38.162.114.0, &#039;&#039;
ip-dst, 43.133.0.0, &#039;&#039;
ip-dst, 43.134.0.0, &#039;&#039;
ip-dst, 43.134.12.32, &#039;&#039;
ip-dst, 43.134.239.46, &#039;&#039;
ip-dst, 43.153.0.0, &#039;&#039;
ip-dst, 43.154.31.214, &#039;&#039;
ip-dst, 43.156.61.150, &#039;&#039;
ip-dst, 43.160.192.0, &#039;&#039;
ip-dst, 43.162.0.0, &#039;&#039;
ip-dst, 43.163.100.238, &#039;&#039;
ip-dst, 45.203.220.0, &#039;&#039;
ip-dst, 47.80.0.0, &#039;&#039;
ip-dst, 47.80.64.106, &#039;&#039;
ip-dst, 47.80.70.114, &#039;&#039;
ip-dst, 47.80.79.203, &#039;&#039;
ip-dst, 8.212.128.102, &#039;&#039;
ip-dst, 8.220.130.133, &#039;&#039;
ip-dst, 8.220.190.2, &#039;&#039;
ip-dst, 101.32.186.29, &#039;&#039;
ip-dst, 154.91.90.0, &#039;&#039;
ip-dst, 156.245.145.174, &#039;&#039;
ip-dst, 156.245.146.210, &#039;&#039;

&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Full IOCs available in Rectifyq’s &lt;a href=&quot;https://mispmy.rectifyq.com/events/view/5109a940-ef8e-4cf9-a5c8-fdfc684aa6ae&quot; class=&quot;external&quot;&gt;MISP&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt; ]]></description>
    <pubDate>Wed, 29 Apr 2026 00:00:00 GMT</pubDate>
  </item><item>
    <title>2026-04-21 GhostCargo, a 5-years campaign</title>
    <link>https://rectifyq.com/MY-Threat-Landscape/threat-lists/9c16b2b8-dd25-4533-958e-97d8d1c92cca</link>
    <guid>https://rectifyq.com/MY-Threat-Landscape/threat-lists/9c16b2b8-dd25-4533-958e-97d8d1c92cca</guid>
    <description><![CDATA[ &lt;p&gt;📃Title: GhostCargo, a 5-years campaign&lt;br&gt;
📅Date: 2026-04-21&lt;br&gt;
🔗References:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.syntx.com.my/blog/ghostcargo-a-5-years-campaign&quot; class=&quot;external&quot;&gt;https://www.syntx.com.my/blog/ghostcargo-a-5-years-campaign&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;🔖Rectifyq Taxonomies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;relevancy: 🔴 Highly Relevant&lt;/li&gt;
&lt;li&gt;category: &lt;a href=&quot;../.././../tags/⚔Threat&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/⚔Threat&quot;&gt;⚔Threat&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;sub-category: &lt;a href=&quot;../.././../tags/intrusion-analysis&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/intrusion-analysis&quot;&gt;intrusion-analysis&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;target: &lt;a href=&quot;../.././../tags/targeted&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/targeted&quot;&gt;targeted&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;MY-relevancy: &lt;a href=&quot;../.././../tags/relevant&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/relevant&quot;&gt;relevant&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;🔖MISP Galaxies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;financial-fraud=“Phishing”&lt;/li&gt;
&lt;li&gt;financial-fraud=“Fake Website”&lt;/li&gt;
&lt;li&gt;financial-fraud=“Distraction”&lt;/li&gt;
&lt;li&gt;financial-fraud=“Scam”&lt;/li&gt;
&lt;li&gt;financial-fraud=“Merchant Fraud”&lt;/li&gt;
&lt;li&gt;financial-fraud=“Compromised Personally Identifiable Information (PII)”&lt;/li&gt;
&lt;li&gt;target-information=“Malaysia”&lt;/li&gt;
&lt;li&gt;country=“indonesia”&lt;/li&gt;
&lt;li&gt;country=“venezuela”&lt;/li&gt;
&lt;li&gt;country=“australia”&lt;/li&gt;
&lt;li&gt;online-service=“b0c71d51-34fd-47b5-9eb4-dd406ffc607f”&lt;/li&gt;
&lt;li&gt;online-service=“01031d3f-c9c9-4288-bb58-234c38e4246e”&lt;/li&gt;
&lt;li&gt;mitre-attack-pattern=[‘T1657’, ‘T1056’, ‘T1204.001’, ‘T1036’, ‘T1593’, ‘T1566.002’]&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;MISP event uuid: &lt;a href=&quot;https://mispmy.rectifyq.com/events/view/9c16b2b8-dd25-4533-958e-97d8d1c92cca&quot; class=&quot;external&quot;&gt;9c16b2b8-dd25-4533-958e-97d8d1c92cca&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2 id=&quot;indicator-of-compromise-iocs&quot;&gt;Indicator of Compromise (IoCs)&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#indicator-of-compromise-iocs&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;pre&gt;&lt;code&gt;type,value,comment
hostname, bnk.ing-boa.pro, &#039;Active fake Barclays portal&#039;
domain, ing-boa.pro, &#039;Parent domain; wildcard cert *.ing-boa[.]pro issued Feb 2026&#039;
domain, jetexpressdeliveries.com, &#039;Fake logistics front (Drupal + transpix theme)&#039;
hostname, barcl.ays-uk.com, &#039;Predecessor Barclays portal (Jun 2024 to May 2025, now NXDOMAIN)&#039;
domain, ays-uk.com, &#039;Parent of predecessor; same Hostinger IP&#039;
hostname, ban.king-en.com, &#039;Predecessor bank portal (Feb 2023, now NXDOMAIN)&#039;
domain, king-en.com, &#039;Parent domain; wildcard cert from Dec 2020&#039;
domain, topexpresdelivery.com, &#039;Predecessor delivery domain (Sep 2020, HTTrack source)&#039;
domain, doorcargoexpress.com, &#039;Predecessor tracking page template (Feb 2023)&#039;
domain, ermontexpressdelivery.com, &#039;Same-Actor Domain - Fake delivery; same NS, IP, registrar&#039;
domain, fastlinkquickdelivery.com, &#039;Same-Actor Domain - Fake delivery; same NS, IP, registrar&#039;
domain, firstcredituni.pro, &#039;Same-Actor Domain - Fake bank; confirmed Bankpro default deployment, .pro TLD match&#039;
domain, suntrustcomunityfcu.com, &#039;Fake credit union&#039;
domain, cresttcredit.com, &#039;Fake credit institution&#039;
domain, trusteqbank.com, &#039;Fake bank&#039;
domain, metropolis-credit.com, &#039;Fake credit&#039;
domain, finestostandard.com, &#039;Fake financial institution&#039;
domain, digitaltradechainpro.com, &#039;Fake trading platform&#039;
domain, expert-traders.net, &#039;Fake trading&#039;
domain, coinbaseminingfarm.com, &#039;Coinbase impersonation / crypto scam&#039;
domain, greenfund.live, &#039;Fake charity / investment&#039;
domain, futurezioncharity.org, &#039;Fake charity&#039;
domain, daltevintransact.online, &#039;Fake transaction service&#039;
domain, zeltextransact.click, &#039;Fake transaction service&#039;
domain, hiltonacessglobal.com, &#039;Fake Hilton access / global services&#039;
domain, zenixtransit.online, &#039;Fake transit / logistics&#039;
domain, royalgatesschools.com, &#039;Fake school with finance admin portal&#039;
domain, credixrise.com, &#039;Fake banking (Cloudflare NS, same IP)&#039;
ip-dst, 198.251.89.82, &#039;Primary hosting IP (FranTech AS53667, Cheyenne WY)&#039;
ip-dst, 91.108.101.78, &#039;barcl.ays-uk[.]com hosting IP (Hostinger, Paris)&#039;
ip-dst, 46.202.172.167, &#039;jetexpressdeliveries[.]com hosting IP (Hostinger)&#039;
hostname, ns115.my-control-panel.com, &#039;Hosted on same IP as scam domains&#039;
hostname, ns116.my-control-panel.com, &#039;Hosted on same IP as scam domains&#039;
domain, zentroid.com, &#039;unrelated sites&#039;
domain, ultraviewvault.com, &#039;unrelated sites&#039;
email-src, admin@ing-boa.pro, &#039;Operator contact&#039;
email-src, support@indigenousservice.com, &#039;Contact email on firstcredituni[.]pro&#039;
email-src, support@dirtyscripts.shop, &#039;Bankpro kit default admin login&#039;

&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Full IOCs available in Rectifyq’s &lt;a href=&quot;https://mispmy.rectifyq.com/events/view/9c16b2b8-dd25-4533-958e-97d8d1c92cca&quot; class=&quot;external&quot;&gt;MISP&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt; ]]></description>
    <pubDate>Tue, 21 Apr 2026 00:00:00 GMT</pubDate>
  </item><item>
    <title>2026-04-08 A new Mac stealer targeting $10K+ crypto wallets</title>
    <link>https://rectifyq.com/MY-Threat-Landscape/threat-lists/c4af9327-6041-4a3b-99f2-33c7af75c9ad</link>
    <guid>https://rectifyq.com/MY-Threat-Landscape/threat-lists/c4af9327-6041-4a3b-99f2-33c7af75c9ad</guid>
    <description><![CDATA[ &lt;p&gt;📃Title: A new Mac stealer targeting $10K+ crypto wallets&lt;br&gt;
📅Date: 2026-04-08&lt;br&gt;
🔗References:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://moonlock.com/notorious-hacker-returns-notnullosx-stealer&quot; class=&quot;external&quot;&gt;https://moonlock.com/notorious-hacker-returns-notnullosx-stealer&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;blockquote class=&quot;callout abstract&quot; data-callout=&quot;abstract&quot;&gt;
&lt;div class=&quot;callout-title&quot;&gt;
                  &lt;div class=&quot;callout-icon&quot;&gt;&lt;/div&gt;
                  &lt;div class=&quot;callout-title-inner&quot;&gt;&lt;p&gt; &lt;strong&gt;Description&lt;/strong&gt;&lt;/p&gt;&lt;/div&gt;
                  
                &lt;/div&gt;
&lt;div class=&quot;callout-content&quot;&gt;
&lt;p&gt;A sophisticated macOS stealer called notnullOSX emerged in March 2026, developed by threat actor alh1mik (formerly 0xFFF) who returned after a 2023 exit from underground forums. This Go-written modular stealer exclusively targets macOS users with cryptocurrency holdings exceeding $10,000. Distribution occurs through ClickFix social engineering and malicious DMG files disguised as legitimate applications like WallSpace. The malware employs a modular architecture with specialized components to exfiltrate iMessage history, Apple Notes, browser credentials, Safari cookies, crypto wallet files, SSH keys, and cloud provider credentials. By social-engineering victims into granting Full Disk Access, notnullOSX bypasses macOS TCC protections without triggering permission dialogs. The stealer maintains persistent WebSocket connections to Firebase infrastructure, functioning as both an infostealer and backdoor with remote module update capabilities.&lt;/p&gt;
&lt;/div&gt;
&lt;/blockquote&gt;
&lt;p&gt;🔖Rectifyq Taxonomies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;relevancy: 🔴 Highly Relevant&lt;/li&gt;
&lt;li&gt;category: &lt;a href=&quot;../.././../tags/⚔Threat&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/⚔Threat&quot;&gt;⚔Threat&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;sub-category: &lt;a href=&quot;../.././../tags/campaign-analysis&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/campaign-analysis&quot;&gt;campaign-analysis&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;topic: &lt;a href=&quot;../.././../tags/crypto-related&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/crypto-related&quot;&gt;crypto-related&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;target: &lt;a href=&quot;../.././../tags/broad-based&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/broad-based&quot;&gt;broad-based&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;MY-relevancy: &lt;a href=&quot;../.././../tags/relevant&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/relevant&quot;&gt;relevant&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;🔖MISP Galaxies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;target-information=“Spain”&lt;/li&gt;
&lt;li&gt;target-information=“Taiwan”&lt;/li&gt;
&lt;li&gt;country=“malaysia”&lt;/li&gt;
&lt;li&gt;mitre-attack-pattern=[‘T1056.001’, ‘T1539’, ‘T1036.005’, ‘T1204.002’, ‘T1566.002’, ‘T1119’, ‘T1005’, ‘T1140’, ‘T1555.003’, ‘T1552.004’, ‘T1087’, ‘T1083’, ‘T1552.001’, ‘T1041’, ‘T1059.004’, ‘T1562.001’, ‘T1573.002’, ‘T1543.001’, ‘T1071.001’, ‘T1564.001’]&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;MISP event uuid: &lt;a href=&quot;https://mispmy.rectifyq.com/events/view/c4af9327-6041-4a3b-99f2-33c7af75c9ad&quot; class=&quot;external&quot;&gt;c4af9327-6041-4a3b-99f2-33c7af75c9ad&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2 id=&quot;indicator-of-compromise-iocs&quot;&gt;Indicator of Compromise (IoCs)&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#indicator-of-compromise-iocs&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;pre&gt;&lt;code&gt;type,value,comment
md5, c4c249ee87fbda08834e5883f8626db1, &#039;&#039;
md5, a1f06c2c83835259998f2d9d518ee2f6, &#039;&#039;
md5, ddf5c959ef9d990152d39c90b5efbfde, &#039;&#039;
md5, 85870d9889492e3df9fbec630bbb5fde, &#039;&#039;
md5, 48ac3d7ed39152844b8b3112563cfcf7, &#039;&#039;
domain, coockie.pro, &#039;&#039;
ip-dst, 83.217.209.88, &#039;&#039;
sha256, 4584d02b5193799453766857dba97021f966b9cbf6033d7dd3a33d61eb975a6c, &#039;No sample in VT\r\nLast check:20/04/2026&#039;
sha256, 47373950e1d23c066de0ed2d511b4b7eea56ec22d7b501db265995fec51dbb44, &#039;No sample in VT\r\nLast check:20/04/2026&#039;
sha256, 82cb3a22c90aee6cfc2f7e7f72e921e21226492c1d424d2b754b9cd763ab0b20, &#039;No sample in VT\r\nLast check:20/04/2026&#039;
sha256, b73adc5dc04159241e4a89cbc82eaa381f406080f3aaaa1f27d145900dd54267, &#039;No sample in VT\r\nLast check:20/04/2026&#039;
ip-dst, 111.90.149.111, &#039;&#039;
url, http://wallpapermacos.com/download/, &#039;&#039;
domain, wallpapermacos.com, &#039;&#039;
domain, wallspaceapp.com, &#039;&#039;
hostname, mactest-6b2ab-default-rtdb.firebaseio.com, &#039;&#039;
hostname, cdn.filestackcontent.com, &#039;&#039;
url, https://www.youtube.com/watch?v=nbH5KJGYBHk, &#039;&#039;
url, https://www.youtube.com/@wallspacemacos, &#039;&#039;
url, http://111.90.149.111:8080/installer, &#039;bash installer script location at Shinjiru IP&#039;

