<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
    <channel>
      <title>Rectifyq</title>
      <link>https://rectifyq.com</link>
      <description>Last 20 notes on Rectifyq</description>
      <generator>Quartz -- quartz.jzhao.xyz</generator>
      <item>
    <title>Get access to Rectifyq&#039;s MISP</title>
    <link>https://rectifyq.com/Threat-Intelligence-Platform-(TIP)/access-to-misp</link>
    <guid>https://rectifyq.com/Threat-Intelligence-Platform-(TIP)/access-to-misp</guid>
    <description><![CDATA[ &lt;p&gt;Application to get access to Rectifyq’s TIP (MISP) is now open.
&lt;a href=&quot;https://forms.gle/b57aaQixjdS5CPTEA&quot; class=&quot;external&quot;&gt;https://forms.gle/b57aaQixjdS5CPTEA&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Courses to be released soon.🙏&lt;/p&gt;
&lt;h2 id=&quot;role-cybervigilantes&quot;&gt;Role: Cybervigilantes&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#role-cybervigilantes&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;pre&gt;&lt;button class=&quot;expand-button&quot; aria-label=&quot;Expand mermaid diagram&quot; data-view-component&gt;&lt;svg width=&quot;16&quot; height=&quot;16&quot; viewBox=&quot;0 0 16 16&quot; fill=&quot;currentColor&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M3.72 3.72a.75.75 0 011.06 1.06L2.56 7h10.88l-2.22-2.22a.75.75 0 011.06-1.06l3.5 3.5a.75.75 0 010 1.06l-3.5 3.5a.75.75 0 11-1.06-1.06l2.22-2.22H2.56l2.22 2.22a.75.75 0 11-1.06 1.06l-3.5-3.5a.75.75 0 010-1.06l3.5-3.5z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/button&gt;&lt;code class=&quot;mermaid&quot; data-clipboard=&quot;&amp;#x22;flowchart LR\n    B1[Complete Rectifyq Course in Coursestack] --&gt; B2[Apply via Google Form]\n    B2 --&gt; B4[Post min 1 Article on Malaysia Threat Landscape on any platform]\n    B4 -- Checked Quarterly--&gt; B5{Requirement fulfilled &amp;#x26; inline with T&amp;#x26;C?}\n\n    B5 -- Yes --&gt; B6[Access MISP202X &amp;#x26; MISPMY]\n    B7 --&gt; B4\n    B6 --&gt; B7(TLP:CLEAR &amp;#x26; TLP:GREEN)\n\n    B5 -- No --&gt; B8[Account Disabled]\n    B8 --&gt; B2&amp;#x22;&quot;&gt;flowchart LR
    B1[Complete Rectifyq Course in Coursestack] --&gt; B2[Apply via Google Form]
    B2 --&gt; B4[Post min 1 Article on Malaysia Threat Landscape on any platform]
    B4 -- Checked Quarterly--&gt; B5{Requirement fulfilled &amp;#x26; inline with T&amp;#x26;C?}

    B5 -- Yes --&gt; B6[Access MISP202X &amp;#x26; MISPMY]
    B7 --&gt; B4
    B6 --&gt; B7(TLP:CLEAR &amp;#x26; TLP:GREEN)

    B5 -- No --&gt; B8[Account Disabled]
    B8 --&gt; B2
&lt;/code&gt;&lt;div id=&quot;mermaid-container&quot; role=&quot;dialog&quot;&gt;&lt;div id=&quot;mermaid-space&quot;&gt;&lt;div class=&quot;mermaid-content&quot;&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/pre&gt;
&lt;h2 id=&quot;role-cyberheroes&quot;&gt;Role: Cyberheroes&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#role-cyberheroes&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;pre&gt;&lt;button class=&quot;expand-button&quot; aria-label=&quot;Expand mermaid diagram&quot; data-view-component&gt;&lt;svg width=&quot;16&quot; height=&quot;16&quot; viewBox=&quot;0 0 16 16&quot; fill=&quot;currentColor&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M3.72 3.72a.75.75 0 011.06 1.06L2.56 7h10.88l-2.22-2.22a.75.75 0 011.06-1.06l3.5 3.5a.75.75 0 010 1.06l-3.5 3.5a.75.75 0 11-1.06-1.06l2.22-2.22H2.56l2.22 2.22a.75.75 0 11-1.06 1.06l-3.5-3.5a.75.75 0 010-1.06l3.5-3.5z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/button&gt;&lt;code class=&quot;mermaid&quot; data-clipboard=&quot;&amp;#x22;flowchart LR\n    C0[Currently Cybervigilantes Role] --&gt; C1[Continuous Contribution] \n    C1 --&gt; D{Vetting Process &amp;#x26; inline with T&amp;#x26;C}\n    C2[Proven Contribution Track Record]  --&gt; D\n    D -- Approved --&gt; C3[Access MISP202X &amp;#x26; MISPMY]\n    D -- Denied --&gt; R[Account Disabled]\n    C3 --&gt; C4(TLP:CLEAR, TLP:GREEN, &amp;#x26; TLP:AMBER)\n    C4 -- Checked Quarterly --&gt; D\n&amp;#x22;&quot;&gt;flowchart LR
    C0[Currently Cybervigilantes Role] --&gt; C1[Continuous Contribution] 
    C1 --&gt; D{Vetting Process &amp;#x26; inline with T&amp;#x26;C}
    C2[Proven Contribution Track Record]  --&gt; D
    D -- Approved --&gt; C3[Access MISP202X &amp;#x26; MISPMY]
    D -- Denied --&gt; R[Account Disabled]
    C3 --&gt; C4(TLP:CLEAR, TLP:GREEN, &amp;#x26; TLP:AMBER)
    C4 -- Checked Quarterly --&gt; D

&lt;/code&gt;&lt;div id=&quot;mermaid-container&quot; role=&quot;dialog&quot;&gt;&lt;div id=&quot;mermaid-space&quot;&gt;&lt;div class=&quot;mermaid-content&quot;&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/pre&gt; ]]></description>
    <pubDate>Wed, 18 Mar 2026 09:38:05 GMT</pubDate>
  </item><item>
    <title>Phish Hunt MY</title>
    <link>https://rectifyq.com/MY-Threat-Landscape/phishhuntmy</link>
    <guid>https://rectifyq.com/MY-Threat-Landscape/phishhuntmy</guid>
    <description><![CDATA[ &lt;h2 id=&quot;background&quot;&gt;Background&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#background&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Phishing scams—like Telegram takeovers, fake APK wedding invites, and Bantuan Kerajaan fakesite—have been around for ages. Most IT pros and cybersecurity experts tend to ignore them, thinking they’re “uninteresting” or wondering how anyone could still fall for them. But the fact that these scams are still happening means they work. Even if they don’t catch everyone, they only need to hit the right victim for the financial impact to be devastating.&lt;/p&gt;
&lt;p&gt;A few things triggered me to organize this challenge. One was an article by Foxy about recent phishing campaigns, which reminded me of my own previous writing. Then, a “threat actor” actually had the nerve to post a phishing link right in the OWASP Malaysia WhatsApp group!😂 When KDJebat called for an advisory, it gave me an idea: why not create a challenge to push pros and students to actually analyze these campaigns?&lt;/p&gt;
&lt;p&gt;It’s a win-win. I get to learn from their findings, and they get to build their portfolios and potentially win prizes.&lt;/p&gt;
&lt;p&gt;So, a big shout out to Foxy and KDJebat for the inspiration! 🙌&lt;/p&gt;
&lt;h2 id=&quot;challenge-details&quot;&gt;Challenge Details&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#challenge-details&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;With the festive season approaching, scams impersonating local organizations, governments, and local e-wallets are on the rise. We’re looking for Phish Hunters and analysts to help map out these campaigns, warn the community, and get them taken down.&lt;/p&gt;
&lt;p&gt;🔍 How to Participate&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Identify&lt;/strong&gt;: Find an active phishing link or campaign (SMS, Email, Social Media) specifically targeting Malaysians.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Analyze&lt;/strong&gt;: Break down the infrastructure and TTP used by Threat Actor. Who is the registrar? Where is it hosted? Can you find the phishing kit etc? (Always use a sandbox/VM).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Report &amp;#x26; Post&lt;/strong&gt;: File a report with Google Safe Browsing or MyCERT (Cyber999) or any relevant parties. Then, share your findings on LinkedIn, X, Facebook, or your blog to educate others.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Submit&lt;/strong&gt;: Drop your analysis and post link in our entry form: [&lt;a href=&quot;https://forms.gle/ei6EqfBFsbtzdEJU9&quot; class=&quot;external&quot;&gt;https://forms.gle/ei6EqfBFsbtzdEJU9&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;] before 12 midnight of 15th March 2026
🏆 The Prizes (Touch ‘n Go e-Wallet Credit: Each category will win RM100)&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;We’re awarding two distinct types of hunters:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;The Apex Hunter (Technical Prize)&lt;/strong&gt;: For the most thorough technical breakdown. We’re looking for high-quality analysis—TTPs, indicators of compromise (IOCs), kit discovery, evidence of reporting and so on. Technical evaluation will be done on 12 noon of 16th March 2026; if you submitted your analysis but have some minor adjustment, please do so before this date.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;The Community Advocate (Engagement Prize)&lt;/strong&gt;: For the Rectifyq’s Linkedin repost (once you submitted your entry, we will repost it in our page) that gets the most Likes &amp;#x26; Shares. This is about making the warning go viral to prevent others from falling victim.
Counting date fort his prize will be on 12 noon of 18th March 2026. Do share with everyone your specific Rectifyq’s Linkedin repost for everyone to like and share.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Rule: To keep the rewards distributed, one participant cannot win both. If the top technical entry also has the highest engagement, the engagement prize will go to the next runner-up and/or student winner will be prioritized for the community advocate category.&lt;/p&gt;
&lt;h2 id=&quot;results-for-apex-hunter&quot;&gt;Results for Apex Hunter&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#results-for-apex-hunter&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;h3 id=&quot;2-champions---mohd-fazri--ahmad-nazif&quot;&gt;2 champions - Mohd Fazri &amp;#x26; Ahmad Nazif&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#2-champions---mohd-fazri--ahmad-nazif&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h3&gt;
&lt;blockquote class=&quot;callout abstract&quot; data-callout=&quot;abstract&quot;&gt;
&lt;div class=&quot;callout-title&quot;&gt;
                  &lt;div class=&quot;callout-icon&quot;&gt;&lt;/div&gt;
                  &lt;div class=&quot;callout-title-inner&quot;&gt;&lt;p&gt; &lt;strong&gt;Updates&lt;/strong&gt;&lt;/p&gt;&lt;/div&gt;
                  
                &lt;/div&gt;
&lt;div class=&quot;callout-content&quot;&gt;
&lt;p&gt;After another round of review and recalculation, the previously announced winner lost 1 point which resulted to a draw between Mohd Fazri &amp;#x26; Ahmad Nazif. Therefore, decision has been made to announce both as champion for this challenge with the accumulating of same score points. So, both won the duit raya!&lt;/p&gt;
&lt;/div&gt;
&lt;/blockquote&gt;
&lt;h3 id=&quot;below-are-the-top-5&quot;&gt;Below are the top 5:&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#below-are-the-top-5&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h3&gt;















































&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Article link&lt;/th&gt;&lt;th&gt;Category&lt;/th&gt;&lt;th&gt;Total Points&lt;/th&gt;&lt;th&gt;Extra points given&lt;/th&gt;&lt;th&gt;Room for improvement&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;a href=&quot;https://ayiezola.github.io/2026-03-09-Phishing-Page-Semakan-Tunai-Rahmah/&quot; class=&quot;external&quot;&gt;ayiezola&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Working Professional&lt;/td&gt;&lt;td&gt;26&lt;/td&gt;&lt;td&gt;Infection chain using AI/clean diagram, nuclei template, comparative analysis, sample of exfiltrated data&lt;/td&gt;&lt;td&gt;No Recommendation included, TTPs listed not using known framework such as MITRE ATT&amp;#x26;CK&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href=&quot;https://www.notion.so/How-Scammers-Stole-Telegram-Accounts-During-Ramadhan-2026-3211ea45347c80f19a61cbb0f570fc64&quot; class=&quot;external&quot;&gt;nazif&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Working Professional&lt;/td&gt;&lt;td&gt;26&lt;/td&gt;&lt;td&gt;Included Impact assessment and usage of PCAP analysis&lt;/td&gt;&lt;td&gt;No infection chain diagram included &amp;#x26; report format to be more concise and succinct&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href=&quot;https://171k.my/2026/03/10/tngmadaniphishing/&quot; class=&quot;external&quot;&gt;171k&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Student&lt;/td&gt;&lt;td&gt;25&lt;/td&gt;&lt;td&gt;Included TA assessment and TA’s opsec fails&lt;/td&gt;&lt;td&gt;No Action taken (e.g. report to google safe browsing) included, TTPs listed not using known framework such as MITRE ATT&amp;#x26;CK&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href=&quot;https://myos-esc.gitbook.io/myos-esc./blogs/phishing-campaign-analysis-laptop-percuma-bantuan-e-wallet-scam&quot; class=&quot;external&quot;&gt;Myo&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Student&lt;/td&gt;&lt;td&gt;23&lt;/td&gt;&lt;td&gt;None&lt;/td&gt;&lt;td&gt;Action taken (e.g. report to google safe browsing) can be beyond the two listed in the google form&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href=&quot;https://remarkable-xenon-ff5.notion.site/TNG-eWallet-Quishing-Campaign-31ea6f58415f80cc8e2dd5cee0c56826&quot; class=&quot;external&quot;&gt;Alif &amp;#x26; Faez&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Student&lt;/td&gt;&lt;td&gt;22&lt;/td&gt;&lt;td&gt;Included Chain of Code Reuse&lt;/td&gt;&lt;td&gt;TTPs listed not using known framework such as MITRE ATT&amp;#x26;CK&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
&lt;h3 id=&quot;remaining-6-listed-in-random-and-no-particular-order&quot;&gt;Remaining 6 (listed in random and no particular order)&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#remaining-6-listed-in-random-and-no-particular-order&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h3&gt;















