&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Full IOCs available in Rectifyq’s &lt;a href=&quot;https://mispmy.rectifyq.com/events/view/c4af9327-6041-4a3b-99f2-33c7af75c9ad&quot; class=&quot;external&quot;&gt;MISP&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt; ]]></description>
    <pubDate>Wed, 08 Apr 2026 00:00:00 GMT</pubDate>
  </item><item>
    <title>Phish Hunt MY 2026</title>
    <link>https://rectifyq.com/MY-Threat-Landscape/phishhuntmy</link>
    <guid>https://rectifyq.com/MY-Threat-Landscape/phishhuntmy</guid>
    <description><![CDATA[ &lt;h2 id=&quot;background&quot;&gt;Background&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#background&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Phishing scams—like Telegram takeovers, fake APK wedding invites, and Bantuan Kerajaan fakesite—have been around for ages. Most IT pros and cybersecurity experts tend to ignore them, thinking they’re “uninteresting” or wondering how anyone could still fall for them. But the fact that these scams are still happening means they work. Even if they don’t catch everyone, they only need to hit the right victim for the financial impact to be devastating.&lt;/p&gt;
&lt;p&gt;A few things triggered me to organize this challenge. One was an article by Foxy about recent phishing campaigns, which reminded me of my own previous writing. Then, a “threat actor” actually had the nerve to post a phishing link right in the OWASP Malaysia WhatsApp group!😂 When KDJebat called for an advisory, it gave me an idea: why not create a challenge to push pros and students to actually analyze these campaigns?&lt;/p&gt;
&lt;p&gt;It’s a win-win. I get to learn from their findings, and they get to build their portfolios and potentially win prizes.&lt;/p&gt;
&lt;p&gt;So, a big shout out to Foxy and KDJebat for the inspiration! 🙌&lt;/p&gt;
&lt;h2 id=&quot;challenge-details&quot;&gt;Challenge Details&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#challenge-details&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;With the festive season approaching, scams impersonating local organizations, governments, and local e-wallets are on the rise. We’re looking for Phish Hunters and analysts to help map out these campaigns, warn the community, and get them taken down.&lt;/p&gt;
&lt;p&gt;🔍 How to Participate&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Identify&lt;/strong&gt;: Find an active phishing link or campaign (SMS, Email, Social Media) specifically targeting Malaysians.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Analyze&lt;/strong&gt;: Break down the infrastructure and TTP used by Threat Actor. Who is the registrar? Where is it hosted? Can you find the phishing kit etc? (Always use a sandbox/VM).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Report &amp;#x26; Post&lt;/strong&gt;: File a report with Google Safe Browsing or MyCERT (Cyber999) or any relevant parties. Then, share your findings on LinkedIn, X, Facebook, or your blog to educate others.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Submit&lt;/strong&gt;: Drop your analysis and post link in our entry form: [&lt;a href=&quot;https://forms.gle/ei6EqfBFsbtzdEJU9&quot; class=&quot;external&quot;&gt;https://forms.gle/ei6EqfBFsbtzdEJU9&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;] before 12 midnight of 15th March 2026
🏆 The Prizes (Touch ‘n Go e-Wallet Credit: Each category will win RM100)&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;We’re awarding two distinct types of hunters:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;The Apex Hunter (Technical Prize)&lt;/strong&gt;: For the most thorough technical breakdown. We’re looking for high-quality analysis—TTPs, indicators of compromise (IOCs), kit discovery, evidence of reporting and so on. Technical evaluation will be done on 12 noon of 16th March 2026; if you submitted your analysis but have some minor adjustment, please do so before this date.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;The Community Advocate (Engagement Prize)&lt;/strong&gt;: For the Rectifyq’s Linkedin repost (once you submitted your entry, we will repost it in our page) that gets the most Likes &amp;#x26; Shares. This is about making the warning go viral to prevent others from falling victim.
Counting date fort his prize will be on 12 noon of 18th March 2026. Do share with everyone your specific Rectifyq’s Linkedin repost for everyone to like and share.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Rule: To keep the rewards distributed, one participant cannot win both. If the top technical entry also has the highest engagement, the engagement prize will go to the next runner-up and/or student winner will be prioritized for the community advocate category.&lt;/p&gt;
&lt;h2 id=&quot;results-for-apex-hunter&quot;&gt;Results for Apex Hunter&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#results-for-apex-hunter&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;h3 id=&quot;2-champions---mohd-fazri--ahmad-nazif&quot;&gt;2 champions - Mohd Fazri &amp;#x26; Ahmad Nazif&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#2-champions---mohd-fazri--ahmad-nazif&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h3&gt;
&lt;blockquote class=&quot;callout abstract&quot; data-callout=&quot;abstract&quot;&gt;
&lt;div class=&quot;callout-title&quot;&gt;
                  &lt;div class=&quot;callout-icon&quot;&gt;&lt;/div&gt;
                  &lt;div class=&quot;callout-title-inner&quot;&gt;&lt;p&gt; &lt;strong&gt;Updates&lt;/strong&gt;&lt;/p&gt;&lt;/div&gt;
                  
                &lt;/div&gt;
&lt;div class=&quot;callout-content&quot;&gt;
&lt;p&gt;After another round of review and recalculation, the previously announced winner lost 1 point which resulted to a draw between Mohd Fazri &amp;#x26; Ahmad Nazif. Therefore, decision has been made to announce both as champion for this challenge with the accumulating of same score points. So, both won the duit raya!&lt;/p&gt;
&lt;/div&gt;
&lt;/blockquote&gt;
&lt;h3 id=&quot;below-are-the-top-5&quot;&gt;Below are the top 5:&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#below-are-the-top-5&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h3&gt;















































&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Article link&lt;/th&gt;&lt;th&gt;Category&lt;/th&gt;&lt;th&gt;Total Points&lt;/th&gt;&lt;th&gt;Extra points given&lt;/th&gt;&lt;th&gt;Room for improvement&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;a href=&quot;https://ayiezola.github.io/2026-03-09-Phishing-Page-Semakan-Tunai-Rahmah/&quot; class=&quot;external&quot;&gt;ayiezola&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Working Professional&lt;/td&gt;&lt;td&gt;26&lt;/td&gt;&lt;td&gt;Infection chain using AI/clean diagram, nuclei template, comparative analysis, sample of exfiltrated data&lt;/td&gt;&lt;td&gt;No Recommendation included, TTPs listed not using known framework such as MITRE ATT&amp;#x26;CK&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href=&quot;https://www.notion.so/How-Scammers-Stole-Telegram-Accounts-During-Ramadhan-2026-3211ea45347c80f19a61cbb0f570fc64&quot; class=&quot;external&quot;&gt;nazif&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Working Professional&lt;/td&gt;&lt;td&gt;26&lt;/td&gt;&lt;td&gt;Included Impact assessment and usage of PCAP analysis&lt;/td&gt;&lt;td&gt;No infection chain diagram included &amp;#x26; report format to be more concise and succinct&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href=&quot;https://171k.my/2026/03/10/tngmadaniphishing/&quot; class=&quot;external&quot;&gt;171k&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Student&lt;/td&gt;&lt;td&gt;25&lt;/td&gt;&lt;td&gt;Included TA assessment and TA’s opsec fails&lt;/td&gt;&lt;td&gt;No Action taken (e.g. report to google safe browsing) included, TTPs listed not using known framework such as MITRE ATT&amp;#x26;CK&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href=&quot;https://myos-esc.gitbook.io/myos-esc./blogs/phishing-campaign-analysis-laptop-percuma-bantuan-e-wallet-scam&quot; class=&quot;external&quot;&gt;Myo&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Student&lt;/td&gt;&lt;td&gt;23&lt;/td&gt;&lt;td&gt;None&lt;/td&gt;&lt;td&gt;Action taken (e.g. report to google safe browsing) can be beyond the two listed in the google form&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href=&quot;https://remarkable-xenon-ff5.notion.site/TNG-eWallet-Quishing-Campaign-31ea6f58415f80cc8e2dd5cee0c56826&quot; class=&quot;external&quot;&gt;Alif &amp;#x26; Faez&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Student&lt;/td&gt;&lt;td&gt;22&lt;/td&gt;&lt;td&gt;Included Chain of Code Reuse&lt;/td&gt;&lt;td&gt;TTPs listed not using known framework such as MITRE ATT&amp;#x26;CK&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
&lt;h3 id=&quot;remaining-6-listed-in-random-and-no-particular-order&quot;&gt;Remaining 6 (listed in random and no particular order)&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#remaining-6-listed-in-random-and-no-particular-order&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h3&gt;















