&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Article link&lt;/th&gt;&lt;th&gt;Category&lt;/th&gt;&lt;th&gt;Extra points given&lt;/th&gt;&lt;th&gt;Room for improvement&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;a href=&quot;https://badrulmunir.com/posts/fake-ewallet-my/&quot; class=&quot;external&quot;&gt;n3r&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Working Professional&lt;/td&gt;&lt;td&gt;OTP Form &amp;#x26; Anti analysis&lt;/td&gt;&lt;td&gt;To include executive summary, to include action taken&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href=&quot;https://www.linkedin.com/posts/khairul-zuhaili-4abb2435a_initial-discovery-a-suspicious-activity-7438077834687881216-5pHw&quot; class=&quot;external&quot;&gt;khairul-zuhaili&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Student&lt;/td&gt;&lt;td&gt;Telegram bot screenshot with victim data&lt;/td&gt;&lt;td&gt;To include executive summary, IoCs and action taken&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href=&quot;https://medium.com/@work.akmaltaufik/hunting-a-touch-n-go-duit-raya-phishing-campaign-targeting-malaysians-dedad86d39b1&quot; class=&quot;external&quot;&gt;akmaltaufik&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Student&lt;/td&gt;&lt;td&gt;Usage of crt.sh for pivoting&lt;/td&gt;&lt;td&gt;To include executive summary, TTPs using known framework and action taken &amp;#x26; report format to be more concise and succinct&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href=&quot;https://www.linkedin.com/posts/syazwanisubri_phishhuntmy-phishhuntmy-quishing-activity-7438584878696325120-YoYN&quot; class=&quot;external&quot;&gt;syazwanisubri&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Working Professional&lt;/td&gt;&lt;td&gt;Usage of VT collection&lt;/td&gt;&lt;td&gt;To include infection diagram/attack diagram and screenshots/proof of reporting to be included directly in the article (audience may missed to check in the evidence folder you’ve created)&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href=&quot;https://shrouded-brake-a7f.notion.site/Bantuan-Laptop-eMadani-Phishing-Analysis-320002229ba780278300f55f5b06adb1&quot; class=&quot;external&quot;&gt;matpwnguin&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Working Professional&lt;/td&gt;&lt;td&gt;Included TA assessment and security misconfig&lt;/td&gt;&lt;td&gt;Executive summary is a bit too long - can be more concise, to include action taken&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href=&quot;https://www.linkedin.com/posts/amirulhmd_phishing-alert-think-before-you-scan-ugcPost-7438172372588924928-zlYa&quot; class=&quot;external&quot;&gt;amirulhmd&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Student&lt;/td&gt;&lt;td&gt;Asked questions to stakeholder (Rectifyq) - which is good to understand stakeholder’s requirement, reporting (action taken) beyond suggested (Cloudflare abuse)&lt;/td&gt;&lt;td&gt;Overview if chosen as executive summary is bit too long, TTPs listed not using known framework such as MITRE ATT&amp;#x26;CK&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
&lt;h2 id=&quot;results-for-community-advocate&quot;&gt;Results for Community Advocate&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#results-for-community-advocate&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://www.linkedin.com/feed/update/urn:li:activity:7438379392071839744/&quot; class=&quot;external&quot;&gt;Winner: Alif &amp;#x26; Faez&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h3 id=&quot;scoring-criteria&quot;&gt;Scoring Criteria&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#scoring-criteria&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Brief Summary - if it is too short, too long or just right&lt;/li&gt;
&lt;li&gt;Diagrams - if includes screenshots, code snippets, infection chain/attack diagram&lt;/li&gt;
&lt;li&gt;Indicator Pivoting - pivoting from initial indicator (often phishing url) to underlying IP then whois record and so on&lt;/li&gt;
&lt;li&gt;TTP - TTPs listed and usage of known framework such as MITRE ATT&amp;#x26;CK or attck4fraud&lt;/li&gt;
&lt;li&gt;IoC - if IoCs were included, compiled and each IoCs has context&lt;/li&gt;
&lt;li&gt;Action Taken - proof of action taken (such as reporting to Google safe browsing and even beyond suggested previously) that gives out result (e.g. site no longer reachable)&lt;/li&gt;
&lt;li&gt;Phishing Kit - found phishing kit used, may pivot to similar campaigns that uses same phsihing kit, or even found the source code of the phishing kit&lt;/li&gt;
&lt;li&gt;Recommendation - provided relevant recommendation, be it to the public or organizations&lt;/li&gt;
&lt;li&gt;Extra points - interesting part of the report which unique to the writer&lt;/li&gt;
&lt;li&gt;Questions to Stakeholder - contacted stakeholder (Rectifyq) to clarify the expectation in terms formatting, or even the scoring criteria&lt;/li&gt;
&lt;li&gt;Follow Rectifyq’s social media - followed all Rectifyq’s social media&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;conclusion&quot;&gt;Conclusion&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#conclusion&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;This challenge really shows that Malaysia has amazing cybersecurity talent, from students to working pros. Everyone brought something different to the table—whether it was offensive skills or traffic analysis—and used those strengths to break down the phishing campaigns targeting Malaysian.&lt;/p&gt;
&lt;p&gt;I learned a ton from organizing this, and the feedback from few participants were great. Like I told one of the participants, I can’t officially promise to make this a regular thing just yet. But hopefully, even if I’m not the one running it next time, I hope this inspires other companies or organizations to host similar challenges.&lt;/p&gt; ]]></description>
    <pubDate>Wed, 18 Mar 2026 00:00:00 GMT</pubDate>
  </item><item>
    <title>Threat Intelligence focusing on Malaysia 🇲🇾</title>
    <link>https://rectifyq.com/</link>
    <guid>https://rectifyq.com/</guid>
    <description><![CDATA[ &lt;link href=&quot;https://cdnjs.cloudflare.com/ajax/libs/font-awesome/7.0.0/css/all.min.css&quot; rel=&quot;stylesheet&quot;&gt;
&lt;h1 id=&quot;-empowering-malaysias-cyber-defense&quot;&gt;🇲🇾 Empowering Malaysia’s Cyber Defense&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#-empowering-malaysias-cyber-defense&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h1&gt;
&lt;blockquote class=&quot;callout tip&quot; data-callout=&quot;tip&quot;&gt;
&lt;div class=&quot;callout-title&quot;&gt;
                  &lt;div class=&quot;callout-icon&quot;&gt;&lt;/div&gt;
                  &lt;div class=&quot;callout-title-inner&quot;&gt;&lt;p&gt; &lt;strong&gt;Help us build the future&lt;/strong&gt;&lt;/p&gt;&lt;/div&gt;
                  
                &lt;/div&gt;
&lt;div class=&quot;callout-content&quot;&gt;
&lt;p&gt;Rectifyq is evolving. Share your feedback or feature requests via our &lt;strong&gt;&lt;a href=&quot;https://forms.gle/Vfs3LFg9X6g2tibv7&quot; class=&quot;external&quot;&gt;Google Form&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/strong&gt;.&lt;/p&gt;
&lt;/div&gt;
&lt;/blockquote&gt;
&lt;hr&gt;
&lt;h3 id=&quot;️-the-mission&quot;&gt;🛡️ The Mission&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#️-the-mission&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h3&gt;
&lt;blockquote class=&quot;callout abstract&quot; data-callout=&quot;abstract&quot;&gt;
&lt;div class=&quot;callout-title&quot;&gt;
                  &lt;div class=&quot;callout-icon&quot;&gt;&lt;/div&gt;
                  &lt;div class=&quot;callout-title-inner&quot;&gt;&lt;p&gt; &lt;strong&gt;A Personal Initiative for National Resilience&lt;/strong&gt;&lt;/p&gt;&lt;/div&gt;
                  
                &lt;/div&gt;
&lt;div class=&quot;callout-content&quot;&gt;
&lt;p&gt;Threat Intelligence Malaysia | Rectifyq is a self-funded, personal project dedicated to refining the Malaysian cybersecurity ecosystem. It’s a space for continuous learning, data sharing, and collective defense—bridging the gap between global intelligence and local reality.&lt;/p&gt;
&lt;/div&gt;
&lt;/blockquote&gt;
&lt;hr&gt;
&lt;h2 id=&quot;-addressing-the-malaysian-gap&quot;&gt;🔍 Addressing the “Malaysian Gap”&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#-addressing-the-malaysian-gap&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Global threat reports often overlook our region. Rectifyq focuses on:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Localized Intelligence:&lt;/strong&gt; Moving beyond Western-centric APT reports to focus on threats hitting 🇲🇾 infrastructure.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Strategic Justification:&lt;/strong&gt; Providing concrete, local data to help leaders justify cybersecurity investments.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Actionable Contribution:&lt;/strong&gt; Providing a structured platform for local analysts to share findings and grow together.&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;
&lt;h2 id=&quot;️-ecosystem-map&quot;&gt;🕸️ Ecosystem Map&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#️-ecosystem-map&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Our intelligence flows through several specialized channels. Click any node below to explore.&lt;/p&gt;
&lt;hr&gt;
&lt;pre&gt;&lt;button class=&quot;expand-button&quot; aria-label=&quot;Expand mermaid diagram&quot; data-view-component&gt;&lt;svg width=&quot;16&quot; height=&quot;16&quot; viewBox=&quot;0 0 16 16&quot; fill=&quot;currentColor&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M3.72 3.72a.75.75 0 011.06 1.06L2.56 7h10.88l-2.22-2.22a.75.75 0 011.06-1.06l3.5 3.5a.75.75 0 010 1.06l-3.5 3.5a.75.75 0 11-1.06-1.06l2.22-2.22H2.56l2.22 2.22a.75.75 0 11-1.06 1.06l-3.5-3.5a.75.75 0 010-1.06l3.5-3.5z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/button&gt;&lt;code class=&quot;mermaid&quot; data-clipboard=&quot;&amp;#x22;flowchart LR\n    A@{ shape: lean-r, label: \&amp;#x22;Sources\&amp;#x22; } ==&gt; B[fa:fa-comment MISP202x]\n    B ==&gt; C[fa:fa-comment MISPMY]\n\n    subgraph Global\n    E@{ shape: lean-r, label: \&amp;#x22;fab:fa-telegram Telegram\&amp;#x22; }\n    H@{ shape: lean-r, label: \&amp;#x22;fab:fa-github Github\&amp;#x22; }\n    I@{ shape: lean-r, label: \&amp;#x22;fab:fa-medium Medium\&amp;#x22; }\n    J@{ shape: lean-r, label: \&amp;#x22;fab:fa-notion Notion\&amp;#x22; }\n    K@{ shape: lean-r, label: \&amp;#x22;fab:fa-tiktok Tiktok\&amp;#x22; }\n    L@{ shape: lean-r, label: \&amp;#x22;fa:fa-virus VirusTotal\&amp;#x22; }\n\n    end\n    subgraph MY-focused\n    D@{ shape: lean-r, label: \&amp;#x22;fa:fa-globe Web\&amp;#x22; }\n    F@{ shape: lean-r, label: \&amp;#x22;fab:fa-x X(Twitter)\&amp;#x22; }\n    G@{ shape: lean-r, label: \&amp;#x22;fab:fa-linkedin LinkedIn\&amp;#x22; }\n    end\n\n    B --&gt; E\n    B --&gt; J\n    B --&gt; K\n    B --&gt; I\n    B --&gt; H\n    B --&gt; L\n\n    C --&gt; D\n    C --&gt; F\n    C --&gt; G\n\n    click B \&amp;#x22;https://misp2026.rectifyq.com\&amp;#x22; _blank\n    click C \&amp;#x22;https://mispmy.rectifyq.com\&amp;#x22; _blank\n    click D \&amp;#x22;https://rectifyq.com\&amp;#x22; _blank\n    click E \&amp;#x22;http://t.me/rectifyq\&amp;#x22; _blank\n    click F \&amp;#x22;https://x.com/_rectifyq\&amp;#x22; _blank\n    click G \&amp;#x22;https://linkedin.com/company/rectifyq\&amp;#x22; _blank\n    click H \&amp;#x22;https://github.com/rectifyq\&amp;#x22; _blank\n    click I \&amp;#x22;https://medium.com/@rectifyq\&amp;#x22; _blank\n    click J \&amp;#x22;https://rectifyq.notion.site/Rectifyq-7ece6db87cd44ad4b7503e238191b801\&amp;#x22; _blank\n    click K \&amp;#x22;https://www.tiktok.com/@rectifyq\&amp;#x22; _blank\n    click L \&amp;#x22;https://www.virustotal.com/gui/user/rectifyq\&amp;#x22; _blank\n\n    style A stroke:#0f0\n    style B stroke:#00f\n    style C stroke:#00f&amp;#x22;&quot;&gt;flowchart LR
    A@{ shape: lean-r, label: &quot;Sources&quot; } ==&gt; B[fa:fa-comment MISP202x]
    B ==&gt; C[fa:fa-comment MISPMY]

    subgraph Global
    E@{ shape: lean-r, label: &quot;fab:fa-telegram Telegram&quot; }
    H@{ shape: lean-r, label: &quot;fab:fa-github Github&quot; }
    I@{ shape: lean-r, label: &quot;fab:fa-medium Medium&quot; }
    J@{ shape: lean-r, label: &quot;fab:fa-notion Notion&quot; }
    K@{ shape: lean-r, label: &quot;fab:fa-tiktok Tiktok&quot; }
    L@{ shape: lean-r, label: &quot;fa:fa-virus VirusTotal&quot; }

    end
    subgraph MY-focused
    D@{ shape: lean-r, label: &quot;fa:fa-globe Web&quot; }
    F@{ shape: lean-r, label: &quot;fab:fa-x X(Twitter)&quot; }
    G@{ shape: lean-r, label: &quot;fab:fa-linkedin LinkedIn&quot; }
    end

    B --&gt; E
    B --&gt; J
    B --&gt; K
    B --&gt; I
    B --&gt; H
    B --&gt; L

    C --&gt; D
    C --&gt; F
    C --&gt; G

    click B &quot;https://misp2026.rectifyq.com&quot; _blank
    click C &quot;https://mispmy.rectifyq.com&quot; _blank
    click D &quot;https://rectifyq.com&quot; _blank
    click E &quot;http://t.me/rectifyq&quot; _blank
    click F &quot;https://x.com/_rectifyq&quot; _blank
    click G &quot;https://linkedin.com/company/rectifyq&quot; _blank
    click H &quot;https://github.com/rectifyq&quot; _blank
    click I &quot;https://medium.com/@rectifyq&quot; _blank
    click J &quot;https://rectifyq.notion.site/Rectifyq-7ece6db87cd44ad4b7503e238191b801&quot; _blank
    click K &quot;https://www.tiktok.com/@rectifyq&quot; _blank
    click L &quot;https://www.virustotal.com/gui/user/rectifyq&quot; _blank

    style A stroke:#0f0
    style B stroke:#00f
    style C stroke:#00f
&lt;/code&gt;&lt;div id=&quot;mermaid-container&quot; role=&quot;dialog&quot;&gt;&lt;div id=&quot;mermaid-space&quot;&gt;&lt;div class=&quot;mermaid-content&quot;&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/pre&gt; ]]></description>
    <pubDate>Thu, 05 Mar 2026 15:01:06 GMT</pubDate>
  </item><item>
    <title>2026-03-03 Silver Dragon Targets Organizations in Southeast Asia and Europe</title>
    <link>https://rectifyq.com/MY-Threat-Landscape/threat-lists/2e319e49-6c2f-442b-ba50-ae7d2e43ddb4</link>
    <guid>https://rectifyq.com/MY-Threat-Landscape/threat-lists/2e319e49-6c2f-442b-ba50-ae7d2e43ddb4</guid>
    <description><![CDATA[ &lt;p&gt;📃Title: Silver Dragon Targets Organizations in Southeast Asia and Europe&lt;br&gt;
📅Date: 2026-03-03&lt;br&gt;
🔗References:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://research.checkpoint.com/2026/silver-dragon-targets-organizations-in-southeast-asia-and-europe/&quot; class=&quot;external&quot;&gt;https://research.checkpoint.com/2026/silver-dragon-targets-organizations-in-southeast-asia-and-europe/&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;blockquote class=&quot;callout abstract&quot; data-callout=&quot;abstract&quot;&gt;
&lt;div class=&quot;callout-title&quot;&gt;
                  &lt;div class=&quot;callout-icon&quot;&gt;&lt;/div&gt;
                  &lt;div class=&quot;callout-title-inner&quot;&gt;&lt;p&gt; &lt;strong&gt;Description&lt;/strong&gt;&lt;/p&gt;&lt;/div&gt;
                  
                &lt;/div&gt;
&lt;div class=&quot;callout-content&quot;&gt;
&lt;p&gt;Check Point Research has identified a Chinese-nexus advanced persistent threat group named Silver Dragon, targeting organizations in Southeast Asia and Europe since mid-2024. The group, likely operating under APT41, exploits public-facing servers and uses phishing emails for initial access. They deploy custom tools including GearDoor, a backdoor using Google Drive for command and control, SSHcmd for remote access, and SilverScreen for covert screen monitoring. Silver Dragon primarily focuses on government entities, utilizing Cobalt Strike beacons and DNS tunneling for communication. The group’s sophisticated tactics and evolving toolkit demonstrate a well-resourced and adaptable threat actor.&lt;/p&gt;
&lt;/div&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;img src=&quot;https://raw.githubusercontent.com/rectifyq/Collections/refs/heads/main/Diamond-Models/2026/260307-SilverDragon/260307-SilverDragon.png&quot; alt=&quot;&quot;&gt;&lt;/p&gt;
&lt;p&gt;🔖Rectifyq Taxonomies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;relevancy: 🔴 Highly Relevant&lt;/li&gt;
&lt;li&gt;category: &lt;a href=&quot;../.././../tags/⚔Threat&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/⚔Threat&quot;&gt;⚔Threat&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;sub-category: &lt;a href=&quot;../.././../tags/TA-profile&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/TA-profile&quot;&gt;TA-profile&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;target: &lt;a href=&quot;../.././../tags/broad-based&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/broad-based&quot;&gt;broad-based&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;MY-relevancy: &lt;a href=&quot;../.././../tags/relevant&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/relevant&quot;&gt;relevant&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;action-taken: &lt;a href=&quot;../.././../tags/diamond-model&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/diamond-model&quot;&gt;diamond-model&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;🔖MISP Galaxies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;producer &lt;a href=&quot;../.././../tags/Check-Point&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/Check-Point&quot;&gt;Check-Point&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;region=“035 - South-eastern Asia”&lt;/li&gt;
&lt;li&gt;threat-actor &lt;a href=&quot;../.././../tags/APT41&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/APT41&quot;&gt;APT41&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;target-information=“Italy”&lt;/li&gt;
&lt;li&gt;target-information=“Japan”&lt;/li&gt;
&lt;li&gt;target-information=“Kazakhstan”&lt;/li&gt;
&lt;li&gt;target-information=“Malaysia”&lt;/li&gt;
&lt;li&gt;target-information=“Myanmar”&lt;/li&gt;
&lt;li&gt;target-information=“Poland”&lt;/li&gt;
&lt;li&gt;target-information=“Russia”&lt;/li&gt;
&lt;li&gt;online-service=“4a9eade3-5de4-4a80-9c7a-ba3a7566e130”&lt;/li&gt;
&lt;li&gt;malpedia=“Cobalt Strike”&lt;/li&gt;
&lt;li&gt;sector=“Government, Administration”&lt;/li&gt;
&lt;li&gt;mitre-attack-pattern=[‘T1113’, ‘T1033’, ‘T1132.001’, ‘T1071.004’, ‘T1036.005’, ‘T1021.004’, ‘T1082’, ‘T1053’, ‘T1055’, ‘T1016’, ‘T1083’, ‘T1036.004’, ‘T1049’, ‘T1057’, ‘T1059.001’, ‘T1078’, ‘T1102.002’, ‘T1001.003’, ‘T1059.003’, ‘T1105’]&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;MISP event uuid: &lt;a href=&quot;https://mispmy.rectifyq.com/events/view/2e319e49-6c2f-442b-ba50-ae7d2e43ddb4&quot; class=&quot;external&quot;&gt;2e319e49-6c2f-442b-ba50-ae7d2e43ddb4&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2 id=&quot;indicator-of-compromise-iocs&quot;&gt;Indicator of Compromise (IoCs)&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#indicator-of-compromise-iocs&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;pre&gt;&lt;code&gt;type,value,comment
md5, 9d3f61dcaba90db2ede1c1906a80ace2, &#039;No sample in VT\r\nLast check:06/03/2026&#039;
sha256, 16b9a7358be88632378ba20ba1430786f3b844694b1f876211ecdbecf5cccbc2, &#039;No sample in VT\r\nLast check:06/03/2026&#039;
sha256, 37b485ed8d150d022c41e5e307b8c54c34ef806625b44d0c940b18be7d5b29ce, &#039;No sample in VT\r\nLast check:06/03/2026&#039;
domain, ampolice.org, &#039;&#039;
domain, bigflx.net, &#039;&#039;
domain, copilot-cloud.net, &#039;&#039;
domain, exchange4study.com, &#039;&#039;
domain, mindssurpass.com, &#039;&#039;
domain, oicm.org, &#039;&#039;
domain, onedriveconsole.com, &#039;&#039;
domain, protacik.com, &#039;&#039;
domain, revitpourtous.com, &#039;&#039;
domain, splunkds.com, &#039;&#039;
domain, wikipedla.blog, &#039;&#039;
domain, zhydromet.com, &#039;&#039;
hostname, ns1.exchange4study.com, &#039;&#039;
hostname, ns1.onedriveconsole.com, &#039;&#039;
hostname, ns2.onedriveconsole.com, &#039;&#039;
hostname, drivefrontend.pa-clients.workers.dev, &#039;&#039;

Full IOCs available in Rectifyq&#039;s MISP```
&lt;/code&gt;&lt;/pre&gt; ]]></description>
    <pubDate>Tue, 03 Mar 2026 00:00:00 GMT</pubDate>
  </item><item>
    <title>2026-02-28 Analysis of the “Kongsi Rezeki” on Threads social media QR-phishing campaign</title>
    <link>https://rectifyq.com/MY-Threat-Landscape/threat-lists/0b6037c8-d75d-4ba2-a378-7e0a2757a051</link>
    <guid>https://rectifyq.com/MY-Threat-Landscape/threat-lists/0b6037c8-d75d-4ba2-a378-7e0a2757a051</guid>
    <description><![CDATA[ &lt;p&gt;📃Title: Analysis of the “Kongsi Rezeki” on Threads social media QR-phishing campaign&lt;br&gt;
📅Date: 2026-02-28&lt;br&gt;
🔗References:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.notion.so/3ch0/Analysis-of-the-Kongsi-Rezeki-on-Threads-social-media-QR-phishing-campaign-314d05a447d5809abc48e44233792978&quot; class=&quot;external&quot;&gt;https://www.notion.so/3ch0/Analysis-of-the-Kongsi-Rezeki-on-Threads-social-media-QR-phishing-campaign-314d05a447d5809abc48e44233792978&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;🔖Rectifyq Taxonomies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;relevancy: 🔴 Highly Relevant&lt;/li&gt;
&lt;li&gt;category: &lt;a href=&quot;../.././../tags/⚔Threat&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/⚔Threat&quot;&gt;⚔Threat&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;sub-category: &lt;a href=&quot;../.././../tags/campaign-analysis&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/campaign-analysis&quot;&gt;campaign-analysis&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;target: &lt;a href=&quot;../.././../tags/broad-based&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/broad-based&quot;&gt;broad-based&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;MY-relevancy: &lt;a href=&quot;../.././../tags/relevant&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/relevant&quot;&gt;relevant&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;🔖MISP Galaxies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;target-information=“Malaysia”&lt;/li&gt;
&lt;li&gt;mitre-attack-pattern=[‘T1531’, ‘T1588.004’, ‘T1583.001’, ‘T1041’, ‘T1111’, ‘T1566.002’, ‘T1598.003’]&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;MISP event uuid: &lt;a href=&quot;https://mispmy.rectifyq.com/events/view/0b6037c8-d75d-4ba2-a378-7e0a2757a051&quot; class=&quot;external&quot;&gt;0b6037c8-d75d-4ba2-a378-7e0a2757a051&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2 id=&quot;indicator-of-compromise-iocs&quot;&gt;Indicator of Compromise (IoCs)&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#indicator-of-compromise-iocs&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;pre&gt;&lt;code&gt;type,value,comment
url, https://tngduitraya14.gbdjw.my/, &#039;Landing page after QR scan.&#039;
url, https://tngduitraya14.gbdjw.my/go/, &#039;Data collection page.&#039;
url, https://tngduitraya14.gbdjw.my/API/index.php, &#039;C2 server for data exfiltration.&#039;
domain, gbdjw.my, &#039;Malicious Domain.&#039;
hostname, money.gbdjw.my, &#039;&#039;
hostname, tngduitraya.gbdjw.my, &#039;&#039;
hostname, moneypocket.gbdjw.my, &#039;&#039;