&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Article link&lt;/th&gt;&lt;th&gt;Category&lt;/th&gt;&lt;th&gt;Extra points given&lt;/th&gt;&lt;th&gt;Room for improvement&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;a href=&quot;https://badrulmunir.com/posts/fake-ewallet-my/&quot; class=&quot;external&quot;&gt;n3r&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Working Professional&lt;/td&gt;&lt;td&gt;OTP Form &amp;#x26; Anti analysis&lt;/td&gt;&lt;td&gt;To include executive summary, to include action taken&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href=&quot;https://www.linkedin.com/posts/khairul-zuhaili-4abb2435a_initial-discovery-a-suspicious-activity-7438077834687881216-5pHw&quot; class=&quot;external&quot;&gt;khairul-zuhaili&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Student&lt;/td&gt;&lt;td&gt;Telegram bot screenshot with victim data&lt;/td&gt;&lt;td&gt;To include executive summary, IoCs and action taken&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href=&quot;https://medium.com/@work.akmaltaufik/hunting-a-touch-n-go-duit-raya-phishing-campaign-targeting-malaysians-dedad86d39b1&quot; class=&quot;external&quot;&gt;akmaltaufik&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Student&lt;/td&gt;&lt;td&gt;Usage of crt.sh for pivoting&lt;/td&gt;&lt;td&gt;To include executive summary, TTPs using known framework and action taken &amp;#x26; report format to be more concise and succinct&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href=&quot;https://www.linkedin.com/posts/syazwanisubri_phishhuntmy-phishhuntmy-quishing-activity-7438584878696325120-YoYN&quot; class=&quot;external&quot;&gt;syazwanisubri&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Working Professional&lt;/td&gt;&lt;td&gt;Usage of VT collection&lt;/td&gt;&lt;td&gt;To include infection diagram/attack diagram and screenshots/proof of reporting to be included directly in the article (audience may missed to check in the evidence folder you’ve created)&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href=&quot;https://shrouded-brake-a7f.notion.site/Bantuan-Laptop-eMadani-Phishing-Analysis-320002229ba780278300f55f5b06adb1&quot; class=&quot;external&quot;&gt;matpwnguin&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Working Professional&lt;/td&gt;&lt;td&gt;Included TA assessment and security misconfig&lt;/td&gt;&lt;td&gt;Executive summary is a bit too long - can be more concise, to include action taken&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href=&quot;https://www.linkedin.com/posts/amirulhmd_phishing-alert-think-before-you-scan-ugcPost-7438172372588924928-zlYa&quot; class=&quot;external&quot;&gt;amirulhmd&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Student&lt;/td&gt;&lt;td&gt;Asked questions to stakeholder (Rectifyq) - which is good to understand stakeholder’s requirement, reporting (action taken) beyond suggested (Cloudflare abuse)&lt;/td&gt;&lt;td&gt;Overview if chosen as executive summary is bit too long, TTPs listed not using known framework such as MITRE ATT&amp;#x26;CK&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
&lt;h2 id=&quot;results-for-community-advocate&quot;&gt;Results for Community Advocate&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#results-for-community-advocate&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://www.linkedin.com/feed/update/urn:li:activity:7438379392071839744/&quot; class=&quot;external&quot;&gt;Winner: Alif &amp;#x26; Faez&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h3 id=&quot;scoring-criteria&quot;&gt;Scoring Criteria&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#scoring-criteria&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Brief Summary - if it is too short, too long or just right&lt;/li&gt;
&lt;li&gt;Diagrams - if includes screenshots, code snippets, infection chain/attack diagram&lt;/li&gt;
&lt;li&gt;Indicator Pivoting - pivoting from initial indicator (often phishing url) to underlying IP then whois record and so on&lt;/li&gt;
&lt;li&gt;TTP - TTPs listed and usage of known framework such as MITRE ATT&amp;#x26;CK or attck4fraud&lt;/li&gt;
&lt;li&gt;IoC - if IoCs were included, compiled and each IoCs has context&lt;/li&gt;
&lt;li&gt;Action Taken - proof of action taken (such as reporting to Google safe browsing and even beyond suggested previously) that gives out result (e.g. site no longer reachable)&lt;/li&gt;
&lt;li&gt;Phishing Kit - found phishing kit used, may pivot to similar campaigns that uses same phsihing kit, or even found the source code of the phishing kit&lt;/li&gt;
&lt;li&gt;Recommendation - provided relevant recommendation, be it to the public or organizations&lt;/li&gt;
&lt;li&gt;Extra points - interesting part of the report which unique to the writer&lt;/li&gt;
&lt;li&gt;Questions to Stakeholder - contacted stakeholder (Rectifyq) to clarify the expectation in terms formatting, or even the scoring criteria&lt;/li&gt;
&lt;li&gt;Follow Rectifyq’s social media - followed all Rectifyq’s social media&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;conclusion&quot;&gt;Conclusion&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#conclusion&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;This challenge really shows that Malaysia has amazing cybersecurity talent, from students to working pros. Everyone brought something different to the table—whether it was offensive skills or traffic analysis—and used those strengths to break down the phishing campaigns targeting Malaysian.&lt;/p&gt;
&lt;p&gt;I learned a ton from organizing this, and the feedback from few participants were great. Like I told one of the participants, I can’t officially promise to make this a regular thing just yet. But hopefully, even if I’m not the one running it next time, I hope this inspires other companies or organizations to host similar challenges.&lt;/p&gt; ]]></description>
    <pubDate>Wed, 18 Mar 2026 00:00:00 GMT</pubDate>
  </item><item>
    <title>2026-03-18 Iran — US/Israel Conflict, how is it impacted Malaysia Organisation?</title>
    <link>https://rectifyq.com/MY-Threat-Landscape/threat-lists/12ec4fe2-55a7-4cd4-b7d4-f3acf5d223e0</link>
    <guid>https://rectifyq.com/MY-Threat-Landscape/threat-lists/12ec4fe2-55a7-4cd4-b7d4-f3acf5d223e0</guid>
    <description><![CDATA[ &lt;p&gt;📃Title: Iran — US/Israel Conflict, how is it impacted Malaysia Organisation?&lt;br&gt;
📅Date: 2026-03-18&lt;br&gt;
🔗References:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://medium.com/@StampedeOps/iran-us-israel-conflict-how-is-it-impacted-malaysia-organisation-8ec8e3535959&quot; class=&quot;external&quot;&gt;https://medium.com/@StampedeOps/iran-us-israel-conflict-how-is-it-impacted-malaysia-organisation-8ec8e3535959&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;🔖Rectifyq Taxonomies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;relevancy: 🔴 Highly Relevant&lt;/li&gt;
&lt;li&gt;category: &lt;a href=&quot;../.././../tags/⚔Threat&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/⚔Threat&quot;&gt;⚔Threat&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;topic: &lt;a href=&quot;../.././../tags/geopolitical&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/geopolitical&quot;&gt;geopolitical&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;target: &lt;a href=&quot;../.././../tags/broad-based&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/broad-based&quot;&gt;broad-based&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;MY-relevancy: &lt;a href=&quot;../.././../tags/relevant&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/relevant&quot;&gt;relevant&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;sub-category: &lt;a href=&quot;../.././../tags/TA-profile&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/TA-profile&quot;&gt;TA-profile&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;topic: &lt;a href=&quot;../.././../tags/ics-ot&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/ics-ot&quot;&gt;ics-ot&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;🔖MISP Galaxies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;target-information=“Malaysia”&lt;/li&gt;
&lt;li&gt;country=“iran”&lt;/li&gt;
&lt;li&gt;country=“israel”&lt;/li&gt;
&lt;li&gt;country=“united states of america”&lt;/li&gt;
&lt;li&gt;threat-actor= &lt;a href=&quot;../.././../tags/MuddyWater&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/MuddyWater&quot;&gt;MuddyWater&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;threat-actor= &lt;a href=&quot;../.././../tags/APT35&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/APT35&quot;&gt;APT35&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;threat-actor= &lt;a href=&quot;../.././../tags/APT42&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/APT42&quot;&gt;APT42&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;threat-actor= &lt;a href=&quot;../.././../tags/Cyber-Av3ngers&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/Cyber-Av3ngers&quot;&gt;Cyber-Av3ngers&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;threat-actor= &lt;a href=&quot;../.././../tags/Fox-Kitten&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/Fox-Kitten&quot;&gt;Fox-Kitten&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;threat-actor= &lt;a href=&quot;../.././../tags/OilRig&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/OilRig&quot;&gt;OilRig&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;mitre-attack-pattern=[]&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;MISP event uuid: &lt;a href=&quot;https://mispmy.rectifyq.com/events/view/12ec4fe2-55a7-4cd4-b7d4-f3acf5d223e0&quot; class=&quot;external&quot;&gt;12ec4fe2-55a7-4cd4-b7d4-f3acf5d223e0&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2 id=&quot;indicator-of-compromise-iocs&quot;&gt;Indicator of Compromise (IoCs)&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#indicator-of-compromise-iocs&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;pre&gt;&lt;code&gt;type,value,comment
md5, f6a4c531e92cbdd5ffac75c76939d7f3, &#039;IoCs related to MuddyWater&#039;
md5, c89671f994af65677aa48b699a01fe9d, &#039;IoCs related to MuddyWater&#039;
md5, 2ed6ebaa28a9bfccc59c6e89a8990631, &#039;IoCs related to MuddyWater&#039;
md5, cd555279b6438260ec71b32e4d02cd9d, &#039;IoCs related to MuddyWater&#039;
md5, ef6ec560efd05d21976a6fd3f489e206, &#039;IoCs related to MuddyWater&#039;
md5, 4c169dde3bc184c42ca7a712a61c6f3c, &#039;IoCs related to MuddyWater&#039;
md5, d2b0785b69f8578bdddf039634507f47, &#039;IoCs related to MuddyWater&#039;
md5, 7da3d206519086f2725494b3ab095fbb, &#039;IoCs related to MuddyWater&#039;
md5, 68352f61da6e3236c4fe760997a981ea, &#039;IoCs related to MuddyWater&#039;
md5, 3a95186019af1943a0ea0f8eb07a288f, &#039;IoCs related to MuddyWater&#039;
md5, 404f5b1ff4ed035c6178d1789192c4d8, &#039;IoCs related to MuddyWater&#039;
md5, 74e75830252220cbbe7e3adec4340d2d, &#039;IoCs related to MuddyWater&#039;
md5, c5c0829df294cc4fd701df5d5c55718f, &#039;IoCs related to MuddyWater&#039;
md5, cdeb7abfc7775c63745135431272dda3, &#039;IoCs related to MuddyWater&#039;
md5, f97650ede0c39a29b0b5c5472f685d11, &#039;IoCs related to MuddyWater&#039;
md5, 0a95918fd6000a69b8a70609f93e910f, &#039;IoCs related to MuddyWater&#039;
md5, b9a67ffb81420e68f9e5607cc200604a, &#039;IoCs related to MuddyWater&#039;
md5, 95d9e6c262632abe004c4693a71eaced, &#039;IoCs related to MuddyWater&#039;
md5, aba760ec55fdeccb35adb068443feb89, &#039;IoCs related to MuddyWater&#039;
md5, 809334c0b55009c5a50f37e4eec63c43, &#039;IoCs related to MuddyWater&#039;
md5, 75060f5394b72421c0d8f81f79931aa9, &#039;IoCs related to MuddyWater&#039;
md5, 93be13bbcad30440a0d0ef3868d67003, &#039;IoCs related to MuddyWater&#039;
md5, 806adc79e7ea3be50ef1d3974a16b7fb, &#039;IoCs related to MuddyWater&#039;
md5, 242098c3e87822bffa7c337987065fbe, &#039;IoCs related to MuddyWater&#039;
md5, c381c2cb8fdd6acf1636280b9424f573, &#039;IoCs related to MuddyWater&#039;
md5, 2533307ec1ef8b0611c8896e1460b076, &#039;IoCs related to MuddyWater&#039;
md5, 1f280f51eeb6cf895fe80082ce725841, &#039;IoCs related to MuddyWater&#039;
md5, 43be8a405a7f57cf9f910d829c521b21, &#039;IoCs related to MuddyWater&#039;
md5, 23d99f912f2491749b89e4fd337273bc, &#039;IoCs related to MuddyWater&#039;
md5, 0873ce3db84b79da935f71df3d6c8e6d, &#039;IoCs related to MuddyWater&#039;
md5, f06e30dee8629e951cefa73373fdef9d, &#039;IoCs related to MuddyWater&#039;
md5, 1e9a4e774b61acc8a6b35ee50417e661, &#039;IoCs related to MuddyWater&#039;
md5, d276b8c1660f264d64eff3474718509b, &#039;IoCs related to MuddyWater&#039;
md5, d70ddec75de88bf4ca7cbb67b56627f6, &#039;IoCs related to MuddyWater&#039;
md5, 3ab16bd1c339fd0727be650104b74dd1, &#039;IoCs related to MuddyWater&#039;
md5, 64fc017a451ef273dcacdf6c099031f3, &#039;IoCs related to MuddyWater&#039;
md5, 4055d8b5c2e909f5db8b75a5750a7005, &#039;IoCs related to MuddyWater&#039;
md5, e2d6031afd81bf3b6a44de4d0b039055, &#039;IoCs related to MuddyWater&#039;
md5, f1c935ce028022ab2a495eae83adacc6, &#039;IoCs related to MuddyWater&#039;
md5, 47e312ecca7af098bb1c6c69188f54cf, &#039;IoCs related to MuddyWater&#039;
md5, b181ecbb7394e3b1394a8c97af65b7e2, &#039;IoCs related to MuddyWater&#039;
md5, 08d8ab5dd375847ce909297e59e7df00, &#039;IoCs related to MuddyWater&#039;
md5, c478e472f6223e7ee92cff8b459e55e2, &#039;IoCs related to MuddyWater&#039;
md5, 96d5a7e0e75654c444cb1a915c666ac8, &#039;IoCs related to MuddyWater&#039;
md5, 244a4f81cff4a8dc5872628a40713735, &#039;IoCs related to MuddyWater&#039;
md5, 6d7ce5b03fe61683229c29a859505163, &#039;IoCs related to MuddyWater&#039;
md5, aaa9db79b5d6ba319e24e6180a7935d6, &#039;IoCs related to MuddyWater&#039;
md5, 80c91b4343fe1260e348872e1b4c0713, &#039;IoCs related to APT35&#039;
md5, 83b7ec5f0d5d6f11ba1284a3f705e98e, &#039;IoCs related to APT35&#039;
md5, b7e4b752adff07ac1b7b67a9be30b366, &#039;IoCs related to APT35&#039;
md5, 223196939e1e1ba9256f515b0a510d7a, &#039;IoCs related to APT35&#039;
md5, e8e0f2ade7294808d86b23a989b21be1, &#039;IoCs related to APT35&#039;
md5, 7391c3d895246dbd5d26bf70f1d8cbad, &#039;IoCs related to APT35&#039;
md5, b40533e67e70b7ff7bb53d34a4b9170e, &#039;IoCs related to APT35&#039;
md5, a17b40b8133c1cc29c6146732086db69, &#039;IoCs related to APT35&#039;
md5, 14d8e865d3ca67b88c01f7e5d2b0862d, &#039;IoCs related to APT35&#039;
md5, 67dbe102978e4b612237ad3ee371702f, &#039;IoCs related to APT35&#039;
md5, 721ec011d75fea67ce9cb2796412651e, &#039;IoCs related to APT35&#039;
md5, 0c6f48c62d56b454ebc0e1b7e044ca69, &#039;IoCs related to APT35&#039;
md5, 097447c4b526f8a42e3144afe510ec20, &#039;IoCs related to APT35&#039;
md5, b319d8972115895f156807348fa9b45f, &#039;IoCs related to APT35&#039;
md5, 7d216c57da81193a45c67c323d4049c3, &#039;IoCs related to APT35&#039;
md5, fac805be171884ddbd1396f6a59c90eb, &#039;IoCs related to APT35&#039;
md5, 776677256087a5a0f543a6b6317cadf8, &#039;IoCs related to APT35&#039;
md5, 1baeff23794e47eb5c927c0303b7cd92, &#039;IoCs related to APT35&#039;
md5, cef266a5ea7ba57abc576cbeb5497c97, &#039;IoCs related to APT35&#039;
md5, b19a097c237d594a85986881f69f127d, &#039;IoCs related to APT35&#039;
md5, 3a85381dd880c69f40b02859cd9fd473, &#039;IoCs related to APT35&#039;
md5, 53d0f4a75e8acbb6255bb44242e4843f, &#039;IoCs related to APT35&#039;
md5, c4b95c1ba3671c5172e7eb01178a7c39, &#039;IoCs related to APT35&#039;
md5, 20e80c787e129ec11de9accdd0ae4611, &#039;IoCs related to APT35&#039;
md5, 0c76c41dfe6989ba042e27755e2b68f7, &#039;IoCs related to APT35&#039;
md5, b683628884cc1d00c234ea2f4b85d153, &#039;IoCs related to APT35&#039;
md5, 1965a61d6f96b7bb221564ad52ba9719, &#039;IoCs related to APT35&#039;
md5, 68abbdd75f82a22e3cf6200e13a664b3, &#039;IoCs related to APT35&#039;
md5, be2bd408c615997c600871970573f023, &#039;IoCs related to APT35&#039;
md5, be556a0d7d75524acc5518482e43ed9a, &#039;IoCs related to APT35&#039;
md5, e5f0aea43ac33bf19a78c1a600f690d5, &#039;IoCs related to APT35&#039;
md5, e23637423599434a6de45b9080b7c561, &#039;IoCs related to APT35&#039;
md5, 96a9078d97a8b2a0cdc6632b48b8a649, &#039;IoCs related to APT35&#039;
md5, e16c8c285b1d537be5fe32e93247c282, &#039;IoCs related to APT35&#039;
md5, 2dab429e52096fd9eb031fc666965a5e, &#039;IoCs related to APT35&#039;
md5, 347b273df245f5e1fcbef32f5b836f1d, &#039;IoCs related to APT42&#039;
md5, 2ff97de7a16519b74113ea9137c6ba0c, &#039;IoCs related to APT42&#039;
md5, d32f89a8a3dd360db3fa9b838163ffa0, &#039;IoCs related to APT42&#039;
md5, 853687659483d215309941dae391a68f, &#039;IoCs related to APT42&#039;
md5, dd2653a2543fa44eaeeff3ca82fe3513, &#039;IoCs related to APT42&#039;
md5, 081419a484bbf99f278ce636d445b9d8, &#039;IoCs related to APT42&#039;
md5, 4551a6cdf8d23a96aa4124ac9bdb6d1d, &#039;IoCs related to APT42&#039;
md5, 22e9135a650cd674eb330cbb4a7329c3, &#039;IoCs related to APT42&#039;
md5, e7df84a5a22aeafcf1c3abf4fd986c91, &#039;IoCs related to APT42&#039;
md5, d783001d1f98fe3b33e7b97b0b7d96dc, &#039;IoCs related to APT42&#039;
md5, 755c0350038daefb29b888b6f8739e81, &#039;IoCs related to APT42&#039;
md5, 2783376fd7af9ec138ecf49ad7391f16, &#039;IoCs related to APT42&#039;
md5, c23663ebdfbc340457201dbec7469386, &#039;IoCs related to APT42&#039;
md5, a70d6bbf2acb62e257c98cb0450f4fec, &#039;IoCs related to APT42&#039;
md5, 5746a9e0a410349b17f8a64af30f9cd3, &#039;IoCs related to APT42&#039;
md5, c92e2655d115368f92e7b7de5803b7bc, &#039;IoCs related to APT42&#039;
md5, a50a20edddaded453410600549968914, &#039;IoCs related to APT42&#039;
md5, a713e686fd984588a4db74f34bf32275, &#039;IoCs related to APT42&#039;
md5, d7bf138d1aa2b70d6204a2f3c3bc72a7, &#039;IoCs related to APT42&#039;
md5, bdd0d556166ad0af9ded39ab4b9ed34f, &#039;IoCs related to APT42&#039;
md5, abe531e9f1e642c47260fac40dc41f59, &#039;IoCs related to APT42&#039;
md5, 93c19436e6e5207e2e2bed425107f080, &#039;IoCs related to APT42&#039;
md5, a9cd92a3a4d90daf9331036c772c67de, &#039;IoCs related to APT42&#039;
md5, d533a3c61e8425e51dca36415b9e8af2, &#039;IoCs related to APT42&#039;
md5, 8678cca1ee25121546883db16846878b, &#039;IoCs related to APT42&#039;
md5, c17f4bb8e415e21e6010b98e13c6dff3, &#039;IoCs related to APT42&#039;
md5, cafe08392d476a057d85de4983bac94e, &#039;IoCs related to APT42&#039;
md5, 63c4c31965ed08a3207d44e885ebd5e4, &#039;IoCs related to APT42&#039;
md5, b3411927cc7cd05e02ba64b2a789bbde, &#039;IoCs related to PARISITE&#039;
md5, ebd96cf97f93e62210fe4d928c49464c, &#039;IoCs related to PARISITE&#039;
md5, 48274e0b14ce2fbea39bbb98d7c8d495, &#039;IoCs related to PARISITE&#039;
md5, 6a58b52b184715583cda792b56a0a1ed, &#039;IoCs related to PARISITE&#039;
md5, 057999f7fedb3339def3be576a2408a7, &#039;IoCs related to PARISITE&#039;
md5, 923cab44221fabd8f42dd00cc0701ac3, &#039;IoCs related to PARISITE&#039;
md5, 6445cddd5284516b192330a2805606de, &#039;IoCs related to PARISITE&#039;
md5, fe94c576b99dcc99b1c82fce00af97ab, &#039;IoCs related to PARISITE&#039;
md5, e736229e890a138ccf7810e00a6bb50d, &#039;IoCs related to PARISITE&#039;
domain, stratioai.org, &#039;IoCs related to MuddyWater&#039;
domain, moodleuni.com, &#039;IoCs related to MuddyWater&#039;
hostname, nomercys.it.com, &#039;IoCs related to MuddyWater&#039;
domain, bootcamptg.org, &#039;IoCs related to MuddyWater&#039;
hostname, sso.moodleuni.com, &#039;IoCs related to MuddyWater&#039;
domain, bookairway.com, &#039;IoCs related to MuddyWater&#039;
hostname, sso.facetalk.org, &#039;IoCs related to MuddyWater&#039;
domain, netivtech.org, &#039;IoCs related to MuddyWater&#039;
domain, processplanet.org, &#039;IoCs related to MuddyWater&#039;
domain, screenai.online, &#039;IoCs related to MuddyWater&#039;
domain, pharmacynod.com, &#039;IoCs related to MuddyWater&#039;
domain, facetalk.org, &#039;IoCs related to MuddyWater&#039;
domain, photosjournalism.com, &#039;IoCs related to MuddyWater&#039;
ip-dst, 165.227.82.147, &#039;IoCs related to MuddyWater&#039;
ip-dst, 194.11.246.101, &#039;IoCs related to MuddyWater&#039;
ip-dst, 157.20.182.49, &#039;IoCs related to MuddyWater&#039;
ip-dst, 161.35.228.250, &#039;IoCs related to MuddyWater&#039;
ip-dst, 195.20.17.189, &#039;IoCs related to MuddyWater&#039;
ip-dst, 62.106.66.112, &#039;IoCs related to MuddyWater&#039;
ip-dst, 159.198.68.25, &#039;IoCs related to MuddyWater&#039;
ip-dst, 159.65.227.190, &#039;IoCs related to MuddyWater&#039;
ip-dst, 18.116.63.2, &#039;IoCs related to MuddyWater&#039;
ip-dst, 209.74.87.100, &#039;IoCs related to MuddyWater&#039;
ip-dst, 35.175.224.64, &#039;IoCs related to MuddyWater&#039;
ip-dst, 159.198.66.153, &#039;IoCs related to MuddyWater&#039;
ip-dst, 143.198.5.41, &#039;IoCs related to MuddyWater&#039;
ip-dst, 18.223.24.218, &#039;IoCs related to MuddyWater&#039;
ip-dst, 185.128.139.4, &#039;IoCs related to MuddyWater&#039;
sha1, 2d5b8da0d0719e6f8212497d7e34d5f1b1fa6776, &#039;IoCs related to APT35 No sample in VT\r\nLast check:21/03/2026&#039;
md5, 8db7338c487143a4d43ed1a22fec49a7, &#039;IoCs related to APT35 No sample in VT\r\nLast check:21/03/2026&#039;
md5, f5dd107eaca971f24effbaf598119ca1, &#039;IoCs related to APT35 No sample in VT\r\nLast check:21/03/2026&#039;
sha1, 4d6bf3834e9afb8e3c3861bf2ad64a68d9c7d870, &#039;IoCs related to APT35 No sample in VT\r\nLast check:21/03/2026&#039;
md5, 943981571f4e095063850c26158835b8, &#039;IoCs related to APT35 No sample in VT\r\nLast check:21/03/2026&#039;
md5, 25d3a014c332aaa3adce429d0e714e31, &#039;IoCs related to APT35 No sample in VT\r\nLast check:21/03/2026&#039;
md5, 7d887893a6107d7ae902e6771f30e080, &#039;IoCs related to APT35 No sample in VT\r\nLast check:21/03/2026&#039;
md5, 63080b45ca4978fb5d2d71387dbaf610, &#039;IoCs related to APT35 No sample in VT\r\nLast check:21/03/2026&#039;
md5, a933c623e3b047292efd55e0e424c732, &#039;IoCs related to APT35 No sample in VT\r\nLast check:21/03/2026&#039;
sha1, 544bf4f9e5fdb4d35987b4c25f537213ce3c926a, &#039;IoCs related to APT35 No sample in VT\r\nLast check:21/03/2026&#039;
md5, 67e09818d1aa650896a432b1de54d376, &#039;IoCs related to APT35 No sample in VT\r\nLast check:21/03/2026&#039;
md5, 424f887f651371aa3058cf7c8e908d2a, &#039;IoCs related to APT35 No sample in VT\r\nLast check:21/03/2026&#039;
domain, unityprogressall.org, &#039;IoCs related to APT35&#039;
domain, transfergocompany.com, &#039;IoCs related to APT35&#039;
domain, defenceprodindia.site, &#039;IoCs related to APT35&#039;
domain, mojavemassageandwellness.com, &#039;IoCs related to APT35&#039;
domain, supervisor-intendant.info, &#039;IoCs related to APT35&#039;
ip-dst, 185.132.176.13, &#039;IoCs related to APT35&#039;
ip-dst, 195.160.220.202, &#039;IoCs related to APT35&#039;
ip-dst, 1.235.222.140, &#039;IoCs related to APT35&#039;
hostname, whatsapp-meeting.duckdns.org, &#039;IoCs related to APT42&#039;
hostname, whatsapp-meet.duckdns.org, &#039;IoCs related to APT42&#039;
hostname, meet-join.duckdns.org, &#039;IoCs related to APT42&#039;
hostname, whatsapp-join-meet.duckdns.org, &#039;IoCs related to APT42&#039;
domain, meet-safe.online, &#039;IoCs related to APT42&#039;
hostname, meet-login.duckdns.org, &#039;IoCs related to APT42&#039;
domain, act-rights-gaming.digital, &#039;IoCs related to APT42&#039;
hostname, book.good-while.online, &#039;IoCs related to APT42&#039;
domain, net-vision.xyz, &#039;IoCs related to APT42&#039;
domain, join-host-room.xyz, &#039;IoCs related to APT42&#039;
domain, joining-inside-space.world, &#039;IoCs related to APT42&#039;
domain, forward-goal-inner.digital, &#039;IoCs related to APT42&#039;
hostname, www.whatsapp-meet.duckdns.org, &#039;IoCs related to APT42&#039;
domain, accord-room-check.live, &#039;IoCs related to APT42&#039;
domain, joining-room-host.xyz, &#039;IoCs related to APT42&#039;
domain, net-works.xyz, &#039;IoCs related to APT42&#039;
domain, re-shrt98.xyz, &#039;IoCs related to APT42&#039;
domain, first-step.space, &#039;IoCs related to APT42&#039;
domain, tiny-name.cyou, &#039;IoCs related to APT42&#039;
domain, bonjour-ills.christmas, &#039;IoCs related to APT42&#039;
md5, 59f636854f5a511945eb4870cce6a85b, &#039;IoCs related to PARISITE No sample in VT\r\nLast check:21/03/2026&#039;
sha1, 786379bb3c0e3ea6ec7d7af88d109994c20bb849, &#039;IoCs related to PARISITE No sample in VT\r\nLast check:21/03/2026&#039;
md5, 923cefd8623c495b31415e0775c099c2, &#039;IoCs related to PARISITE No sample in VT\r\nLast check:21/03/2026&#039;
sha256, e12acf1b58b633d090b7e9828b0790502c9b9cd2df51a6863319912d2152dbc9, &#039;IoCs related to PARISITE No sample in VT\r\nLast check:21/03/2026&#039;
sha256, c0786c60e92be76cb9f9b3da5f53d5e8b999b2c86a73e94d793070f2b96f852e, &#039;IoCs related to PARISITE No sample in VT\r\nLast check:21/03/2026&#039;
sha256, 30c4ff83d5dc3d4c5be77283defce614f6310339705b039cae022bdde72dec38, &#039;IoCs related to PARISITE No sample in VT\r\nLast check:21/03/2026&#039;
sha1, 86969bc9f13c6359c54151432f3819301074164c, &#039;IoCs related to PARISITE No sample in VT\r\nLast check:21/03/2026&#039;
md5, 9dcf203b7d87698d678cf9df42ab4ac0, &#039;IoCs related to PARISITE No sample in VT\r\nLast check:21/03/2026&#039;
md5, 56401106c49609c526e218a4a4103fee, &#039;IoCs related to PARISITE No sample in VT\r\nLast check:21/03/2026&#039;
sha1, def5cb2d480d058902b7cc2f6c0915afd972ad0b, &#039;IoCs related to PARISITE No sample in VT\r\nLast check:21/03/2026&#039;
sha256, 9885c4343942163087fbbea7939bec38702086e0f737c97deb288e8d3e6f140a, &#039;IoCs related to PARISITE No sample in VT\r\nLast check:21/03/2026&#039;
md5, 9e7f2b5e0c5b164f2c62b412a9a91cbc, &#039;IoCs related to PARISITE No sample in VT\r\nLast check:21/03/2026&#039;
sha256, a841c8179ac48bdc2ebf1e646d4f552d9cd02fc79207fdc2fc783889049f32bc, &#039;IoCs related to PARISITE No sample in VT\r\nLast check:21/03/2026&#039;
sha256, ea10bc8c77446c9a7eb4720df656a465e3cf4edb40a2c5cacd7f6b665960ccda, &#039;IoCs related to PARISITE No sample in VT\r\nLast check:21/03/2026&#039;
sha1, 5d3ddb0e95725974b6034f19cfaef2d6ebd69c87, &#039;IoCs related to PARISITE No sample in VT\r\nLast check:21/03/2026&#039;
md5, 03f2b01a9bc670ce6f2a2a50d5c08b22, &#039;IoCs related to PARISITE No sample in VT\r\nLast check:21/03/2026&#039;
sha1, ddc5bdace73c1754d87d9ea1c545a0cb9112789b, &#039;IoCs related to PARISITE No sample in VT\r\nLast check:21/03/2026&#039;
sha256, 9208034af160357c99b45564ff54570b1510baf3bc033999ae4281482617ff5b, &#039;IoCs related to PARISITE No sample in VT\r\nLast check:21/03/2026&#039;
sha1, e6a1157020746cf487799ad344a5b1a603052f0e, &#039;IoCs related to PARISITE No sample in VT\r\nLast check:21/03/2026&#039;
md5, 669437838a13bf783d6ff1574274e5b0, &#039;IoCs related to PARISITE No sample in VT\r\nLast check:21/03/2026&#039;
sha1, b6e4db5df0f92783341267dedea4fdc5530e4a4f, &#039;IoCs related to PARISITE No sample in VT\r\nLast check:21/03/2026&#039;
sha1, bbe681caebf5711ffc366d09097c7c587e212ebb, &#039;IoCs related to PARISITE No sample in VT\r\nLast check:21/03/2026&#039;
sha1, f7ec27cd5b05a66b263f620402c39c2b7d2f23ef, &#039;IoCs related to PARISITE No sample in VT\r\nLast check:21/03/2026&#039;
md5, 07ab4dd676f477e9f93be1a325073d93, &#039;IoCs related to PARISITE No sample in VT\r\nLast check:21/03/2026&#039;
sha256, 27ae97933a4dd955a7e928be0efa361907c088076837446ada5642bd32500627, &#039;IoCs related to PARISITE No sample in VT\r\nLast check:21/03/2026&#039;
sha256, 1c4147fb6edf4075102432716c6a62711b5c57599c6a22a20eda61321023a429, &#039;IoCs related to PARISITE No sample in VT\r\nLast check:21/03/2026&#039;
sha1, 28e04219b84d36243cfa03320ab0b9677bc9fd1d, &#039;IoCs related to PARISITE No sample in VT\r\nLast check:21/03/2026&#039;
sha1, 5d573209939c737a829dac72383062d9965a8fa3, &#039;IoCs related to PARISITE No sample in VT\r\nLast check:21/03/2026&#039;
md5, 04f9274c62c612342e74f868fc3069f5, &#039;IoCs related to PARISITE No sample in VT\r\nLast check:21/03/2026&#039;
sha256, 903638cceca0718c586739cb822ca396f84693bc3e9b3d07daff5c09f0a5b2a6, &#039;IoCs related to PARISITE No sample in VT\r\nLast check:21/03/2026&#039;
sha256, a87b96ae9a31ec92e29a48a522ef9554d02ce74db7cb6cd4b133fff07c5b258e, &#039;IoCs related to PARISITE No sample in VT\r\nLast check:21/03/2026&#039;
sha256, 64892920b813f61eab4797bd60e3fc79a810354e2318061b252dfc027bf72329, &#039;IoCs related to PARISITE No sample in VT\r\nLast check:21/03/2026&#039;
sha1, efb7b3c47ae74663f153a4b091abfa841c15ea7c, &#039;IoCs related to PARISITE No sample in VT\r\nLast check:21/03/2026&#039;
sha1, 876fd4e9676ef914bbaf3bbaf7d97e368290e09c, &#039;IoCs related to PARISITE No sample in VT\r\nLast check:21/03/2026&#039;
sha1, 10f64f4a976195e25587713c4f754b46b61849cc, &#039;IoCs related to PARISITE No sample in VT\r\nLast check:21/03/2026&#039;
sha1, cf7399acf378c147e706f90e924015ef47cdb364, &#039;IoCs related to PARISITE No sample in VT\r\nLast check:21/03/2026&#039;
md5, 42c497d2b9b43061482d2544c6d09d14, &#039;IoCs related to PARISITE No sample in VT\r\nLast check:21/03/2026&#039;
md5, 167f4e92fb3d937bd6a7ded14bf076e6, &#039;IoCs related to PARISITE No sample in VT\r\nLast check:21/03/2026&#039;
domain, encoremir.com, &#039;IoCs related to PARISITE&#039;
hostname, apps.gist.githubapp.net, &#039;IoCs related to PARISITE&#039;
ip-dst, 66.55.159.84, &#039;IoCs related to PARISITE&#039;
ip-dst, 64.176.165.175, &#039;IoCs related to PARISITE&#039;
ip-dst, 5.255.100.203, &#039;IoCs related to PARISITE&#039;