Full IOCs available in Rectifyq&#039;s MISP```
&lt;/code&gt;&lt;/pre&gt; ]]></description>
    <pubDate>Sat, 28 Feb 2026 00:00:00 GMT</pubDate>
  </item><item>
    <title>2026-02-23 Chronology of MuddyWater APT Attacks Targeting the Middle East</title>
    <link>https://rectifyq.com/MY-Threat-Landscape/threat-lists/902d955b-e5f7-4bca-948e-857e6ab0017c</link>
    <guid>https://rectifyq.com/MY-Threat-Landscape/threat-lists/902d955b-e5f7-4bca-948e-857e6ab0017c</guid>
    <description><![CDATA[ &lt;p&gt;📃Title: Chronology of MuddyWater APT Attacks Targeting the Middle East&lt;br&gt;
📅Date: 2026-02-23&lt;br&gt;
🔗References:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.genians.co.kr/en/blog/threat_intelligence/muddywater-apt?hs_amp=true&quot; class=&quot;external&quot;&gt;https://www.genians.co.kr/en/blog/threat_intelligence/muddywater-apt?hs_amp=true&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;blockquote class=&quot;callout abstract&quot; data-callout=&quot;abstract&quot;&gt;
&lt;div class=&quot;callout-title&quot;&gt;
                  &lt;div class=&quot;callout-icon&quot;&gt;&lt;/div&gt;
                  &lt;div class=&quot;callout-title-inner&quot;&gt;&lt;p&gt; &lt;strong&gt;Description&lt;/strong&gt;&lt;/p&gt;&lt;/div&gt;
                  
                &lt;/div&gt;
&lt;div class=&quot;callout-content&quot;&gt;
&lt;p&gt;This report analyzes the recent activities of the MuddyWater APT group, which primarily targets organizations in the Middle East. The group employs sophisticated spear-phishing techniques, often impersonating legitimate entities and using malicious documents to gain initial access. Their attacks focus on long-term infiltration and intelligence gathering rather than immediate disruption. The report details several attack cases from 2019 to 2026, highlighting the group’s evolving tactics, including the abuse of legitimate remote management tools and the use of Rust-based malware. The analysis emphasizes the importance of endpoint detection and response (EDR) solutions in identifying and mitigating these threats, as traditional perimeter-based security measures prove insufficient against such advanced persistent threats.&lt;/p&gt;
&lt;/div&gt;
&lt;/blockquote&gt;
&lt;p&gt;🔖Rectifyq Taxonomies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;relevancy: 🔴 Highly Relevant&lt;/li&gt;
&lt;li&gt;category: &lt;a href=&quot;../.././../tags/⚔Threat&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/⚔Threat&quot;&gt;⚔Threat&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;sub-category: &lt;a href=&quot;../.././../tags/campaign-analysis&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/campaign-analysis&quot;&gt;campaign-analysis&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;topic: &lt;a href=&quot;../.././../tags/geopolitical&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/geopolitical&quot;&gt;geopolitical&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;target: &lt;a href=&quot;../.././../tags/broad-based&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/broad-based&quot;&gt;broad-based&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;MY-relevancy: &lt;a href=&quot;../.././../tags/relevant&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/relevant&quot;&gt;relevant&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;🔖MISP Galaxies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;target-information=“Egypt”&lt;/li&gt;
&lt;li&gt;target-information=“Iraq”&lt;/li&gt;
&lt;li&gt;target-information=“Israel”&lt;/li&gt;
&lt;li&gt;target-information=“Jordan”&lt;/li&gt;
&lt;li&gt;target-information=“Malaysia”&lt;/li&gt;
&lt;li&gt;target-information=“Oman”&lt;/li&gt;
&lt;li&gt;target-information=“Turkmenistan”&lt;/li&gt;
&lt;li&gt;threat-actor &lt;a href=&quot;../.././../tags/MuddyWater&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/MuddyWater&quot;&gt;MuddyWater&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;mitre-attack-pattern=[‘T1133’, ‘T1071’, ‘T1190’, ‘T1583.001’, ‘T1036’, ‘T1588.001’, ‘T1102’, ‘T1204’, ‘T1059.001’, ‘T1547.001’, ‘T1199’, ‘T1588.002’, ‘T1566’, ‘T1078’, ‘T1027’, ‘T1213’, ‘T1105’, ‘T1569.002’]&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;MISP event uuid: &lt;a href=&quot;https://mispmy.rectifyq.com/events/view/902d955b-e5f7-4bca-948e-857e6ab0017c&quot; class=&quot;external&quot;&gt;902d955b-e5f7-4bca-948e-857e6ab0017c&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2 id=&quot;indicator-of-compromise-iocs&quot;&gt;Indicator of Compromise (IoCs)&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#indicator-of-compromise-iocs&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;pre&gt;&lt;code&gt;type,value,comment
ip-dst, 159.198.66.153, &#039;&#039;
ip-dst, 159.198.68.25, &#039;&#039;
domain, screenai.online, &#039;&#039;
domain, stratioai.org, &#039;&#039;
hostname, nomercys.it.com, &#039;&#039;

Full IOCs available in Rectifyq&#039;s MISP```
&lt;/code&gt;&lt;/pre&gt; ]]></description>
    <pubDate>Mon, 23 Feb 2026 00:00:00 GMT</pubDate>
  </item><item>
    <title>Achievement</title>
    <link>https://rectifyq.com/achievement</link>
    <guid>https://rectifyq.com/achievement</guid>
    <description><![CDATA[ &lt;h1 id=&quot;public-mentionsfeatured&quot;&gt;Public mentions/featured&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#public-mentionsfeatured&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h1&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://x.com/ElementalX2/status/1945379345280983096&quot; class=&quot;external&quot;&gt;https://x.com/ElementalX2/status/1945379345280983096&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://x.com/RussianPanda9xx/status/1999515380746797447&quot; class=&quot;external&quot;&gt;https://x.com/RussianPanda9xx/status/1999515380746797447&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://x.com/skocherhan/status/2023549256590913812?s=20&quot; class=&quot;external&quot;&gt;https://x.com/skocherhan/status/2023549256590913812?s=20&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;misp-contribution&quot;&gt;MISP contribution&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#misp-contribution&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.misp-project.org/Changelog-misp-galaxy.txt&quot; class=&quot;external&quot;&gt;https://www.misp-project.org/Changelog-misp-galaxy.txt&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.misp-project.org/objects.html&quot; class=&quot;external&quot;&gt;https://www.misp-project.org/objects.html&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;misc&quot;&gt;Misc&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#misc&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://blog.pulsedive.com/content/files/2024/01/CTI-Networking-Report-2024_Grace-Chi.pdf&quot; class=&quot;external&quot;&gt;https://blog.pulsedive.com/content/files/2024/01/CTI-Networking-Report-2024_Grace-Chi.pdf&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h1 id=&quot;speakingtraining&quot;&gt;Speaking/Training&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#speakingtraining&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h1&gt;
&lt;ul&gt;
&lt;li&gt;Trainer at Malaysia Cyber Camp 2025 - &lt;a href=&quot;https://cybercamp.my/posts/2025/mcc-2025-conquer&quot; class=&quot;external&quot;&gt;https://cybercamp.my/posts/2025/mcc-2025-conquer&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt; ]]></description>
    <pubDate>Thu, 19 Feb 2026 01:51:50 GMT</pubDate>
  </item><item>
    <title>MISP Initial Setup</title>
    <link>https://rectifyq.com/Threat-Intelligence-Platform-(TIP)/Install-Your-Own-TIP/MISP-initial-setup</link>
    <guid>https://rectifyq.com/Threat-Intelligence-Platform-(TIP)/Install-Your-Own-TIP/MISP-initial-setup</guid>
    <description><![CDATA[ &lt;h1 id=&quot;initial-setup&quot;&gt;Initial Setup&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#initial-setup&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h1&gt;
&lt;h2 id=&quot;setting-up-taxonomies&quot;&gt;Setting up Taxonomies&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#setting-up-taxonomies&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;h3 id=&quot;enable-taxonomies&quot;&gt;Enable Taxonomies&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#enable-taxonomies&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h3&gt;
&lt;details&gt;
&lt;summary&gt;Enable the following taxonomies:&lt;/summary&gt;
&lt;ul class=&quot;contains-task-list&quot;&gt;
&lt;li class=&quot;task-list-item&quot;&gt;&lt;input type=&quot;checkbox&quot; class=&quot;checkbox-toggle&quot;&gt; tlp&lt;/li&gt;
&lt;li class=&quot;task-list-item&quot;&gt;&lt;input type=&quot;checkbox&quot; class=&quot;checkbox-toggle&quot;&gt; type&lt;/li&gt;
&lt;li class=&quot;task-list-item&quot;&gt;&lt;input type=&quot;checkbox&quot; class=&quot;checkbox-toggle&quot;&gt; workflow&lt;/li&gt;
&lt;li class=&quot;task-list-item&quot;&gt;&lt;input type=&quot;checkbox&quot; class=&quot;checkbox-toggle&quot;&gt; ms-caro-malware&lt;/li&gt;
&lt;/ul&gt;
&lt;/details&gt;
&lt;h3 id=&quot;adding-custom-rectifyq-taxonomies&quot;&gt;Adding Custom Rectifyq Taxonomies&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#adding-custom-rectifyq-taxonomies&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h3&gt;
&lt;figure data-rehype-pretty-code-figure=&quot;&quot;&gt;&lt;pre tabindex=&quot;0&quot; data-language=&quot;shell&quot; data-theme=&quot;github-light github-dark&quot;&gt;&lt;code data-language=&quot;shell&quot; data-theme=&quot;github-light github-dark&quot; style=&quot;display: grid;&quot;&gt;&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#005CC5;--shiki-dark:#79B8FF&quot;&gt;cd&lt;/span&gt;&lt;span style=&quot;--shiki-light:#032F62;--shiki-dark:#9ECBFF&quot;&gt; /var/www/MISP/app/files/taxonomies/&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#6F42C1;--shiki-dark:#B392F0&quot;&gt;mkdir&lt;/span&gt;&lt;span style=&quot;--shiki-light:#032F62;--shiki-dark:#9ECBFF&quot;&gt; rectifyq&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#005CC5;--shiki-dark:#79B8FF&quot;&gt;cd&lt;/span&gt;&lt;span style=&quot;--shiki-light:#032F62;--shiki-dark:#9ECBFF&quot;&gt; rectifyq&lt;/span&gt;&lt;/span&gt;
&lt;span data-line=&quot;&quot;&gt;&lt;span style=&quot;--shiki-light:#6F42C1;--shiki-dark:#B392F0&quot;&gt;nano&lt;/span&gt;&lt;span style=&quot;--shiki-light:#032F62;--shiki-dark:#9ECBFF&quot;&gt; machinetag.json&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;
&lt;p&gt;Tips in case of copy issue: &lt;/p&gt;
&lt;pre&gt;&lt;code&gt;jq . machinetag.json &gt; temp
mv temp machinetag.json
&lt;/code&gt;&lt;/pre&gt;
&lt;details&gt;
&lt;summary&gt;Add the following content to machinetag.json&lt;/summary&gt;
&lt;pre&gt;&lt;code&gt;{
    &quot;namespace&quot;: &quot;rectifyq&quot;,
    &quot;description&quot;: &quot;Rectifyq taxonomies used for checklist, context and statistics&quot;,
    &quot;version&quot;: 2.6,
    &quot;predicates&quot;: [{
            &quot;value&quot;: &quot;category&quot;,
            &quot;expanded&quot;: &quot;Category&quot;
        }, {
            &quot;value&quot;: &quot;sub-category&quot;,
            &quot;expanded&quot;: &quot;Sub-Category&quot;
        }, {
            &quot;value&quot;: &quot;topic&quot;,
            &quot;expanded&quot;: &quot;Related topics&quot;
        }, {
            &quot;value&quot;: &quot;TA-category&quot;,
            &quot;expanded&quot;: &quot;Threat Actor Category&quot;
        }, {
            &quot;value&quot;: &quot;target&quot;,
            &quot;expanded&quot;: &quot;Target&quot;
        }, {
            &quot;value&quot;: &quot;samples-found-in&quot;,
            &quot;expanded&quot;: &quot;Samples found in&quot;
        }, {
            &quot;value&quot;: &quot;no-samples-in&quot;,
            &quot;expanded&quot;: &quot;No samples in&quot;
        }, {
            &quot;value&quot;: &quot;ioc&quot;,
            &quot;expanded&quot;: &quot;IOC&quot;
        }, {
            &quot;value&quot;: &quot;MY-relevancy&quot;,
            &quot;expanded&quot;: &quot;Malaysia relevancy&quot;
        }, {
            &quot;value&quot;: &quot;workflow&quot;,
            &quot;expanded&quot;: &quot;Workflow&quot;
        }, {
            &quot;value&quot;: &quot;mitre-att&amp;#x26;ck&quot;,
            &quot;expanded&quot;: &quot;MITRE ATT&amp;#x26;CK&quot;
        }, {
            &quot;value&quot;: &quot;detection-rules&quot;,
            &quot;expanded&quot;: &quot;Detection Rules&quot;
        }, {
            &quot;value&quot;: &quot;action-taken&quot;,
            &quot;expanded&quot;: &quot;Action taken&quot;
        }
    ],
    &quot;values&quot;: [{
            &quot;predicate&quot;: &quot;category&quot;,
            &quot;entry&quot;: [{
                    &quot;value&quot;: &quot;threat&quot;,
					&quot;colour&quot;: &quot;#49a260&quot;,
                    &quot;expanded&quot;: &quot;Threat related event - mostly contains IOCs&quot;
                }, {
                    &quot;value&quot;: &quot;data-breach&quot;,
					&quot;colour&quot;: &quot;#49a260&quot;,
                    &quot;expanded&quot;: &quot;Data breach related event&quot;
                }, {
                    &quot;value&quot;: &quot;vulnerability&quot;,
					&quot;colour&quot;: &quot;#49a260&quot;,
                    &quot;expanded&quot;: &quot;Vulnerability related event&quot;
                }
            ]
        }, {
            &quot;predicate&quot;: &quot;sub-category&quot;,
            &quot;entry&quot;: [{
                    &quot;value&quot;: &quot;TA-profile&quot;,
                    &quot;expanded&quot;: &quot;Threat Actor Profile: Comprehensive dossiers on specific groups (e.g., APT41, Lazarus), including motives, history, and suspected origin.&quot;
                }, {
                    &quot;value&quot;: &quot;tool-profile&quot;,
                    &quot;expanded&quot;: &quot;Tooling Context: Analysis of non-malicious tools used for malicious purposes (e.g., Cobalt Strike, PowerShell, AdFind).&quot;
                }, {
                    &quot;value&quot;: &quot;malware-analysis&quot;,
                    &quot;expanded&quot;: &quot;Technical Deep-Dive: Results from sandbox execution, reverse engineering, or static analysis of a specific sample.&quot;
                }, {
                    &quot;value&quot;: &quot;intrusion-analysis&quot;,
                    &quot;expanded&quot;: &quot;Incident Reconstruction: The story of a breach, mapping out the full kill-chain from initial access to data exfiltration.&quot;
                }, {
                    &quot;value&quot;: &quot;infra-profile&quot;,
                    &quot;expanded&quot;: &quot;Infrastructure Mapping: Details on C2 servers, IP ranges, ASN reputations, and domain registration patterns used by attackers.&quot;
                }, {
					&quot;value&quot;: &quot;campaign-analysis&quot;,
                    &quot;expanded&quot;: &quot;Strategic Grouping: Analysis of a series of related incidents/attacks over a specific timeframe, often linked by shared infrastructure, TTPs, or themes.&quot;
                }, {
                    &quot;value&quot;: &quot;leak-forums&quot;,
                    &quot;expanded&quot;: &quot;Dark Web Monitoring: Intelligence gathered from illicit underground marketplaces or forums where data/access is sold.&quot;
                }, {
                    &quot;value&quot;: &quot;leak-infostealer&quot;,
                    &quot;expanded&quot;: &quot;Stealer Logs: Specific data exfiltrated via malware like RedLine or Lumma (e.g., credentials, cookies, crypto wallets).&quot;
                }, {
                    &quot;value&quot;: &quot;report&quot;,
                    &quot;expanded&quot;: &quot;Finished Intel: High-level narrative summaries or white papers (internal or third-party) that synthesize multiple events.&quot;
                }, {
                    &quot;value&quot;: &quot;zero-day&quot;,
                    &quot;expanded&quot;: &quot;Unpatched Exploits: High-priority indicators for vulnerabilities that have no official patch or were exploited before public awareness.&quot;
                }, {
                    &quot;value&quot;: &quot;branded-vuln&quot;,
                    &quot;expanded&quot;: &quot;High-Profile Bugs: Vulnerabilities with marketing names/logos (e.g., Heartbleed, PwnKit) that often see rapid, mass exploitation.&quot;
                }, {
                    &quot;value&quot;: &quot;critical-vuln&quot;,
                    &quot;expanded&quot;: &quot;High-Severity Flaws: Standard vulnerabilities that carry a high CVSS/EPSS score but may not have a brand name.&quot;
                }
            ]
        }, {
            &quot;predicate&quot;: &quot;topic&quot;,
            &quot;entry&quot;: [{
                    &quot;value&quot;: &quot;mobile-attack&quot;,
                    &quot;expanded&quot;: &quot;Indicators and patterns related to mobile OS (Android/iOS) exploits, malicious apps, and smishing.&quot;
                }, {
                    &quot;value&quot;: &quot;ai&quot;,
                    &quot;expanded&quot;: &quot;Threats targeting AI models (adversarial ML), or attacks generated/enhanced by AI/LLMs.&quot;
                }, {
                    &quot;value&quot;: &quot;supply-chain&quot;,
                    &quot;expanded&quot;: &quot;Compromises of third-party vendors, software libraries (e.g., npm/PyPI), or hardware manufacturing.&quot;
                }, {
                    &quot;value&quot;: &quot;ics-ot&quot;,
                    &quot;expanded&quot;: &quot;Attacks on Industrial Control Systems, SCADA, and operational technology in critical infrastructure.&quot;
                }, {
					&quot;value&quot;: &quot;web3&quot;,
                    &quot;expanded&quot;: &quot;Threats targeting decentralized protocols, DAOs, and smart contract vulnerabilities.&quot;
                }, {
                    &quot;value&quot;: &quot;crypto-related&quot;,
                    &quot;expanded&quot;: &quot;Cryptojacking, wallet draining, and fraudulent initial offerings or exchange breaches.&quot;
                }, {
                    &quot;value&quot;: &quot;cloud&quot;,
                    &quot;expanded&quot;: &quot;Exploits targeting container orchestration (Kubernetes), serverless functions, and CSP misconfigurations.&quot;
                }, {
                    &quot;value&quot;: &quot;insider-threat&quot;,
                    &quot;expanded&quot;: &quot;Malicious or accidental data exfiltration and system sabotage by authorized users.&quot;
                }, {
                    &quot;value&quot;: &quot;geopolitical&quot;,
                    &quot;expanded&quot;: &quot;Nation-state sponsored activity, cyber-espionage, and attacks linked to physical conflicts.&quot;
                }, {
                    &quot;value&quot;: &quot;api-security&quot;,
                    &quot;expanded&quot;: &quot;Vulnerabilities in REST/GraphQL endpoints, broken authentication, and mass assignment attacks.&quot;
                }
            ]
        }, {
            &quot;predicate&quot;: &quot;TA-category&quot;,
            &quot;entry&quot;: [{
                    &quot;value&quot;: &quot;APT&quot;,
					&quot;colour&quot;: &quot;#f1dfed&quot;,
                    &quot;expanded&quot;: &quot;Advance Persistent Threat&quot;
                }, {
                    &quot;value&quot;: &quot;State-Sponsored&quot;,
					&quot;colour&quot;: &quot;#f1dfed&quot;,
                    &quot;expanded&quot;: &quot;State Sponsored&quot;
                }, {
                    &quot;value&quot;: &quot;Cybercrime&quot;,
					&quot;colour&quot;: &quot;#f1dfed&quot;,
                    &quot;expanded&quot;: &quot;Cybercrime&quot;
                }, {
                    &quot;value&quot;: &quot;Ransomware&quot;,
					&quot;colour&quot;: &quot;#f1dfed&quot;,
                    &quot;expanded&quot;: &quot;Ransomware&quot;
                }, {
                    &quot;value&quot;: &quot;Hacktivist&quot;,
					&quot;colour&quot;: &quot;#f1dfed&quot;,
                    &quot;expanded&quot;: &quot;Hacktivist&quot;
                }
            ]
        }, {
            &quot;predicate&quot;: &quot;target&quot;,
            &quot;entry&quot;: [{
                    &quot;value&quot;: &quot;broad-based&quot;,
					&quot;colour&quot;: &quot;#ffd12e&quot;,
                    &quot;expanded&quot;: &quot;Broad based attacks&quot;
                }, {
                    &quot;value&quot;: &quot;targeted&quot;,
					&quot;colour&quot;: &quot;#d92121&quot;,
                    &quot;expanded&quot;: &quot;Targeted attacks&quot;
                }
            ]
        }, {
            &quot;predicate&quot;: &quot;samples-found-in&quot;,
            &quot;entry&quot;: [{
                    &quot;value&quot;: &quot;MalwareBazaar&quot;,
                    &quot;expanded&quot;: &quot;MalwareBazaar&quot;
                }, {
                    &quot;value&quot;: &quot;VirusTotal&quot;,
                    &quot;expanded&quot;: &quot;VirusTotal&quot;
                }, {
                    &quot;value&quot;: &quot;Tria.ge&quot;,
                    &quot;expanded&quot;: &quot;Tria.ge&quot;
                }
            ]
        }, {
            &quot;predicate&quot;: &quot;no-samples-in&quot;,
            &quot;entry&quot;: [{