&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Full IOCs available in Rectifyq’s &lt;a href=&quot;https://mispmy.rectifyq.com/events/view/12ec4fe2-55a7-4cd4-b7d4-f3acf5d223e0&quot; class=&quot;external&quot;&gt;MISP&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt; ]]></description>
    <pubDate>Wed, 18 Mar 2026 00:00:00 GMT</pubDate>
  </item><item>
    <title>2026-03-15 PhishHuntMY] QRaya A Quishing Campaign Targeting TNG eWallet Users During Ramadhan 2026</title>
    <link>https://rectifyq.com/MY-Threat-Landscape/threat-lists/a0e17fad-45e1-4ab2-9704-ffed51520720</link>
    <guid>https://rectifyq.com/MY-Threat-Landscape/threat-lists/a0e17fad-45e1-4ab2-9704-ffed51520720</guid>
    <description><![CDATA[ &lt;p&gt;📃Title: PhishHuntMY] QRaya: A Quishing Campaign Targeting TNG eWallet Users During Ramadhan 2026&lt;br&gt;
📅Date: 2026-03-15&lt;br&gt;
🔗References:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.linkedin.com/posts/syazwanisubri_phishhuntmy-phishhuntmy-quishing-activity-7438584878696325120-YoYN&quot; class=&quot;external&quot;&gt;https://www.linkedin.com/posts/syazwanisubri_phishhuntmy-phishhuntmy-quishing-activity-7438584878696325120-YoYN&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/Syazwani-s246/phish-hunt-my-2026&quot; class=&quot;external&quot;&gt;https://github.com/Syazwani-s246/phish-hunt-my-2026&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.virustotal.com/gui/collection/7d38c7c478078131663e9928cc5b5ac8f01c87a7ddb5882e9f8508c52ff5f8e8&quot; class=&quot;external&quot;&gt;https://www.virustotal.com/gui/collection/7d38c7c478078131663e9928cc5b5ac8f01c87a7ddb5882e9f8508c52ff5f8e8&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;🔖Rectifyq Taxonomies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;relevancy: 🔴 Highly Relevant&lt;/li&gt;
&lt;li&gt;category: &lt;a href=&quot;../.././../tags/⚔Threat&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/⚔Threat&quot;&gt;⚔Threat&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;sub-category: &lt;a href=&quot;../.././../tags/campaign-analysis&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/campaign-analysis&quot;&gt;campaign-analysis&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;target: &lt;a href=&quot;../.././../tags/broad-based&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/broad-based&quot;&gt;broad-based&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;MY-relevancy: &lt;a href=&quot;../.././../tags/relevant&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/relevant&quot;&gt;relevant&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;🔖MISP Galaxies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;target-information=“Malaysia”&lt;/li&gt;
&lt;li&gt;mitre-attack-pattern=[‘T1041’, ‘T1566’, ‘T1566.002’, ‘T1056.003’]&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;MISP event uuid: &lt;a href=&quot;https://mispmy.rectifyq.com/events/view/a0e17fad-45e1-4ab2-9704-ffed51520720&quot; class=&quot;external&quot;&gt;a0e17fad-45e1-4ab2-9704-ffed51520720&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2 id=&quot;indicator-of-compromise-iocs&quot;&gt;Indicator of Compromise (IoCs)&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#indicator-of-compromise-iocs&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;pre&gt;&lt;code&gt;type,value,comment
url, https://t.ly/cdn.tngdigital.com.my/s/oauth2/berbagirezki/, &#039;Fake TNG OAuth path, Indonesian-language strings&#039;
url, https://myportalregistration.com/claim-segera, &#039;Direct phishing domain&#039;
url, https://tngduitraya.gbdjw.my/, &#039;Direct phishing domain&#039;
url, https://t.ly/Claim11-money-pocket.com?r=qr, &#039;t.ly shortener to phishing domain&#039;
url, https://cdntng.sit-e.com/daftar/, &#039;Typosquats TNG CDN domain&#039;
url, https://bantuan-tng.inst-my.online/in, &#039;Malay-language targeting&#039;
hostname, cdn-tngdigital9.my-regist.com, &#039;Typosquats cdn.tngdigital.com.my&#039;
url, https://shrturl.dev, &#039;Fortinet flagged: Phishing&#039;
url, https://cq7zc1x.clxz-hv.xyz, &#039;Cloudflare-protected credential harvester, ~3mo old domain&#039;
hostname, register-now-7528.vercel.app, &#039;secondary campaign, Bantuan Aidilfitri RM750&#039;
url, myportalregistration.com/claim-segera, &#039;&#039;
hostname, tngduitraya.gbdjw.my, &#039;&#039;
hostname, cdntng.sit-e.com, &#039;&#039;
hostname, cdn.tngdigital.com.my, &#039;&#039;
hostname, bantuan-tng.inst-my.online, &#039;&#039;
url, https://t.ly/cdn.tngdigital.com.my/s/oauth2/berbagirezki/bulansuciramadhan/penuhberkah/moneypacket/1234567890/234567876543234567887654345678765432345678987654323456788765432345677654334567887654234567?r=qr, &#039;&#039;
url, https://t.ly/cdn.tngdigital.com.my/s/oauth2/berbagirezki/bulansuciramadhan/penuhberkah/moneypacket/1234567890/123456787654323456788765432345678876543234567887654323456789876543256787654328765387643876?r=qr, &#039;&#039;
url, https://t.ly/cdn.tngdigital.com.my/s/oauth2/berbagirezki/bulansuciramadhan/penuhberkah/moneypacket/1234567890/234567898765432124567887654321234567898765432345678987654323456789876543234567898765432456?r=qr, &#039;&#039;