                    &quot;value&quot;: &quot;MalwareBazaar&quot;,
					&quot;colour&quot;: &quot;#626567&quot;,
                    &quot;expanded&quot;: &quot;MalwareBazaar&quot;
                }, {
                    &quot;value&quot;: &quot;VirusTotal&quot;,
					&quot;colour&quot;: &quot;#626567&quot;,
                    &quot;expanded&quot;: &quot;VirusTotal&quot;
                }, {
                    &quot;value&quot;: &quot;Tria.ge&quot;,
					&quot;colour&quot;: &quot;#626567&quot;,
                    &quot;expanded&quot;: &quot;Tria.ge&quot;
                }
            ]
        }, {
            &quot;predicate&quot;: &quot;ioc&quot;,
            &quot;entry&quot;: [{
                    &quot;value&quot;: &quot;enriched&quot;,
                    &quot;expanded&quot;: &quot;IOC enriched&quot;
                }, {
                    &quot;value&quot;: &quot;no-detection-by-any-vendor&quot;,
                    &quot;expanded&quot;: &quot;No detection by any vendor&quot;
                }, {
                    &quot;value&quot;: &quot;low-detection-by-any-vendor&quot;,
                    &quot;expanded&quot;: &quot;Low detection by any vendor&quot;
                }
            ]
        }, {
            &quot;predicate&quot;: &quot;MY-relevancy&quot;,
            &quot;entry&quot;: [{
                    &quot;value&quot;: &quot;not-relevant&quot;,
					&quot;colour&quot;: &quot;#31373d&quot;,
                    &quot;expanded&quot;: &quot;Not relevant to Malaysia context - good to know&quot;
                }, {
                    &quot;value&quot;: &quot;potentially-relevant&quot;,
					&quot;colour&quot;: &quot;#55acee&quot;,
                    &quot;expanded&quot;: &quot;Potentially relevant to Malaysia context e.g. Infostealers impact globally&quot;
                }, {
                    &quot;value&quot;: &quot;somewhat-relevant&quot;,
					&quot;colour&quot;: &quot;#fdcb58&quot;,
                    &quot;expanded&quot;: &quot;Somewhat relevant to Malaysia context e.g. APT target Asian country.&quot;
                }, {
                    &quot;value&quot;: &quot;relevant&quot;,
					&quot;colour&quot;: &quot;#dd2e44&quot;,
                    &quot;expanded&quot;: &quot;Highly relevant to Malaysia context e.g. APT target Malaysia&quot;
                }
            ]
        }, {
            &quot;predicate&quot;: &quot;workflow&quot;,
            &quot;entry&quot;: [{
                    &quot;value&quot;: &quot;check-date&quot;,
                    &quot;expanded&quot;: &quot;Check article date&quot;
                }, {
                    &quot;value&quot;: &quot;review-severity&quot;,
                    &quot;expanded&quot;: &quot;Review Severity&quot;
                }, {
                    &quot;value&quot;: &quot;check-producer&quot;,
                    &quot;expanded&quot;: &quot;Check producer&quot;
                }, {
                    &quot;value&quot;: &quot;check-actor&quot;,
                    &quot;expanded&quot;: &quot;Check Threat Actor&quot;
                }, {
                    &quot;value&quot;: &quot;check-target&quot;,
                    &quot;expanded&quot;: &quot;Check Target&quot;
                }, {
                    &quot;value&quot;: &quot;check-tool&quot;,
                    &quot;expanded&quot;: &quot;Check Tools&quot;
                }, {
                    &quot;value&quot;: &quot;check-malware&quot;,
                    &quot;expanded&quot;: &quot;Check Malware&quot;
                }, {
                    &quot;value&quot;: &quot;check-TTP&quot;,
                    &quot;expanded&quot;: &quot;Check TTPs&quot;
                }, {
                    &quot;value&quot;: &quot;add-ioc-context&quot;,
                    &quot;expanded&quot;: &quot;Add IOC contexts&quot;
                }, {
                    &quot;value&quot;: &quot;check-key-indicator&quot;,
                    &quot;expanded&quot;: &quot;Check Key Indicator unique to TA&quot;
                }, {
                    &quot;value&quot;: &quot;enrichment&quot;,
                    &quot;expanded&quot;: &quot;Enrichment&quot;
                }, {
                    &quot;value&quot;: &quot;need-sample-sponsor&quot;,
                    &quot;expanded&quot;: &quot;Require Malware sample sponsor, either upload to Malware Bazaar (preferred) or upload directly to MISP(for sample with sensitive data)&quot;
                }, {
                    &quot;value&quot;: &quot;to-report-to&quot;,
                    &quot;expanded&quot;: &quot;To report to relevant parties such as the owner, hosting provider, MyCERT, registrar or etc.&quot;
                }
            ]
        }, {
            &quot;predicate&quot;: &quot;mitre-att&amp;#x26;ck&quot;,
            &quot;entry&quot;: [{
                    &quot;value&quot;: &quot;from-original-src&quot;,
					&quot;colour&quot;: &quot;#b94b1d&quot;,
                    &quot;expanded&quot;: &quot;TTPs included in original source&quot;
                }, {
                    &quot;value&quot;: &quot;none-from-src&quot;,
					&quot;colour&quot;: &quot;#b94b1d&quot;,
                    &quot;expanded&quot;: &quot;No TTPs included in original source&quot;
                }, {
                    &quot;value&quot;: &quot;from-OTX&quot;,
					&quot;colour&quot;: &quot;#b94b1d&quot;,
                    &quot;expanded&quot;: &quot;TTPs from OTX&quot;
                }, {
                    &quot;value&quot;: &quot;self-curated&quot;,
					&quot;colour&quot;: &quot;#b94b1d&quot;,
                    &quot;expanded&quot;: &quot;Self curated TTPs&quot;
                }
            ]
        }, {
            &quot;predicate&quot;: &quot;detection-rules&quot;,
            &quot;entry&quot;: [{
                    &quot;value&quot;: &quot;yara-from-src&quot;,
                    &quot;expanded&quot;: &quot;YARA from source&quot;
                }, {
                    &quot;value&quot;: &quot;sigma-from-src&quot;,
                    &quot;expanded&quot;: &quot;Sigma rules from source&quot;
                }, {
                    &quot;value&quot;: &quot;snort-from-src&quot;,
                    &quot;expanded&quot;: &quot;Snort rule from source&quot;
                }, {
                    &quot;value&quot;: &quot;yara-from-VT&quot;,
                    &quot;expanded&quot;: &quot;YARA from VirusTotal&quot;
                }, {
                    &quot;value&quot;: &quot;sigma-from-VT&quot;,
                    &quot;expanded&quot;: &quot;Sigma rules from source&quot;
                }
            ]
        }, {
            &quot;predicate&quot;: &quot;action-taken&quot;,
            &quot;entry&quot;: [{
                    &quot;value&quot;: &quot;VT-collection&quot;,
                    &quot;expanded&quot;: &quot;Added to VT Collection&quot;
                }, {
                    &quot;value&quot;: &quot;VT-comment&quot;,
                    &quot;expanded&quot;: &quot;Added to VT comment&quot;
                }, {
                    &quot;value&quot;: &quot;github&quot;,
                    &quot;expanded&quot;: &quot;Added to Github&quot;
                }, {
                    &quot;value&quot;: &quot;diamond-model&quot;,
                    &quot;expanded&quot;: &quot;Created Diamond Model&quot;
                }, {
                    &quot;value&quot;: &quot;x&quot;,
                    &quot;expanded&quot;: &quot;Shared to X&quot;
                }, {
                    &quot;value&quot;: &quot;linkedin&quot;,
                    &quot;expanded&quot;: &quot;Shared to Linkedin&quot;
                }, {
                    &quot;value&quot;: &quot;tiktok&quot;,
                    &quot;expanded&quot;: &quot;Shared to Tiktok&quot;
                }, {
                    &quot;value&quot;: &quot;medium&quot;,
                    &quot;expanded&quot;: &quot;Shared to Medium&quot;
                }, {
                    &quot;value&quot;: &quot;telegram&quot;,
                    &quot;expanded&quot;: &quot;Shared to Telegram&quot;
                }, {
                    &quot;value&quot;: &quot;threatfox&quot;,
                    &quot;expanded&quot;: &quot;Added to ThreatFox&quot;
                }, {
                    &quot;value&quot;: &quot;malwarebazaar&quot;,
                    &quot;expanded&quot;: &quot;Added to MalwareBazaar&quot;
                }, {
                    &quot;value&quot;: &quot;phishtank&quot;,
                    &quot;expanded&quot;: &quot;Added to PhishTank&quot;
                }, {
                    &quot;value&quot;: &quot;report-to-mycert&quot;,
                    &quot;expanded&quot;: &quot;Reported to MyCERT&quot;
                }, {
                    &quot;value&quot;: &quot;report-to-hosting-provider&quot;,
                    &quot;expanded&quot;: &quot;Reported to Hosting Provider&quot;
                }, {
                    &quot;value&quot;: &quot;report-to-registrar&quot;,
                    &quot;expanded&quot;: &quot;Reported to Registrar&quot;
                }, {
                    &quot;value&quot;: &quot;urlhaus&quot;,
                    &quot;expanded&quot;: &quot;Added to URLHaus&quot;
                }, {
                    &quot;value&quot;: &quot;urlscan.io&quot;,
                    &quot;expanded&quot;: &quot;Added to urlscan.io&quot;
                }, {
                    &quot;value&quot;: &quot;report-google-safe-browsing&quot;,
                    &quot;expanded&quot;: &quot;Reported to Google Safe Browsing&quot;
                }
            ]
        }
    ]
}
&lt;/code&gt;&lt;/pre&gt;
&lt;/details&gt;
&lt;h2 id=&quot;setting-up-galaxies&quot;&gt;Setting up Galaxies&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#setting-up-galaxies&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;h3 id=&quot;disable-unnecessary-galaxies&quot;&gt;Disable unnecessary Galaxies&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#disable-unnecessary-galaxies&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h3&gt;
&lt;details&gt;
&lt;summary&gt;Disable the following unnecessary galaxies&lt;/summary&gt;
&lt;ul class=&quot;contains-task-list&quot;&gt;
&lt;li class=&quot;task-list-item&quot;&gt;&lt;input type=&quot;checkbox&quot; class=&quot;checkbox-toggle&quot;&gt; All under ‘deprecated’ namespace&lt;/li&gt;
&lt;li class=&quot;task-list-item&quot;&gt;&lt;input type=&quot;checkbox&quot; class=&quot;checkbox-toggle&quot;&gt; Ammunitions&lt;/li&gt;
&lt;li class=&quot;task-list-item&quot;&gt;&lt;input type=&quot;checkbox&quot; class=&quot;checkbox-toggle&quot;&gt; Busy is the New Stupid framework&lt;/li&gt;
&lt;li class=&quot;task-list-item&quot;&gt;&lt;input type=&quot;checkbox&quot; class=&quot;checkbox-toggle&quot;&gt; Cancer&lt;/li&gt;
&lt;li class=&quot;task-list-item&quot;&gt;&lt;input type=&quot;checkbox&quot; class=&quot;checkbox-toggle&quot;&gt; Cert EU GovSector&lt;/li&gt;
&lt;li class=&quot;task-list-item&quot;&gt;&lt;input type=&quot;checkbox&quot; class=&quot;checkbox-toggle&quot;&gt; Election guidelines&lt;/li&gt;
&lt;li class=&quot;task-list-item&quot;&gt;&lt;input type=&quot;checkbox&quot; class=&quot;checkbox-toggle&quot;&gt; Firearms&lt;/li&gt;
&lt;li class=&quot;task-list-item&quot;&gt;&lt;input type=&quot;checkbox&quot; class=&quot;checkbox-toggle&quot;&gt; Handicap&lt;/li&gt;
&lt;li class=&quot;task-list-item&quot;&gt;&lt;input type=&quot;checkbox&quot; class=&quot;checkbox-toggle&quot;&gt; NACE&lt;/li&gt;
&lt;li class=&quot;task-list-item&quot;&gt;&lt;input type=&quot;checkbox&quot; class=&quot;checkbox-toggle&quot;&gt; NAICS&lt;/li&gt;
&lt;li class=&quot;task-list-item&quot;&gt;&lt;input type=&quot;checkbox&quot; class=&quot;checkbox-toggle&quot;&gt; Tea Matrix&lt;/li&gt;
&lt;li class=&quot;task-list-item&quot;&gt;&lt;input type=&quot;checkbox&quot; class=&quot;checkbox-toggle&quot;&gt; UAVs/UCAVs&lt;/li&gt;
&lt;li class=&quot;task-list-item&quot;&gt;&lt;input type=&quot;checkbox&quot; class=&quot;checkbox-toggle&quot;&gt; UKHSA Culture Collections&lt;/li&gt;
&lt;/ul&gt;
&lt;/details&gt;
&lt;h2 id=&quot;dashboard&quot;&gt;Dashboard&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#dashboard&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;details&gt;
&lt;summary&gt;Import following dashboard config&lt;/summary&gt;
&lt;pre&gt;&lt;code&gt;{
    &quot;UserSetting&quot;: {
        &quot;id&quot;: &quot;1&quot;,
        &quot;setting&quot;: &quot;dashboard&quot;,
        &quot;value&quot;: [
            {
                &quot;widget&quot;: &quot;MispStatusWidget&quot;,
                &quot;config&quot;: [],
                &quot;position&quot;: {
                    &quot;x&quot;: &quot;10&quot;,
                    &quot;y&quot;: &quot;10&quot;,
                    &quot;width&quot;: &quot;2&quot;,
                    &quot;height&quot;: &quot;2&quot;
                }
            },
            {
                &quot;widget&quot;: &quot;TrendingTagsWidget&quot;,
                &quot;config&quot;: {
                    &quot;alias&quot;: &quot;Top Category [Threat, Data Breach, Vulnerability]&quot;,
                    &quot;time_window&quot;: &quot;-1&quot;,
                    &quot;include&quot;: [
                        &quot;rectifyq:category&quot;
                    ]
                },
                &quot;position&quot;: {
                    &quot;x&quot;: &quot;0&quot;,
                    &quot;y&quot;: &quot;0&quot;,
                    &quot;width&quot;: &quot;3&quot;,
                    &quot;height&quot;: &quot;2&quot;
                }
            },
            {
                &quot;widget&quot;: &quot;AuthenticationFailureWidget&quot;,
                &quot;config&quot;: [],
                &quot;position&quot;: {
                    &quot;x&quot;: &quot;10&quot;,
                    &quot;y&quot;: &quot;7&quot;,
                    &quot;width&quot;: &quot;2&quot;,
                    &quot;height&quot;: &quot;1&quot;
                }
            },
            {
                &quot;widget&quot;: &quot;MispAdminWorkerWidget&quot;,
                &quot;config&quot;: [],
                &quot;position&quot;: {
                    &quot;x&quot;: &quot;10&quot;,
                    &quot;y&quot;: &quot;0&quot;,
                    &quot;width&quot;: &quot;2&quot;,
                    &quot;height&quot;: &quot;7&quot;
                }
            },
            {
                &quot;widget&quot;: &quot;TrendingTagsWidget&quot;,
                &quot;config&quot;: {
                    &quot;alias&quot;: &quot;Top Sub-Category&quot;,
                    &quot;time_window&quot;: &quot;-1&quot;,
                    &quot;include&quot;: [
                        &quot;rectifyq:sub-category&quot;
                    ]
                },
                &quot;position&quot;: {
                    &quot;x&quot;: &quot;0&quot;,
                    &quot;y&quot;: &quot;2&quot;,
                    &quot;width&quot;: &quot;3&quot;,
                    &quot;height&quot;: &quot;3&quot;
                }
            },
            {
                &quot;widget&quot;: &quot;TrendingTagsWidget&quot;,
                &quot;config&quot;: {
                    &quot;alias&quot;: &quot;Top Relevancy&quot;,
                    &quot;time_window&quot;: &quot;-1&quot;,
                    &quot;include&quot;: [
                        &quot;rectifyq:MY-relevancy&quot;
                    ]
                },
                &quot;position&quot;: {
                    &quot;x&quot;: &quot;0&quot;,
                    &quot;y&quot;: &quot;5&quot;,
                    &quot;width&quot;: &quot;3&quot;,
                    &quot;height&quot;: &quot;2&quot;
                }
            },
            {
                &quot;widget&quot;: &quot;TrendingTagsWidget&quot;,
                &quot;config&quot;: {
                    &quot;alias&quot;: &quot;Top TA-Category&quot;,
                    &quot;time_window&quot;: &quot;-1&quot;,
                    &quot;include&quot;: [
                        &quot;rectifyq:TA-category&quot;
                    ]
                },
                &quot;position&quot;: {
                    &quot;x&quot;: &quot;0&quot;,
                    &quot;y&quot;: &quot;7&quot;,
                    &quot;width&quot;: &quot;3&quot;,
                    &quot;height&quot;: &quot;2&quot;
                }
            },
            {
                &quot;widget&quot;: &quot;TrendingTagsWidget&quot;,
                &quot;config&quot;: {
                    &quot;alias&quot;: &quot;Top MITRE ATT&amp;#x26;CK&quot;,
                    &quot;time_window&quot;: &quot;-1&quot;,
                    &quot;include&quot;: [
                        &quot;rectifyq:mitre-att&amp;#x26;ck&quot;
                    ]
                },
                &quot;position&quot;: {
                    &quot;x&quot;: &quot;0&quot;,
                    &quot;y&quot;: &quot;9&quot;,
                    &quot;width&quot;: &quot;3&quot;,
                    &quot;height&quot;: &quot;3&quot;
                }
            },
            {
                &quot;widget&quot;: &quot;APIActivityWidget&quot;,
                &quot;config&quot;: [],
                &quot;position&quot;: {
                    &quot;x&quot;: &quot;10&quot;,
                    &quot;y&quot;: &quot;8&quot;,
                    &quot;width&quot;: &quot;2&quot;,
                    &quot;height&quot;: &quot;1&quot;
                }
            },
            {
                &quot;widget&quot;: &quot;LoginsWidget&quot;,
                &quot;config&quot;: [],
                &quot;position&quot;: {
                    &quot;x&quot;: &quot;10&quot;,
                    &quot;y&quot;: &quot;9&quot;,
                    &quot;width&quot;: &quot;2&quot;,
                    &quot;height&quot;: &quot;1&quot;
                }
            },
            {
                &quot;widget&quot;: &quot;TrendingTagsWidget&quot;,
                &quot;config&quot;: {
                    &quot;alias&quot;: &quot;Top Producer&quot;,
                    &quot;time_window&quot;: &quot;-1&quot;,
                    &quot;include&quot;: [
                        &quot;misp-galaxy:producer=&quot;
                    ],
                    &quot;threshold&quot;: 100
                },
                &quot;position&quot;: {
                    &quot;x&quot;: &quot;3&quot;,
                    &quot;y&quot;: &quot;0&quot;,
                    &quot;width&quot;: &quot;3&quot;,
                    &quot;height&quot;: &quot;15&quot;
                }
            },
            {
                &quot;widget&quot;: &quot;TrendingTagsWidget&quot;,
                &quot;config&quot;: {
                    &quot;alias&quot;: &quot;Top Detection Included&quot;,
                    &quot;time_window&quot;: &quot;-1&quot;,
                    &quot;include&quot;: [
                        &quot;rectifyq:detection&quot;
                    ]
                },
                &quot;position&quot;: {
                    &quot;x&quot;: &quot;0&quot;,
                    &quot;y&quot;: &quot;12&quot;,
                    &quot;width&quot;: &quot;3&quot;,
                    &quot;height&quot;: &quot;3&quot;
                }
            },
            {
                &quot;widget&quot;: &quot;TrendingTagsWidget&quot;,
                &quot;config&quot;: {
                    &quot;alias&quot;: &quot;Top Ransomware&quot;,
                    &quot;time_window&quot;: &quot;-1&quot;,
                    &quot;include&quot;: [
                        &quot;misp-galaxy:ransomware=&quot;
                    ],
                    &quot;threshold&quot;: &quot;100&quot;
                },
                &quot;position&quot;: {
                    &quot;x&quot;: &quot;6&quot;,
                    &quot;y&quot;: &quot;5&quot;,
                    &quot;width&quot;: &quot;2&quot;,
                    &quot;height&quot;: &quot;10&quot;
                }
            },
            {
                &quot;widget&quot;: &quot;TrendingTagsWidget&quot;,
                &quot;config&quot;: {
                    &quot;alias&quot;: &quot;Top 10 Malpedia&quot;,
                    &quot;time_window&quot;: &quot;-1&quot;,
                    &quot;include&quot;: [
                        &quot;misp-galaxy:malpedia=&quot;
                    ],
                    &quot;threshold&quot;: &quot;10&quot;
                },
                &quot;position&quot;: {
                    &quot;x&quot;: &quot;6&quot;,
                    &quot;y&quot;: &quot;0&quot;,
                    &quot;width&quot;: &quot;2&quot;,
                    &quot;height&quot;: &quot;5&quot;
                }
            },
            {
                &quot;widget&quot;: &quot;TrendingTagsWidget&quot;,
                &quot;config&quot;: {
                    &quot;alias&quot;: &quot;Threat Actor&quot;,
                    &quot;time_window&quot;: &quot;-1&quot;,
                    &quot;include&quot;: [
                        &quot;misp-galaxy:threat-actor=&quot;
                    ],
                    &quot;threshold&quot;: &quot;100&quot;
                },
                &quot;position&quot;: {
                    &quot;x&quot;: &quot;8&quot;,
                    &quot;y&quot;: &quot;0&quot;,
                    &quot;width&quot;: &quot;2&quot;,
                    &quot;height&quot;: &quot;15&quot;
                }
            }
        ],
        &quot;user_id&quot;: &quot;1&quot;,
        &quot;timestamp&quot;: &quot;1742012921&quot;
    }
}
&lt;/code&gt;&lt;/pre&gt;
&lt;/details&gt;
&lt;h2 id=&quot;enable-plugins&quot;&gt;Enable Plugins&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#enable-plugins&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;details&gt;
&lt;summary&gt;Enrichment&lt;/summary&gt;
&lt;ul class=&quot;contains-task-list&quot;&gt;
&lt;li class=&quot;task-list-item&quot;&gt;&lt;input type=&quot;checkbox&quot; class=&quot;checkbox-toggle&quot;&gt; Plugin.Enrichment_vulnerability_lookup_enabled&lt;/li&gt;
&lt;li class=&quot;task-list-item&quot;&gt;&lt;input type=&quot;checkbox&quot; class=&quot;checkbox-toggle&quot;&gt; Plugin.Enrichment_html_to_markdown_enabled&lt;/li&gt;
&lt;li class=&quot;task-list-item&quot;&gt;&lt;input type=&quot;checkbox&quot; class=&quot;checkbox-toggle&quot;&gt; Plugin.Enrichment_extract_url_components_enabled&lt;/li&gt;
&lt;li class=&quot;task-list-item&quot;&gt;&lt;input type=&quot;checkbox&quot; class=&quot;checkbox-toggle&quot;&gt; Plugin.Enrichment_mmdb_lookup_enabled&lt;/li&gt;
&lt;/ul&gt;
&lt;/details&gt;
&lt;details&gt;
&lt;summary&gt;Import&lt;/summary&gt;
&lt;ul class=&quot;contains-task-list&quot;&gt;
&lt;li class=&quot;task-list-item&quot;&gt;&lt;input type=&quot;checkbox&quot; class=&quot;checkbox-toggle&quot;&gt; Plugin.Import_csvimport_enabled&lt;/li&gt;
&lt;li class=&quot;task-list-item&quot;&gt;&lt;input type=&quot;checkbox&quot; class=&quot;checkbox-toggle&quot;&gt; Plugin.Import_ocr_enabled&lt;/li&gt;
&lt;li class=&quot;task-list-item&quot;&gt;&lt;input type=&quot;checkbox&quot; class=&quot;checkbox-toggle&quot;&gt; Plugin.Import_mispjson_enabled&lt;/li&gt;
&lt;/ul&gt;
&lt;/details&gt;
&lt;details&gt;
&lt;summary&gt;Export&lt;/summary&gt;
&lt;/details&gt;
&lt;h2 id=&quot;enable-warning-list&quot;&gt;Enable Warning List&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#enable-warning-list&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;details&gt;
&lt;summary&gt;Warning List&lt;/summary&gt;
&lt;ul class=&quot;contains-task-list&quot;&gt;
&lt;li class=&quot;task-list-item&quot;&gt;
&lt;p&gt;&lt;input type=&quot;checkbox&quot; class=&quot;checkbox-toggle&quot;&gt; List of known hashes with common false-positives (based on Florian Roth input list)&lt;/p&gt;
&lt;/li&gt;
&lt;li class=&quot;task-list-item&quot;&gt;
&lt;p&gt;&lt;input type=&quot;checkbox&quot; class=&quot;checkbox-toggle&quot;&gt; List of known hashes for empty files&lt;/p&gt;
&lt;/li&gt;
&lt;li class=&quot;task-list-item&quot;&gt;
&lt;p&gt;&lt;input type=&quot;checkbox&quot; class=&quot;checkbox-toggle&quot;&gt; List of known Windows 10 connection endpoints&lt;/p&gt;
&lt;/li&gt;
&lt;li class=&quot;task-list-item&quot;&gt;
&lt;p&gt;&lt;input type=&quot;checkbox&quot; class=&quot;checkbox-toggle&quot;&gt; List of known Office 365 IP address ranges&lt;/p&gt;
&lt;/li&gt;
&lt;li class=&quot;task-list-item&quot;&gt;
&lt;p&gt;&lt;input type=&quot;checkbox&quot; class=&quot;checkbox-toggle&quot;&gt; List of known Office 365 IP address ranges in China&lt;/p&gt;
&lt;/li&gt;
&lt;li class=&quot;task-list-item&quot;&gt;
&lt;p&gt;&lt;input type=&quot;checkbox&quot; class=&quot;checkbox-toggle&quot;&gt; cisco-umbrella-blockpage-ipv4&lt;/p&gt;
&lt;/li&gt;
&lt;li class=&quot;task-list-item&quot;&gt;
&lt;p&gt;&lt;input type=&quot;checkbox&quot; class=&quot;checkbox-toggle&quot;&gt; List of RFC 1918 CIDR blocks&lt;/p&gt;
&lt;/li&gt;
&lt;li class=&quot;task-list-item&quot;&gt;
&lt;p&gt;&lt;input type=&quot;checkbox&quot; class=&quot;checkbox-toggle&quot;&gt; List of RFC 5735 CIDR blocks&lt;/p&gt;
&lt;/li&gt;
&lt;li class=&quot;task-list-item&quot;&gt;
&lt;p&gt;&lt;input type=&quot;checkbox&quot; class=&quot;checkbox-toggle&quot;&gt; RFC 6598 CIDR blocks&lt;/p&gt;
&lt;/li&gt;
&lt;li class=&quot;task-list-item&quot;&gt;
&lt;p&gt;&lt;input type=&quot;checkbox&quot; class=&quot;checkbox-toggle&quot;&gt; List of known Apple IP ranges&lt;/p&gt;
&lt;/li&gt;
&lt;li class=&quot;task-list-item&quot;&gt;
&lt;p&gt;&lt;input type=&quot;checkbox&quot; class=&quot;checkbox-toggle&quot;&gt; Censys IP Ranges Used for Scanning&lt;/p&gt;
&lt;/li&gt;
&lt;li class=&quot;task-list-item&quot;&gt;
&lt;p&gt;&lt;input type=&quot;checkbox&quot; class=&quot;checkbox-toggle&quot;&gt; Shodan IP Ranges Used for Scanning&lt;/p&gt;
&lt;/li&gt;
&lt;li class=&quot;task-list-item&quot;&gt;
&lt;p&gt;&lt;input type=&quot;checkbox&quot; class=&quot;checkbox-toggle&quot;&gt; List of known Cloudflare IP ranges&lt;/p&gt;
&lt;/li&gt;
&lt;li class=&quot;task-list-item&quot;&gt;
&lt;p&gt;&lt;input type=&quot;checkbox&quot; class=&quot;checkbox-toggle&quot;&gt; List of known Zscaler IP address ranges&lt;/p&gt;
&lt;/li&gt;
&lt;li class=&quot;task-list-item&quot;&gt;
&lt;p&gt;&lt;input type=&quot;checkbox&quot; class=&quot;checkbox-toggle&quot;&gt; Parking domains&lt;/p&gt;
&lt;/li&gt;
&lt;li class=&quot;task-list-item&quot;&gt;
&lt;p&gt;&lt;input type=&quot;checkbox&quot; class=&quot;checkbox-toggle&quot;&gt; Parking domains name server&lt;/p&gt;
&lt;/li&gt;
&lt;li class=&quot;task-list-item&quot;&gt;
&lt;p&gt;&lt;input type=&quot;checkbox&quot; class=&quot;checkbox-toggle&quot;&gt; List of known microsoft domains&lt;/p&gt;
&lt;/li&gt;
&lt;li class=&quot;task-list-item&quot;&gt;
&lt;p&gt;&lt;input type=&quot;checkbox&quot; class=&quot;checkbox-toggle&quot;&gt; Captive Portal Detection Hostnames&lt;/p&gt;
&lt;/li&gt;
&lt;li class=&quot;task-list-item&quot;&gt;
&lt;p&gt;&lt;input type=&quot;checkbox&quot; class=&quot;checkbox-toggle&quot;&gt; List of known google domains&lt;/p&gt;
&lt;/li&gt;
&lt;li class=&quot;task-list-item&quot;&gt;
&lt;p&gt;&lt;input type=&quot;checkbox&quot; class=&quot;checkbox-toggle&quot;&gt; List of known Office 365 URLs&lt;/p&gt;
&lt;/li&gt;
&lt;li class=&quot;task-list-item&quot;&gt;
&lt;p&gt;&lt;input type=&quot;checkbox&quot; class=&quot;checkbox-toggle&quot;&gt; Top 1000 website from Alexa&lt;/p&gt;
&lt;/li&gt;
&lt;li class=&quot;task-list-item&quot;&gt;
&lt;p&gt;&lt;input type=&quot;checkbox&quot; class=&quot;checkbox-toggle&quot;&gt; List of known URL Shorteners domains&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/details&gt;
&lt;h2 id=&quot;optional-enforce-mfa&quot;&gt;Optional: Enforce MFA&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#optional-enforce-mfa&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Administration &gt; Server Settings &amp;#x26; Maintenance &gt; Security&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;Security.otp_disabled False
&lt;strong&gt;Security.otp_required True
&lt;/strong&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;h2 id=&quot;change-os-timezone&quot;&gt;Change OS Timezone&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#change-os-timezone&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;pre&gt;&lt;code&gt;timedatectl list-timezones
sudo timedatectl set-timezone Asia/Kuala_Lumpur
&lt;/code&gt;&lt;/pre&gt; ]]></description>
    <pubDate>Thu, 12 Feb 2026 08:32:17 GMT</pubDate>
  </item><item>
    <title>Installing MISP + MISP Module</title>
    <link>https://rectifyq.com/Threat-Intelligence-Platform-(TIP)/Install-Your-Own-TIP/install-MISP</link>
    <guid>https://rectifyq.com/Threat-Intelligence-Platform-(TIP)/Install-Your-Own-TIP/install-MISP</guid>
    <description><![CDATA[ &lt;h1 id=&quot;installing-misp--misp-module&quot;&gt;Installing MISP + MISP Module&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#installing-misp--misp-module&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h1&gt;
&lt;h2 id=&quot;ubuntu-2404&quot;&gt;Ubuntu 24.04&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#ubuntu-2404&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Download and install Ubuntu 24.04 from &lt;a href=&quot;https://ubuntu.com/download/server/thank-you?version=24.04.1&amp;#x26;architecture=amd64&amp;#x26;lts=true&quot; class=&quot;external&quot;&gt;here&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;You can use any virtualization method you are familiar with such as Virtualbox, VMware Workstation, Hyper-V, etc.&lt;/p&gt;
&lt;p&gt;My resource setup for this homelab MISP:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;vCPU: 2
RAM: 2GB (Recommended 4GB above)
Disk: 60GB
&lt;/code&gt;&lt;/pre&gt;
&lt;h2 id=&quot;update--upgrade&quot;&gt;Update &amp;#x26;&amp;#x26; Upgrade&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#update--upgrade&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;pre&gt;&lt;code&gt;sudo apt-get update -y &amp;#x26;&amp;#x26; sudo apt-get upgrade -y
&lt;/code&gt;&lt;/pre&gt;
&lt;h2 id=&quot;installing-misp-25&quot;&gt;Installing MISP 2.5&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#installing-misp-25&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;pre&gt;&lt;code&gt;wget --no-cache -O /tmp/INSTALL.sh https://raw.githubusercontent.com/MISP/MISP/refs/heads/2.5/INSTALL/INSTALL.ubuntu2404.sh
&lt;/code&gt;&lt;/pre&gt;
&lt;pre&gt;&lt;code&gt;sudo bash /tmp/INSTALL.sh
&lt;/code&gt;&lt;/pre&gt;
&lt;figure&gt;&lt;img src=&quot;https://miro.medium.com/v2/resize:fit:700/1*WquYSH3h3JlLU5Vt57RVaw.png&quot; alt=&quot;&quot; height=&quot;342&quot; width=&quot;700&quot;&gt;&lt;figcaption&gt;&lt;/figcaption&gt;&lt;/figure&gt;
&lt;figure&gt;&lt;img src=&quot;https://miro.medium.com/v2/resize:fit:700/1*E4CPtRvuZcs7hfWnqc8nnA.png&quot; alt=&quot;&quot; height=&quot;110&quot; width=&quot;700&quot;&gt;&lt;figcaption&gt;&lt;/figcaption&gt;&lt;/figure&gt;
&lt;h2 id=&quot;change-baseurl&quot;&gt;Change BaseURL&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#change-baseurl&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Depending on how you host this MISP and the network adapter config (NAT/Bridge/etc.), change it accordingly&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;sudo -u www-data /var/www/MISP/app/Console/cake admin setSetting MISP.baseurl https://your-ip-or-domain.com
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Login and change your password.&lt;/p&gt;
&lt;figure&gt;&lt;img src=&quot;https://miro.medium.com/v2/resize:fit:700/1*wIHLPHRN-13SnfSPBksu1g.png&quot; alt=&quot;&quot; height=&quot;425&quot; width=&quot;700&quot;&gt;&lt;figcaption&gt;&lt;/figcaption&gt;&lt;/figure&gt;
&lt;h2 id=&quot;install-misp-modules&quot;&gt;Install MISP Modules&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#install-misp-modules&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;pre&gt;&lt;code&gt;sudo -u www-data virtualenv -p python3 /var/www/MISP/venv
&lt;/code&gt;&lt;/pre&gt;
&lt;pre&gt;&lt;code&gt;sudo apt-get install python3-dev python3-pip libpq5 libjpeg-dev tesseract-ocr libpoppler-cpp-dev pkg-config imagemagick virtualenv libopencv-dev zbar-tools libzbar0 libzbar-dev libfuzzy-dev build-essential -y
&lt;/code&gt;&lt;/pre&gt;
&lt;pre&gt;&lt;code&gt;sudo -u www-data /var/www/MISP/venv/bin/pip install misp-modules
&lt;/code&gt;&lt;/pre&gt;
&lt;pre&gt;&lt;code&gt;sudo -u www-data /var/www/MISP/venv/bin/pip install \
    git+https://github.com/cartertemm/ODTReader.git \
    git+https://github.com/abenassi/Google-Search-API \
    git+https://github.com/SteveClement/trustar-python.git \
    git+https://github.com/sebdraven/pydnstrails.git \
    git+https://github.com/sebdraven/pyonyphe.git
&lt;/code&gt;&lt;/pre&gt;
&lt;pre&gt;&lt;code&gt;sudo nano /etc/systemd/system/misp-modules.service
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Then write the following in the file&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;[Unit]
Description=MISP modules
After=network.target