&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Full IOCs available in Rectifyq’s &lt;a href=&quot;https://mispmy.rectifyq.com/events/view/a0e17fad-45e1-4ab2-9704-ffed51520720&quot; class=&quot;external&quot;&gt;MISP&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt; ]]></description>
    <pubDate>Sun, 15 Mar 2026 00:00:00 GMT</pubDate>
  </item><item>
    <title>2026-03-15 PhishHuntMY] PHISH HUNT MY Hunting a Touch ’n Go “Duit Raya” Phishing Campaign Targeting Malaysians</title>
    <link>https://rectifyq.com/MY-Threat-Landscape/threat-lists/acf129a1-cdf0-4e12-89dd-7e94b1fa5c81</link>
    <guid>https://rectifyq.com/MY-Threat-Landscape/threat-lists/acf129a1-cdf0-4e12-89dd-7e94b1fa5c81</guid>
    <description><![CDATA[ &lt;p&gt;📃Title: PhishHuntMY] PHISH HUNT MY: Hunting a Touch ’n Go “Duit Raya” Phishing Campaign Targeting Malaysians&lt;br&gt;
📅Date: 2026-03-15&lt;br&gt;
🔗References:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://medium.com/@work.akmaltaufik/hunting-a-touch-n-go-duit-raya-phishing-campaign-targeting-malaysians-dedad86d39b1&quot; class=&quot;external&quot;&gt;https://medium.com/@work.akmaltaufik/hunting-a-touch-n-go-duit-raya-phishing-campaign-targeting-malaysians-dedad86d39b1&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;🔖Rectifyq Taxonomies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;relevancy: 🔴 Highly Relevant&lt;/li&gt;
&lt;li&gt;category: &lt;a href=&quot;../.././../tags/⚔Threat&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/⚔Threat&quot;&gt;⚔Threat&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;sub-category: &lt;a href=&quot;../.././../tags/campaign-analysis&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/campaign-analysis&quot;&gt;campaign-analysis&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;target: &lt;a href=&quot;../.././../tags/broad-based&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/broad-based&quot;&gt;broad-based&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;MY-relevancy: &lt;a href=&quot;../.././../tags/relevant&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/relevant&quot;&gt;relevant&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;🔖MISP Galaxies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;target-information=“Malaysia”&lt;/li&gt;
&lt;li&gt;mitre-attack-pattern=[]&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;MISP event uuid: &lt;a href=&quot;https://mispmy.rectifyq.com/events/view/acf129a1-cdf0-4e12-89dd-7e94b1fa5c81&quot; class=&quot;external&quot;&gt;acf129a1-cdf0-4e12-89dd-7e94b1fa5c81&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2 id=&quot;indicator-of-compromise-iocs&quot;&gt;Indicator of Compromise (IoCs)&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#indicator-of-compromise-iocs&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;pre&gt;&lt;code&gt;type,value,comment
hostname, tngduitraya79.gofvv2.my, &#039;&#039;
url, https://tngduitraya79.gofvv2.my, &#039;&#039;
url, https://tngduitraya17.gofvv2.my/go, &#039;&#039;
url, https://tngduitraya17.gofvv2.my/go/, &#039;&#039;

&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Full IOCs available in Rectifyq’s &lt;a href=&quot;https://mispmy.rectifyq.com/events/view/acf129a1-cdf0-4e12-89dd-7e94b1fa5c81&quot; class=&quot;external&quot;&gt;MISP&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt; ]]></description>
    <pubDate>Sun, 15 Mar 2026 00:00:00 GMT</pubDate>
  </item><item>
    <title>2026-03-15 PhishHuntMY] Phishing Alert Think Before You Scan!</title>
    <link>https://rectifyq.com/MY-Threat-Landscape/threat-lists/bf98b299-b634-41c8-8591-fc1a1da63824</link>
    <guid>https://rectifyq.com/MY-Threat-Landscape/threat-lists/bf98b299-b634-41c8-8591-fc1a1da63824</guid>
    <description><![CDATA[ &lt;p&gt;📃Title: PhishHuntMY] Phishing Alert: Think Before You Scan!&lt;br&gt;
📅Date: 2026-03-15&lt;br&gt;
🔗References:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.linkedin.com/posts/amirulhmd_phishing-alert-think-before-you-scan-ugcPost-7438172372588924928-zlYa&quot; class=&quot;external&quot;&gt;https://www.linkedin.com/posts/amirulhmd_phishing-alert-think-before-you-scan-ugcPost-7438172372588924928-zlYa&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://drive.google.com/file/d/1xlheNtElkYchFstarKwlpRyeu_U7yQXo/view&quot; class=&quot;external&quot;&gt;https://drive.google.com/file/d/1xlheNtElkYchFstarKwlpRyeu_U7yQXo/view&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;🔖Rectifyq Taxonomies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;relevancy: 🔴 Highly Relevant&lt;/li&gt;
&lt;li&gt;category: &lt;a href=&quot;../.././../tags/⚔Threat&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/⚔Threat&quot;&gt;⚔Threat&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;target: &lt;a href=&quot;../.././../tags/broad-based&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/broad-based&quot;&gt;broad-based&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;MY-relevancy: &lt;a href=&quot;../.././../tags/relevant&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/relevant&quot;&gt;relevant&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;🔖MISP Galaxies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;target-information=“Malaysia”&lt;/li&gt;
&lt;li&gt;mitre-attack-pattern=[]&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;MISP event uuid: &lt;a href=&quot;https://mispmy.rectifyq.com/events/view/bf98b299-b634-41c8-8591-fc1a1da63824&quot; class=&quot;external&quot;&gt;bf98b299-b634-41c8-8591-fc1a1da63824&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2 id=&quot;indicator-of-compromise-iocs&quot;&gt;Indicator of Compromise (IoCs)&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#indicator-of-compromise-iocs&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;pre&gt;&lt;code&gt;type,value,comment
hostname, tng-wallet-qr.ty-fli.com, &#039;Malicious Domain&#039;
url, https://tng-wallet-qr.ty-fli.com/6/, &#039;Full Phishing URL&#039;
ip-dst, 172.67.204.240, &#039;Hosting IP Address&#039;

&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Full IOCs available in Rectifyq’s &lt;a href=&quot;https://mispmy.rectifyq.com/events/view/bf98b299-b634-41c8-8591-fc1a1da63824&quot; class=&quot;external&quot;&gt;MISP&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt; ]]></description>
    <pubDate>Sun, 15 Mar 2026 00:00:00 GMT</pubDate>
  </item><item>
    <title>2026-03-14 PhishHuntMY] Full analysis - BANTUAN TUNAI 2025</title>
    <link>https://rectifyq.com/MY-Threat-Landscape/threat-lists/0bb9238e-aab6-461a-94e5-7cf68f16649d</link>
    <guid>https://rectifyq.com/MY-Threat-Landscape/threat-lists/0bb9238e-aab6-461a-94e5-7cf68f16649d</guid>
    <description><![CDATA[ &lt;p&gt;📃Title: PhishHuntMY] Full analysis - BANTUAN TUNAI 2025&lt;br&gt;
📅Date: 2026-03-14&lt;br&gt;
🔗References:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.linkedin.com/posts/khairul-zuhaili-4abb2435a_initial-discovery-a-suspicious-activity-7438077834687881216-5pHw&quot; class=&quot;external&quot;&gt;https://www.linkedin.com/posts/khairul-zuhaili-4abb2435a_initial-discovery-a-suspicious-activity-7438077834687881216-5pHw&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;🔖Rectifyq Taxonomies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;relevancy: 🔴 Highly Relevant&lt;/li&gt;
&lt;li&gt;category: &lt;a href=&quot;../.././../tags/⚔Threat&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/⚔Threat&quot;&gt;⚔Threat&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;sub-category: &lt;a href=&quot;../.././../tags/campaign-analysis&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/campaign-analysis&quot;&gt;campaign-analysis&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;target: &lt;a href=&quot;../.././../tags/broad-based&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/broad-based&quot;&gt;broad-based&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;MY-relevancy: &lt;a href=&quot;../.././../tags/relevant&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/relevant&quot;&gt;relevant&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;🔖MISP Galaxies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;target-information=“Malaysia”&lt;/li&gt;
&lt;li&gt;mitre-attack-pattern=[]&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;MISP event uuid: &lt;a href=&quot;https://mispmy.rectifyq.com/events/view/0bb9238e-aab6-461a-94e5-7cf68f16649d&quot; class=&quot;external&quot;&gt;0bb9238e-aab6-461a-94e5-7cf68f16649d&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2 id=&quot;indicator-of-compromise-iocs&quot;&gt;Indicator of Compromise (IoCs)&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#indicator-of-compromise-iocs&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;pre&gt;&lt;code&gt;type,value,comment
url, https://t.me/bantuantngggg/2, &#039;&#039;
url, https://bit.ly/4u17ViW, &#039;&#039;
url, https://bantuantngonline.blogspot.com/?m=1, &#039;&#039;
hostname, bantuantngonline.blogspot.com, &#039;&#039;

&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Full IOCs available in Rectifyq’s &lt;a href=&quot;https://mispmy.rectifyq.com/events/view/0bb9238e-aab6-461a-94e5-7cf68f16649d&quot; class=&quot;external&quot;&gt;MISP&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt; ]]></description>
    <pubDate>Sat, 14 Mar 2026 00:00:00 GMT</pubDate>
  </item><item>
    <title>2026-03-14 PhishHuntMY] Phishing Campaign Analysis “Laptop Percuma / Bantuan E-Wallet” Scam</title>
    <link>https://rectifyq.com/MY-Threat-Landscape/threat-lists/2e75d0d3-61e8-431e-8aaa-b047eaa87b52</link>
    <guid>https://rectifyq.com/MY-Threat-Landscape/threat-lists/2e75d0d3-61e8-431e-8aaa-b047eaa87b52</guid>
    <description><![CDATA[ &lt;p&gt;📃Title: PhishHuntMY] Phishing Campaign Analysis: “Laptop Percuma / Bantuan E-Wallet” Scam&lt;br&gt;
📅Date: 2026-03-14&lt;br&gt;
🔗References:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://myos-esc.gitbook.io/myos-esc./blogs/phishing-campaign-analysis-laptop-percuma-bantuan-e-wallet-scam&quot; class=&quot;external&quot;&gt;https://myos-esc.gitbook.io/myos-esc./blogs/phishing-campaign-analysis-laptop-percuma-bantuan-e-wallet-scam&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;🔖Rectifyq Taxonomies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;relevancy: 🔴 Highly Relevant&lt;/li&gt;
&lt;li&gt;category: &lt;a href=&quot;../.././../tags/⚔Threat&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/⚔Threat&quot;&gt;⚔Threat&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;sub-category: &lt;a href=&quot;../.././../tags/campaign-analysis&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/campaign-analysis&quot;&gt;campaign-analysis&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;target: &lt;a href=&quot;../.././../tags/broad-based&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/broad-based&quot;&gt;broad-based&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;MY-relevancy: &lt;a href=&quot;../.././../tags/relevant&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/relevant&quot;&gt;relevant&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;🔖MISP Galaxies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;target-information=“Malaysia”&lt;/li&gt;
&lt;li&gt;country=“indonesia”&lt;/li&gt;
&lt;li&gt;online-service=“b0c71d51-34fd-47b5-9eb4-dd406ffc607f”&lt;/li&gt;
&lt;li&gt;mitre-attack-pattern=[‘T1041’, ‘T1056’, ‘T1036’, ‘T1566’, ‘T1090’]&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;MISP event uuid: &lt;a href=&quot;https://mispmy.rectifyq.com/events/view/2e75d0d3-61e8-431e-8aaa-b047eaa87b52&quot; class=&quot;external&quot;&gt;2e75d0d3-61e8-431e-8aaa-b047eaa87b52&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2 id=&quot;indicator-of-compromise-iocs&quot;&gt;Indicator of Compromise (IoCs)&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#indicator-of-compromise-iocs&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;pre&gt;&lt;code&gt;type,value,comment
url, http://bantuan-malay.biz.id/66/, &#039;Main phishing landing page&#039;
hostname, bantuan-malay.biz.id, &#039;Phishing domain&#039;
domain, xwasq.com, &#039;Backend data collection server&#039;
ip-dst, 104.21.78.24, &#039;Cloudflare proxy IP&#039;
ip-dst, 172.67.215.26, &#039;Cloudflare proxy IP&#039;
ip-dst, 103.163.138.21, &#039;Backend phishing infrastructure&#039;
url, https://xwasq.com/terkini6/send_otp, &#039;&#039;
email-src, lhepakbudak@gmail.com, &#039;Registrant Email&#039;

&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Full IOCs available in Rectifyq’s &lt;a href=&quot;https://mispmy.rectifyq.com/events/view/2e75d0d3-61e8-431e-8aaa-b047eaa87b52&quot; class=&quot;external&quot;&gt;MISP&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt; ]]></description>
    <pubDate>Sat, 14 Mar 2026 00:00:00 GMT</pubDate>
  </item><item>
    <title>2026-03-13 PhishHuntMY] TNG eWallet Quishing Campaign</title>
    <link>https://rectifyq.com/MY-Threat-Landscape/threat-lists/16aad763-2989-4fd3-b6cd-8ceb09e2ef6b</link>
    <guid>https://rectifyq.com/MY-Threat-Landscape/threat-lists/16aad763-2989-4fd3-b6cd-8ceb09e2ef6b</guid>
    <description><![CDATA[ &lt;p&gt;📃Title: PhishHuntMY] TNG eWallet Quishing Campaign&lt;br&gt;
📅Date: 2026-03-13&lt;br&gt;
🔗References:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://remarkable-xenon-ff5.notion.site/TNG-eWallet-Quishing-Campaign-31ea6f58415f80cc8e2dd5cee0c56826&quot; class=&quot;external&quot;&gt;https://remarkable-xenon-ff5.notion.site/TNG-eWallet-Quishing-Campaign-31ea6f58415f80cc8e2dd5cee0c56826&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;🔖Rectifyq Taxonomies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;relevancy: 🔴 Highly Relevant&lt;/li&gt;
&lt;li&gt;category: &lt;a href=&quot;../.././../tags/⚔Threat&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/⚔Threat&quot;&gt;⚔Threat&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;sub-category: &lt;a href=&quot;../.././../tags/campaign-analysis&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/campaign-analysis&quot;&gt;campaign-analysis&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;target: &lt;a href=&quot;../.././../tags/broad-based&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/broad-based&quot;&gt;broad-based&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;MY-relevancy: &lt;a href=&quot;../.././../tags/relevant&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/relevant&quot;&gt;relevant&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;🔖MISP Galaxies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;target-information=“Malaysia”&lt;/li&gt;
&lt;li&gt;mitre-attack-pattern=[]&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;MISP event uuid: &lt;a href=&quot;https://mispmy.rectifyq.com/events/view/16aad763-2989-4fd3-b6cd-8ceb09e2ef6b&quot; class=&quot;external&quot;&gt;16aad763-2989-4fd3-b6cd-8ceb09e2ef6b&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2 id=&quot;indicator-of-compromise-iocs&quot;&gt;Indicator of Compromise (IoCs)&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#indicator-of-compromise-iocs&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;pre&gt;&lt;code&gt;type,value,comment
url, https://bantuan.tng-gov-my.online/aply, &#039;&#039;
url, https://tng-wallet-qr.ty-fli.com/6/, &#039;&#039;
url, https://ewallet.tng-qr.it.com/2/, &#039;&#039;
domain, tng-gov-my.online, &#039;&#039;
domain, ty-fli.com, &#039;&#039;
hostname, tng-qr.it.com, &#039;&#039;
hostname, bantuan.tng-gov-my.online, &#039;&#039;
hostname, tng-wallet-qr.ty-fli.com, &#039;&#039;
hostname, ewallet.tng-qr.it.com, &#039;&#039;
ip-dst, 172.67.217.169, &#039;&#039;
ip-dst, 104.21.62.10, &#039;&#039;
ip-dst, 104.21.50.106, &#039;&#039;
ip-dst, 172.67.204.240, &#039;&#039;
ip-dst, 104.21.37.23, &#039;&#039;
ip-dst, 172.67.203.71, &#039;&#039;
ip-dst, 2606:4700:3037::ac43:d9a9, &#039;&#039;
ip-dst, 2606:4700:3036::6815:3e0a, &#039;&#039;
ip-dst, 2606:4700:3030::ac43:ccf0, &#039;&#039;
ip-dst, 2606:4700:3033::6815:326a, &#039;&#039;
ip-dst, 2606:4700:3032::ac43:cb47, &#039;&#039;
ip-dst, 2606:4700:3032::6815:2517, &#039;&#039;

&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Full IOCs available in Rectifyq’s &lt;a href=&quot;https://mispmy.rectifyq.com/events/view/16aad763-2989-4fd3-b6cd-8ceb09e2ef6b&quot; class=&quot;external&quot;&gt;MISP&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt; ]]></description>
    <pubDate>Fri, 13 Mar 2026 00:00:00 GMT</pubDate>
  </item><item>
    <title>2026-03-12 PhishHuntMY] How Scammers Stole Telegram Accounts During Ramadhan 2026</title>
    <link>https://rectifyq.com/MY-Threat-Landscape/threat-lists/c99cb7b0-3736-4cab-b7b5-3b1b4d769179</link>
    <guid>https://rectifyq.com/MY-Threat-Landscape/threat-lists/c99cb7b0-3736-4cab-b7b5-3b1b4d769179</guid>
    <description><![CDATA[ &lt;p&gt;📃Title: PhishHuntMY] How Scammers Stole Telegram Accounts During Ramadhan 2026&lt;br&gt;
📅Date: 2026-03-12&lt;br&gt;
🔗References:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.notion.so/How-Scammers-Stole-Telegram-Accounts-During-Ramadhan-2026-3211ea45347c80f19a61cbb0f570fc64&quot; class=&quot;external&quot;&gt;https://www.notion.so/How-Scammers-Stole-Telegram-Accounts-During-Ramadhan-2026-3211ea45347c80f19a61cbb0f570fc64&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;🔖Rectifyq Taxonomies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;relevancy: 🔴 Highly Relevant&lt;/li&gt;
&lt;li&gt;category: &lt;a href=&quot;../.././../tags/⚔Threat&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/⚔Threat&quot;&gt;⚔Threat&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;target: &lt;a href=&quot;../.././../tags/broad-based&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/broad-based&quot;&gt;broad-based&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;MY-relevancy: &lt;a href=&quot;../.././../tags/relevant&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/relevant&quot;&gt;relevant&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;🔖MISP Galaxies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;target-information=“Malaysia”&lt;/li&gt;
&lt;li&gt;country=“indonesia”&lt;/li&gt;
&lt;li&gt;online-service=“b0c71d51-34fd-47b5-9eb4-dd406ffc607f”&lt;/li&gt;
&lt;li&gt;mitre-attack-pattern=[]&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;MISP event uuid: &lt;a href=&quot;https://mispmy.rectifyq.com/events/view/c99cb7b0-3736-4cab-b7b5-3b1b4d769179&quot; class=&quot;external&quot;&gt;c99cb7b0-3736-4cab-b7b5-3b1b4d769179&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2 id=&quot;indicator-of-compromise-iocs&quot;&gt;Indicator of Compromise (IoCs)&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#indicator-of-compromise-iocs&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;pre&gt;&lt;code&gt;type,value,comment
ip-dst, 142.251.143.97, &#039;&#039;
url, http://bantuantngmalaysia18.blogspot.com/, &#039;&#039;
hostname, bantuantngmalaysia18.blogspot.com, &#039;&#039;

&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Full IOCs available in Rectifyq’s &lt;a href=&quot;https://mispmy.rectifyq.com/events/view/c99cb7b0-3736-4cab-b7b5-3b1b4d769179&quot; class=&quot;external&quot;&gt;MISP&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt; ]]></description>
    <pubDate>Thu, 12 Mar 2026 00:00:00 GMT</pubDate>
  </item><item>
    <title>2026-03-11 PhishHuntMY] Bantuan Laptop eMadani Phishing Analysis</title>
    <link>https://rectifyq.com/MY-Threat-Landscape/threat-lists/4f13ed69-7e1b-42f7-b8a4-8a47116ab229</link>
    <guid>https://rectifyq.com/MY-Threat-Landscape/threat-lists/4f13ed69-7e1b-42f7-b8a4-8a47116ab229</guid>
    <description><![CDATA[ &lt;p&gt;📃Title: PhishHuntMY] Bantuan Laptop eMadani Phishing Analysis&lt;br&gt;
📅Date: 2026-03-11&lt;br&gt;
🔗References:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://shrouded-brake-a7f.notion.site/Bantuan-Laptop-eMadani-Phishing-Analysis-320002229ba780278300f55f5b06adb1&quot; class=&quot;external&quot;&gt;https://shrouded-brake-a7f.notion.site/Bantuan-Laptop-eMadani-Phishing-Analysis-320002229ba780278300f55f5b06adb1&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;🔖Rectifyq Taxonomies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;relevancy: 🔴 Highly Relevant&lt;/li&gt;
&lt;li&gt;category: &lt;a href=&quot;../.././../tags/⚔Threat&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/⚔Threat&quot;&gt;⚔Threat&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;sub-category: &lt;a href=&quot;../.././../tags/campaign-analysis&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/campaign-analysis&quot;&gt;campaign-analysis&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;target: &lt;a href=&quot;../.././../tags/broad-based&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/broad-based&quot;&gt;broad-based&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;MY-relevancy: &lt;a href=&quot;../.././../tags/relevant&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/relevant&quot;&gt;relevant&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;🔖MISP Galaxies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;target-information=“Malaysia”&lt;/li&gt;
&lt;li&gt;country=“indonesia”&lt;/li&gt;
&lt;li&gt;online-service=“b0c71d51-34fd-47b5-9eb4-dd406ffc607f”&lt;/li&gt;
&lt;li&gt;mitre-attack-pattern=[]&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;MISP event uuid: &lt;a href=&quot;https://mispmy.rectifyq.com/events/view/4f13ed69-7e1b-42f7-b8a4-8a47116ab229&quot; class=&quot;external&quot;&gt;4f13ed69-7e1b-42f7-b8a4-8a47116ab229&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2 id=&quot;indicator-of-compromise-iocs&quot;&gt;Indicator of Compromise (IoCs)&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#indicator-of-compromise-iocs&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;pre&gt;&lt;code&gt;type,value,comment
domain, percumaa477.com, &#039;Phishing Domain&#039;
hostname, bantuan-laptop.percumaa477.com, &#039;Phishing Subdomain&#039;
url, https://bantuan-laptop.percumaa477.com/, &#039;Phishing URL&#039;

&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Full IOCs available in Rectifyq’s &lt;a href=&quot;https://mispmy.rectifyq.com/events/view/4f13ed69-7e1b-42f7-b8a4-8a47116ab229&quot; class=&quot;external&quot;&gt;MISP&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt; ]]></description>
    <pubDate>Wed, 11 Mar 2026 00:00:00 GMT</pubDate>
  </item><item>
    <title>2026-03-10 PhishHuntMY] Touch ‘n Go / Malaysia Madani Scam QR Phishing analysis!</title>
    <link>https://rectifyq.com/MY-Threat-Landscape/threat-lists/5655b3a1-9dac-4fe3-9da0-4f637ca9206d</link>
    <guid>https://rectifyq.com/MY-Threat-Landscape/threat-lists/5655b3a1-9dac-4fe3-9da0-4f637ca9206d</guid>
    <description><![CDATA[ &lt;p&gt;📃Title: PhishHuntMY] Touch ‘n Go / Malaysia Madani Scam QR Phishing analysis!&lt;br&gt;
📅Date: 2026-03-10&lt;br&gt;
🔗References:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://171k.my/2026/03/10/tngmadaniphishing/&quot; class=&quot;external&quot;&gt;https://171k.my/2026/03/10/tngmadaniphishing/&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;🔖Rectifyq Taxonomies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;relevancy: 🔴 Highly Relevant&lt;/li&gt;
&lt;li&gt;category: &lt;a href=&quot;../.././../tags/⚔Threat&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/⚔Threat&quot;&gt;⚔Threat&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;sub-category: &lt;a href=&quot;../.././../tags/campaign-analysis&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/campaign-analysis&quot;&gt;campaign-analysis&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;target: &lt;a href=&quot;../.././../tags/broad-based&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/broad-based&quot;&gt;broad-based&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;MY-relevancy: &lt;a href=&quot;../.././../tags/relevant&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/relevant&quot;&gt;relevant&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;🔖MISP Galaxies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;target-information=“Malaysia”&lt;/li&gt;
&lt;li&gt;country=“azerbaijan”&lt;/li&gt;
&lt;li&gt;country=“indonesia”&lt;/li&gt;
&lt;li&gt;online-service=“b0c71d51-34fd-47b5-9eb4-dd406ffc607f”&lt;/li&gt;
&lt;li&gt;mitre-attack-pattern=[]&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;MISP event uuid: &lt;a href=&quot;https://mispmy.rectifyq.com/events/view/5655b3a1-9dac-4fe3-9da0-4f637ca9206d&quot; class=&quot;external&quot;&gt;5655b3a1-9dac-4fe3-9da0-4f637ca9206d&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2 id=&quot;indicator-of-compromise-iocs&quot;&gt;Indicator of Compromise (IoCs)&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#indicator-of-compromise-iocs&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;pre&gt;&lt;code&gt;type,value,comment
url, https://bantuan-tng-inst.aply-gov.online/ap/, &#039;&#039;
domain, aply-gov.online, &#039;&#039;
hostname, bantuan-tng-inst.aply-gov.online, &#039;&#039;
url, https://bantuan-tng-inst.aply-gov.online/ap/gateway.php?path=/generate-session, &#039;Admin Panel&#039;
url, https://bantuan-tng-inst.aply-gov.online/ap/setting.php, &#039;Config File&#039;

&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Full IOCs available in Rectifyq’s &lt;a href=&quot;https://mispmy.rectifyq.com/events/view/5655b3a1-9dac-4fe3-9da0-4f637ca9206d&quot; class=&quot;external&quot;&gt;MISP&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt; ]]></description>
    <pubDate>Tue, 10 Mar 2026 00:00:00 GMT</pubDate>
  </item><item>
    <title>2026-03-09 PhishHuntMY] Phishing Page Semakan Tunai Rahmah</title>
    <link>https://rectifyq.com/MY-Threat-Landscape/threat-lists/3414f3d9-78e7-4c88-898e-7f39db6f7b68</link>
    <guid>https://rectifyq.com/MY-Threat-Landscape/threat-lists/3414f3d9-78e7-4c88-898e-7f39db6f7b68</guid>
    <description><![CDATA[ &lt;p&gt;📃Title: PhishHuntMY] Phishing Page Semakan Tunai Rahmah&lt;br&gt;
📅Date: 2026-03-09&lt;br&gt;
🔗References:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://ayiezola.github.io/2026-03-09-Phishing-Page-Semakan-Tunai-Rahmah/&quot; class=&quot;external&quot;&gt;https://ayiezola.github.io/2026-03-09-Phishing-Page-Semakan-Tunai-Rahmah/&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;🔖Rectifyq Taxonomies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;relevancy: 🔴 Highly Relevant&lt;/li&gt;
&lt;li&gt;category: &lt;a href=&quot;../.././../tags/⚔Threat&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/⚔Threat&quot;&gt;⚔Threat&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;sub-category: &lt;a href=&quot;../.././../tags/campaign-analysis&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/campaign-analysis&quot;&gt;campaign-analysis&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;target: &lt;a href=&quot;../.././../tags/broad-based&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/broad-based&quot;&gt;broad-based&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;MY-relevancy: &lt;a href=&quot;../.././../tags/relevant&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/relevant&quot;&gt;relevant&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;🔖MISP Galaxies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;target-information=“Malaysia”&lt;/li&gt;
&lt;li&gt;online-service=“b0c71d51-34fd-47b5-9eb4-dd406ffc607f”&lt;/li&gt;
&lt;li&gt;mitre-attack-pattern=[]&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;MISP event uuid: &lt;a href=&quot;https://mispmy.rectifyq.com/events/view/3414f3d9-78e7-4c88-898e-7f39db6f7b68&quot; class=&quot;external&quot;&gt;3414f3d9-78e7-4c88-898e-7f39db6f7b68&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2 id=&quot;indicator-of-compromise-iocs&quot;&gt;Indicator of Compromise (IoCs)&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#indicator-of-compromise-iocs&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;pre&gt;&lt;code&gt;type,value,comment
url, https://bantuanstr.infopublic.my.id/e/, &#039;Primary Phishing URL&#039;
hostname, berjaya66.my.id, &#039;C2 Backend&#039;

&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Full IOCs available in Rectifyq’s &lt;a href=&quot;https://mispmy.rectifyq.com/events/view/3414f3d9-78e7-4c88-898e-7f39db6f7b68&quot; class=&quot;external&quot;&gt;MISP&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt; ]]></description>
    <pubDate>Mon, 09 Mar 2026 00:00:00 GMT</pubDate>
  </item><item>
    <title>2026-03-07 PhishHuntMY] How a Fake eWallet Aid Page Steals Your Telegram Account</title>
    <link>https://rectifyq.com/MY-Threat-Landscape/threat-lists/d5db54fc-c17c-41dd-bf0e-051090d68e97</link>
    <guid>https://rectifyq.com/MY-Threat-Landscape/threat-lists/d5db54fc-c17c-41dd-bf0e-051090d68e97</guid>
    <description><![CDATA[ &lt;p&gt;📃Title: PhishHuntMY] How a Fake eWallet Aid Page Steals Your Telegram Account&lt;br&gt;
📅Date: 2026-03-07&lt;br&gt;
🔗References:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://badrulmunir.com/posts/fake-ewallet-my/&quot; class=&quot;external&quot;&gt;https://badrulmunir.com/posts/fake-ewallet-my/&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;🔖Rectifyq Taxonomies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;relevancy: 🔴 Highly Relevant&lt;/li&gt;
&lt;li&gt;category: &lt;a href=&quot;../.././../tags/⚔Threat&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/⚔Threat&quot;&gt;⚔Threat&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;sub-category: &lt;a href=&quot;../.././../tags/campaign-analysis&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/campaign-analysis&quot;&gt;campaign-analysis&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;target: &lt;a href=&quot;../.././../tags/broad-based&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/broad-based&quot;&gt;broad-based&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;MY-relevancy: &lt;a href=&quot;../.././../tags/relevant&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/relevant&quot;&gt;relevant&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;🔖MISP Galaxies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;target-information=“Malaysia”&lt;/li&gt;
&lt;li&gt;online-service=“b0c71d51-34fd-47b5-9eb4-dd406ffc607f”&lt;/li&gt;
&lt;li&gt;mitre-attack-pattern=[‘T1555.003’, ‘T1589’, ‘T1656’, ‘T1036’, ‘T1027’, ‘T1598’, ‘T1566.002’]&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;MISP event uuid: &lt;a href=&quot;https://mispmy.rectifyq.com/events/view/d5db54fc-c17c-41dd-bf0e-051090d68e97&quot; class=&quot;external&quot;&gt;d5db54fc-c17c-41dd-bf0e-051090d68e97&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2 id=&quot;indicator-of-compromise-iocs&quot;&gt;Indicator of Compromise (IoCs)&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#indicator-of-compromise-iocs&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;pre&gt;&lt;code&gt;type,value,comment
sha256, aea32c34b4c7f43766908856ff2ae7e5c1d75c290eb3b4ae37fb60b9a23c486f, &#039;No sample in VT\r\nLast check:17/03/2026 No sample in VT\r\nLast check:20/03/2026&#039;
url, https://bantuan-ewallet-tng-my65mo.ask88sx.my.id/, &#039;&#039;
url, https://bantuan-tng-ewallet-my-009k.faj8.my.id/, &#039;&#039;
url, https://new-link-update-nhcr52.dwwb41.my.id/, &#039;&#039;
url, https://tng-ewallet-chc5x7.uncategori-v3.my.id/, &#039;&#039;
url, https://tng-ewallet-ch7v1.qx0-b5.my.id/, &#039;&#039;
url, https://tng-ewallet-xvcy8.fast-x9.my.id/, &#039;&#039;
url, https://tng-ewallet-gxk7v3.zx88c.my.id/, &#039;&#039;
url, https://tbg-ewallet-xdt42.qif7.my.id/, &#039;&#039;
url, https://tng-ewallet-chx9m.axf66.my.id/, &#039;&#039;
url, https://tng-ewallet-ex73f.afc88v.my.id/, &#039;&#039;
url, https://tng-digital-bc882x.qx0-b5.my.id/, &#039;&#039;
url, https://bantuan-ewallet-2026.zx88c.my.id/, &#039;&#039;
url, https://tng-digital-cfx008.exc-k7.my.id/, &#039;&#039;
url, https://tng-ewalet2026-vx9.regis-x8.my.id/, &#039;&#039;
url, https://bantuan-tng-ewallet-fj2z8.xxx55.my.id/, &#039;&#039;
url, https://tng-ewallet-ic5s80.zx88.my.id/, &#039;&#039;
url, https://bantuan-tng-ewallet-ckf772f.vip-66dx.my.id/, &#039;&#039;
url, https://bantuan-tng-ewallet-dgp85.saft88.my.id/, &#039;&#039;
url, https://bantuan-ewallet-tng-2025-my76c08.gvw08d.my.id/, &#039;&#039;
url, http://bantuan-ewallet-tng-2025-my76c08.gvw08d.my.id/, &#039;&#039;

&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Full IOCs available in Rectifyq’s &lt;a href=&quot;https://mispmy.rectifyq.com/events/view/d5db54fc-c17c-41dd-bf0e-051090d68e97&quot; class=&quot;external&quot;&gt;MISP&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt; ]]></description>
    <pubDate>Sat, 07 Mar 2026 00:00:00 GMT</pubDate>
  </item><item>
    <title>2026-03-03 Silver Dragon Targets Organizations in Southeast Asia and Europe</title>
    <link>https://rectifyq.com/MY-Threat-Landscape/threat-lists/2e319e49-6c2f-442b-ba50-ae7d2e43ddb4</link>
    <guid>https://rectifyq.com/MY-Threat-Landscape/threat-lists/2e319e49-6c2f-442b-ba50-ae7d2e43ddb4</guid>
    <description><![CDATA[ &lt;p&gt;📃Title: Silver Dragon Targets Organizations in Southeast Asia and Europe&lt;br&gt;
📅Date: 2026-03-03&lt;br&gt;
🔗References:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://research.checkpoint.com/2026/silver-dragon-targets-organizations-in-southeast-asia-and-europe/&quot; class=&quot;external&quot;&gt;https://research.checkpoint.com/2026/silver-dragon-targets-organizations-in-southeast-asia-and-europe/&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;blockquote class=&quot;callout abstract&quot; data-callout=&quot;abstract&quot;&gt;
&lt;div class=&quot;callout-title&quot;&gt;
                  &lt;div class=&quot;callout-icon&quot;&gt;&lt;/div&gt;
                  &lt;div class=&quot;callout-title-inner&quot;&gt;&lt;p&gt; &lt;strong&gt;Description&lt;/strong&gt;&lt;/p&gt;&lt;/div&gt;
                  
                &lt;/div&gt;
&lt;div class=&quot;callout-content&quot;&gt;
&lt;p&gt;Check Point Research has identified a Chinese-nexus advanced persistent threat group named Silver Dragon, targeting organizations in Southeast Asia and Europe since mid-2024. The group, likely operating under APT41, exploits public-facing servers and uses phishing emails for initial access. They deploy custom tools including GearDoor, a backdoor using Google Drive for command and control, SSHcmd for remote access, and SilverScreen for covert screen monitoring. Silver Dragon primarily focuses on government entities, utilizing Cobalt Strike beacons and DNS tunneling for communication. The group’s sophisticated tactics and evolving toolkit demonstrate a well-resourced and adaptable threat actor.&lt;/p&gt;
&lt;/div&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;img src=&quot;https://raw.githubusercontent.com/rectifyq/Collections/refs/heads/main/Diamond-Models/2026/260307-SilverDragon/260307-SilverDragon.png&quot; alt=&quot;&quot;&gt;&lt;/p&gt;
&lt;p&gt;🔖Rectifyq Taxonomies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;relevancy: 🔴 Highly Relevant&lt;/li&gt;
&lt;li&gt;category: &lt;a href=&quot;../.././../tags/⚔Threat&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/⚔Threat&quot;&gt;⚔Threat&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;sub-category: &lt;a href=&quot;../.././../tags/TA-profile&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/TA-profile&quot;&gt;TA-profile&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;target: &lt;a href=&quot;../.././../tags/broad-based&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/broad-based&quot;&gt;broad-based&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;MY-relevancy: &lt;a href=&quot;../.././../tags/relevant&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/relevant&quot;&gt;relevant&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;action-taken: &lt;a href=&quot;../.././../tags/diamond-model&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/diamond-model&quot;&gt;diamond-model&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;🔖MISP Galaxies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;producer= &lt;a href=&quot;../.././../tags/Check-Point&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/Check-Point&quot;&gt;Check-Point&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;region=“035 - South-eastern Asia”&lt;/li&gt;
&lt;li&gt;threat-actor= &lt;a href=&quot;../.././../tags/APT41&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/APT41&quot;&gt;APT41&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;target-information=“Italy”&lt;/li&gt;
&lt;li&gt;target-information=“Japan”&lt;/li&gt;
&lt;li&gt;target-information=“Kazakhstan”&lt;/li&gt;
&lt;li&gt;target-information=“Malaysia”&lt;/li&gt;
&lt;li&gt;target-information=“Myanmar”&lt;/li&gt;
&lt;li&gt;target-information=“Poland”&lt;/li&gt;
&lt;li&gt;target-information=“Russia”&lt;/li&gt;
&lt;li&gt;online-service=“4a9eade3-5de4-4a80-9c7a-ba3a7566e130”&lt;/li&gt;
&lt;li&gt;malpedia=“Cobalt Strike”&lt;/li&gt;
&lt;li&gt;sector=“Government, Administration”&lt;/li&gt;
&lt;li&gt;mitre-attack-pattern=[‘T1113’, ‘T1033’, ‘T1132.001’, ‘T1071.004’, ‘T1036.005’, ‘T1021.004’, ‘T1082’, ‘T1053’, ‘T1055’, ‘T1016’, ‘T1083’, ‘T1036.004’, ‘T1049’, ‘T1057’, ‘T1059.001’, ‘T1078’, ‘T1102.002’, ‘T1001.003’, ‘T1059.003’, ‘T1105’]&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;MISP event uuid: &lt;a href=&quot;https://mispmy.rectifyq.com/events/view/2e319e49-6c2f-442b-ba50-ae7d2e43ddb4&quot; class=&quot;external&quot;&gt;2e319e49-6c2f-442b-ba50-ae7d2e43ddb4&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2 id=&quot;indicator-of-compromise-iocs&quot;&gt;Indicator of Compromise (IoCs)&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#indicator-of-compromise-iocs&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;pre&gt;&lt;code&gt;type,value,comment
md5, 876e6bca4c322db479d00152a5c8231a, &#039;&#039;
md5, 00bd4de2bde0461accdd2e79279b08c2, &#039;&#039;
md5, 2edd53b59f01931888d9d237871aa808, &#039;&#039;
md5, 61bb113beecd0166ac2f2e8e027645fe, &#039;&#039;
md5, 9fd54246d78eacdb02d8d830a27f95bc, &#039;&#039;
md5, 0d1f1d68ae32ee8d51f8ec8f2676bfeb, &#039;&#039;
md5, e43f35f6cbb86a283bf2d8051d73b31c, &#039;&#039;
md5, 8ee654d826ca5243e2ed1bc4d07f86be, &#039;&#039;
md5, ae72b2c870eb5cb9e01183c3cd301c7c, &#039;&#039;
md5, 5f1928e8a644dab9fb294374362b045e, &#039;&#039;
md5, 791de86ffaf47666e3dcf26c8f943f25, &#039;&#039;
md5, ccc1631e700763c4c31cd7540f2bf608, &#039;&#039;
md5, b0bae77341da2871b8354cbe22b39cf6, &#039;&#039;
md5, 7728646e661df092f1e71735a711f05a, &#039;&#039;
md5, 2a7042102cae68fce699e33cd78d847d, &#039;&#039;
md5, 2524f644a0d731c252079870ec7c882e, &#039;&#039;
md5, cbdd29728b03f1da10e3dafd1bc5df30, &#039;&#039;
md5, 1c66d075c3df801f92a24d99b3f69de3, &#039;&#039;
md5, a5c9a0a0f09683ccdcc56b9ff284162a, &#039;&#039;
md5, ae98807d74d87edfc35140d507420874, &#039;&#039;
md5, 14e9ef06501f14449e56fcb3471273ed, &#039;&#039;
md5, 658a1cb18ad9a3450093ade1ef29f94e, &#039;&#039;
md5, e4b79d14ebbca9240e9d763ce90fe0e6, &#039;&#039;
md5, e3dcb68059e854af3b99bd4d1dc02e53, &#039;&#039;
md5, a53331b3562f12c84cb59c24d7641251, &#039;&#039;
md5, b2f9bf291261499f60fbaaaa2b50a4ae, &#039;&#039;
md5, 5a654a8a336156d637abd8cedc2bb977, &#039;&#039;
md5, da1ac5b2ee326a66bfb233c89c1f1aac, &#039;&#039;
md5, 0012f9f7bc6db810618fb914bfa87171, &#039;&#039;
md5, 9d3f61dcaba90db2ede1c1906a80ace2, &#039;No sample in VT\r\nLast check:06/03/2026&#039;
sha256, 16b9a7358be88632378ba20ba1430786f3b844694b1f876211ecdbecf5cccbc2, &#039;No sample in VT\r\nLast check:06/03/2026&#039;
sha256, 37b485ed8d150d022c41e5e307b8c54c34ef806625b44d0c940b18be7d5b29ce, &#039;No sample in VT\r\nLast check:06/03/2026&#039;
domain, ampolice.org, &#039;&#039;
domain, bigflx.net, &#039;&#039;
domain, copilot-cloud.net, &#039;&#039;
domain, exchange4study.com, &#039;&#039;
domain, mindssurpass.com, &#039;&#039;
domain, oicm.org, &#039;&#039;
domain, onedriveconsole.com, &#039;&#039;
domain, protacik.com, &#039;&#039;
domain, revitpourtous.com, &#039;&#039;
domain, splunkds.com, &#039;&#039;
domain, wikipedla.blog, &#039;&#039;
domain, zhydromet.com, &#039;&#039;
hostname, ns1.exchange4study.com, &#039;&#039;
hostname, ns1.onedriveconsole.com, &#039;&#039;
hostname, ns2.onedriveconsole.com, &#039;&#039;
hostname, drivefrontend.pa-clients.workers.dev, &#039;&#039;

&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Full IOCs available in Rectifyq’s &lt;a href=&quot;https://mispmy.rectifyq.com/events/view/2e319e49-6c2f-442b-ba50-ae7d2e43ddb4&quot; class=&quot;external&quot;&gt;MISP&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt; ]]></description>
    <pubDate>Tue, 03 Mar 2026 00:00:00 GMT</pubDate>
  </item><item>
    <title>2026-02-28 Analysis of the “Kongsi Rezeki” on Threads social media QR-phishing campaign</title>
    <link>https://rectifyq.com/MY-Threat-Landscape/threat-lists/0b6037c8-d75d-4ba2-a378-7e0a2757a051</link>
    <guid>https://rectifyq.com/MY-Threat-Landscape/threat-lists/0b6037c8-d75d-4ba2-a378-7e0a2757a051</guid>
    <description><![CDATA[ &lt;p&gt;📃Title: Analysis of the “Kongsi Rezeki” on Threads social media QR-phishing campaign&lt;br&gt;
📅Date: 2026-02-28&lt;br&gt;
🔗References:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.notion.so/3ch0/Analysis-of-the-Kongsi-Rezeki-on-Threads-social-media-QR-phishing-campaign-314d05a447d5809abc48e44233792978&quot; class=&quot;external&quot;&gt;https://www.notion.so/3ch0/Analysis-of-the-Kongsi-Rezeki-on-Threads-social-media-QR-phishing-campaign-314d05a447d5809abc48e44233792978&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;🔖Rectifyq Taxonomies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;relevancy: 🔴 Highly Relevant&lt;/li&gt;
&lt;li&gt;category: &lt;a href=&quot;../.././../tags/⚔Threat&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/⚔Threat&quot;&gt;⚔Threat&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;sub-category: &lt;a href=&quot;../.././../tags/campaign-analysis&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/campaign-analysis&quot;&gt;campaign-analysis&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;target: &lt;a href=&quot;../.././../tags/broad-based&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/broad-based&quot;&gt;broad-based&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;MY-relevancy: &lt;a href=&quot;../.././../tags/relevant&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/relevant&quot;&gt;relevant&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;🔖MISP Galaxies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;target-information=“Malaysia”&lt;/li&gt;
&lt;li&gt;mitre-attack-pattern=[‘T1531’, ‘T1588.004’, ‘T1583.001’, ‘T1041’, ‘T1111’, ‘T1566.002’, ‘T1598.003’]&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;MISP event uuid: &lt;a href=&quot;https://mispmy.rectifyq.com/events/view/0b6037c8-d75d-4ba2-a378-7e0a2757a051&quot; class=&quot;external&quot;&gt;0b6037c8-d75d-4ba2-a378-7e0a2757a051&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2 id=&quot;indicator-of-compromise-iocs&quot;&gt;Indicator of Compromise (IoCs)&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#indicator-of-compromise-iocs&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;pre&gt;&lt;code&gt;type,value,comment
url, https://tngduitraya14.gbdjw.my/, &#039;Landing page after QR scan.&#039;
url, https://tngduitraya14.gbdjw.my/go/, &#039;Data collection page.&#039;
url, https://tngduitraya14.gbdjw.my/API/index.php, &#039;C2 server for data exfiltration.&#039;
domain, gbdjw.my, &#039;Malicious Domain.&#039;
hostname, money.gbdjw.my, &#039;&#039;
hostname, tngduitraya.gbdjw.my, &#039;&#039;
hostname, moneypocket.gbdjw.my, &#039;&#039;

&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Full IOCs available in Rectifyq’s &lt;a href=&quot;https://mispmy.rectifyq.com/events/view/0b6037c8-d75d-4ba2-a378-7e0a2757a051&quot; class=&quot;external&quot;&gt;MISP&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt; ]]></description>
    <pubDate>Sat, 28 Feb 2026 00:00:00 GMT</pubDate>
  </item><item>
    <title>2026-02-23 Chronology of MuddyWater APT Attacks Targeting the Middle East</title>
    <link>https://rectifyq.com/MY-Threat-Landscape/threat-lists/902d955b-e5f7-4bca-948e-857e6ab0017c</link>
    <guid>https://rectifyq.com/MY-Threat-Landscape/threat-lists/902d955b-e5f7-4bca-948e-857e6ab0017c</guid>
    <description><![CDATA[ &lt;p&gt;📃Title: Chronology of MuddyWater APT Attacks Targeting the Middle East&lt;br&gt;
📅Date: 2026-02-23&lt;br&gt;
🔗References:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.genians.co.kr/en/blog/threat_intelligence/muddywater-apt?hs_amp=true&quot; class=&quot;external&quot;&gt;https://www.genians.co.kr/en/blog/threat_intelligence/muddywater-apt?hs_amp=true&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;blockquote class=&quot;callout abstract&quot; data-callout=&quot;abstract&quot;&gt;
&lt;div class=&quot;callout-title&quot;&gt;
                  &lt;div class=&quot;callout-icon&quot;&gt;&lt;/div&gt;
                  &lt;div class=&quot;callout-title-inner&quot;&gt;&lt;p&gt; &lt;strong&gt;Description&lt;/strong&gt;&lt;/p&gt;&lt;/div&gt;
                  
                &lt;/div&gt;
&lt;div class=&quot;callout-content&quot;&gt;
&lt;p&gt;This report analyzes the recent activities of the MuddyWater APT group, which primarily targets organizations in the Middle East. The group employs sophisticated spear-phishing techniques, often impersonating legitimate entities and using malicious documents to gain initial access. Their attacks focus on long-term infiltration and intelligence gathering rather than immediate disruption. The report details several attack cases from 2019 to 2026, highlighting the group’s evolving tactics, including the abuse of legitimate remote management tools and the use of Rust-based malware. The analysis emphasizes the importance of endpoint detection and response (EDR) solutions in identifying and mitigating these threats, as traditional perimeter-based security measures prove insufficient against such advanced persistent threats.&lt;/p&gt;
&lt;/div&gt;
&lt;/blockquote&gt;
&lt;p&gt;🔖Rectifyq Taxonomies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;relevancy: 🔴 Highly Relevant&lt;/li&gt;
&lt;li&gt;category: &lt;a href=&quot;../.././../tags/⚔Threat&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/⚔Threat&quot;&gt;⚔Threat&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;sub-category: &lt;a href=&quot;../.././../tags/campaign-analysis&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/campaign-analysis&quot;&gt;campaign-analysis&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;topic: &lt;a href=&quot;../.././../tags/geopolitical&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/geopolitical&quot;&gt;geopolitical&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;target: &lt;a href=&quot;../.././../tags/broad-based&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/broad-based&quot;&gt;broad-based&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;MY-relevancy: &lt;a href=&quot;../.././../tags/relevant&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/relevant&quot;&gt;relevant&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;🔖MISP Galaxies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;target-information=“Egypt”&lt;/li&gt;
&lt;li&gt;target-information=“Iraq”&lt;/li&gt;
&lt;li&gt;target-information=“Israel”&lt;/li&gt;
&lt;li&gt;target-information=“Jordan”&lt;/li&gt;
&lt;li&gt;target-information=“Malaysia”&lt;/li&gt;
&lt;li&gt;target-information=“Oman”&lt;/li&gt;
&lt;li&gt;target-information=“Turkmenistan”&lt;/li&gt;
&lt;li&gt;threat-actor= &lt;a href=&quot;../.././../tags/MuddyWater&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/MuddyWater&quot;&gt;MuddyWater&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;mitre-attack-pattern=[‘T1133’, ‘T1071’, ‘T1190’, ‘T1583.001’, ‘T1036’, ‘T1588.001’, ‘T1102’, ‘T1204’, ‘T1059.001’, ‘T1547.001’, ‘T1199’, ‘T1588.002’, ‘T1566’, ‘T1078’, ‘T1027’, ‘T1213’, ‘T1105’, ‘T1569.002’]&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;MISP event uuid: &lt;a href=&quot;https://mispmy.rectifyq.com/events/view/902d955b-e5f7-4bca-948e-857e6ab0017c&quot; class=&quot;external&quot;&gt;902d955b-e5f7-4bca-948e-857e6ab0017c&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2 id=&quot;indicator-of-compromise-iocs&quot;&gt;Indicator of Compromise (IoCs)&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#indicator-of-compromise-iocs&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;pre&gt;&lt;code&gt;type,value,comment
md5, 0a95918fd6000a69b8a70609f93e910f, &#039;&#039;
md5, 1f280f51eeb6cf895fe80082ce725841, &#039;&#039;
md5, 244a4f81cff4a8dc5872628a40713735, &#039;&#039;
md5, 3a95186019af1943a0ea0f8eb07a288f, &#039;&#039;
md5, 4055d8b5c2e909f5db8b75a5750a7005, &#039;&#039;
md5, 43be8a405a7f57cf9f910d829c521b21, &#039;&#039;
md5, 4c169dde3bc184c42ca7a712a61c6f3c, &#039;&#039;
md5, 74e75830252220cbbe7e3adec4340d2d, &#039;&#039;
md5, 75060f5394b72421c0d8f81f79931aa9, &#039;&#039;
md5, 7da3d206519086f2725494b3ab095fbb, &#039;&#039;
md5, 806adc79e7ea3be50ef1d3974a16b7fb, &#039;&#039;
md5, 809334c0b55009c5a50f37e4eec63c43, &#039;&#039;
md5, 95d9e6c262632abe004c4693a71eaced, &#039;&#039;
md5, aba760ec55fdeccb35adb068443feb89, &#039;&#039;
md5, b181ecbb7394e3b1394a8c97af65b7e2, &#039;&#039;
md5, c381c2cb8fdd6acf1636280b9424f573, &#039;&#039;
md5, c89671f994af65677aa48b699a01fe9d, &#039;&#039;
md5, e2d6031afd81bf3b6a44de4d0b039055, &#039;&#039;
md5, f1c935ce028022ab2a495eae83adacc6, &#039;&#039;
md5, f6a4c531e92cbdd5ffac75c76939d7f3, &#039;&#039;
md5, 0873ce3db84b79da935f71df3d6c8e6d, &#039;&#039;
md5, 68352f61da6e3236c4fe760997a981ea, &#039;&#039;
md5, 242098c3e87822bffa7c337987065fbe, &#039;&#039;
md5, aaa9db79b5d6ba319e24e6180a7935d6, &#039;&#039;
md5, b9a67ffb81420e68f9e5607cc200604a, &#039;&#039;
md5, c5c0829df294cc4fd701df5d5c55718f, &#039;&#039;
md5, c478e472f6223e7ee92cff8b459e55e2, &#039;&#039;
md5, cdeb7abfc7775c63745135431272dda3, &#039;&#039;
md5, ef6ec560efd05d21976a6fd3f489e206, &#039;&#039;
md5, f06e30dee8629e951cefa73373fdef9d, &#039;&#039;
md5, f97650ede0c39a29b0b5c5472f685d11, &#039;&#039;
md5, 1e9a4e774b61acc8a6b35ee50417e661, &#039;&#039;
md5, 2ed6ebaa28a9bfccc59c6e89a8990631, &#039;&#039;
md5, 3ab16bd1c339fd0727be650104b74dd1, &#039;&#039;
md5, 6d7ce5b03fe61683229c29a859505163, &#039;&#039;
md5, 23d99f912f2491749b89e4fd337273bc, &#039;&#039;
md5, 64fc017a451ef273dcacdf6c099031f3, &#039;&#039;
md5, 93be13bbcad30440a0d0ef3868d67003, &#039;&#039;
md5, 96d5a7e0e75654c444cb1a915c666ac8, &#039;&#039;
ip-dst, 159.198.66.153, &#039;&#039;
ip-dst, 159.198.68.25, &#039;&#039;
domain, screenai.online, &#039;&#039;
domain, stratioai.org, &#039;&#039;
hostname, nomercys.it.com, &#039;&#039;

&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Full IOCs available in Rectifyq’s &lt;a href=&quot;https://mispmy.rectifyq.com/events/view/902d955b-e5f7-4bca-948e-857e6ab0017c&quot; class=&quot;external&quot;&gt;MISP&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt; ]]></description>
    <pubDate>Mon, 23 Feb 2026 00:00:00 GMT</pubDate>
  </item>
    </channel>
  </rss>