[Service]
User=www-data
Group=www-data
Environment=&quot;PATH=/var/www/MISP/venv/bin/&quot;
ExecStart=/var/www/MISP/venv/bin/misp-modules -l 127.0.0.1
Restart=always


[Install]
WantedBy=multi-user.target
&lt;/code&gt;&lt;/pre&gt;
&lt;pre&gt;&lt;code&gt;sudo chmod 774 /etc/systemd/system/misp-modules.service
&lt;/code&gt;&lt;/pre&gt;
&lt;pre&gt;&lt;code&gt;sudo systemctl daemon-reload
&lt;/code&gt;&lt;/pre&gt;
&lt;pre&gt;&lt;code&gt;sudo systemctl enable --now misp-modules
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Enable it in Administration &gt; Server Settings &amp;#x26; Maintenance &gt; Plugins&lt;/p&gt;
&lt;figure&gt;&lt;img src=&quot;https://miro.medium.com/v2/resize:fit:700/1*P0cqg6Qh1nesyA7VnRFQvg.png&quot; alt=&quot;&quot; height=&quot;272&quot; width=&quot;700&quot;&gt;&lt;figcaption&gt;&lt;/figcaption&gt;&lt;/figure&gt; ]]></description>
    <pubDate>Thu, 12 Feb 2026 08:32:17 GMT</pubDate>
  </item><item>
    <title>Threat Intelligence Platform</title>
    <link>https://rectifyq.com/Threat-Intelligence-Platform-(TIP)/</link>
    <guid>https://rectifyq.com/Threat-Intelligence-Platform-(TIP)/</guid>
    <description><![CDATA[ &lt;p&gt;Rectifyq utilizes MISP for Threat Intelligence Platform (TIP)&lt;/p&gt; ]]></description>
    <pubDate>Thu, 12 Feb 2026 08:32:17 GMT</pubDate>
  </item><item>
    <title>Contact Us</title>
    <link>https://rectifyq.com/contact</link>
    <guid>https://rectifyq.com/contact</guid>
    <description><![CDATA[ &lt;h1 id=&quot;connect-with-rectifyq&quot;&gt;Connect with Rectifyq&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#connect-with-rectifyq&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h1&gt;
&lt;p&gt;Whether you’re a CISO looking for a strategic briefing, a SOC analyst needing &lt;a href=&quot;./API&quot; class=&quot;internal&quot; data-slug=&quot;API&quot;&gt;API&lt;/a&gt; support, or a student wanting to learn more about the Malaysian threat landscape—we’re here to help.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;how-can-we-help&quot;&gt;How can we help?&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#how-can-we-help&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;blockquote class=&quot;callout info&quot; data-callout=&quot;info&quot;&gt;
&lt;div class=&quot;callout-title&quot;&gt;
                  &lt;div class=&quot;callout-icon&quot;&gt;&lt;/div&gt;
                  &lt;div class=&quot;callout-title-inner&quot;&gt;&lt;p&gt; &lt;strong&gt;General Inquiries&lt;/strong&gt;&lt;/p&gt;&lt;/div&gt;
                  
                &lt;/div&gt;
&lt;div class=&quot;callout-content&quot;&gt;
&lt;p&gt;For partnerships, media requests, or just to say &lt;em&gt;Salam&lt;/em&gt;, drop us an email:
📧 &lt;strong&gt;&lt;a href=&quot;mailto:hello@rectifyq.com&quot; class=&quot;external&quot;&gt;hello@rectifyq.com&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/blockquote&gt;
&lt;blockquote class=&quot;callout code&quot; data-callout=&quot;code&quot;&gt;
&lt;div class=&quot;callout-title&quot;&gt;
                  &lt;div class=&quot;callout-icon&quot;&gt;&lt;/div&gt;
                  &lt;div class=&quot;callout-title-inner&quot;&gt;&lt;p&gt; &lt;strong&gt;API &amp;#x26; Technical Support&lt;/strong&gt;&lt;/p&gt;&lt;/div&gt;
                  
                &lt;/div&gt;
&lt;div class=&quot;callout-content&quot;&gt;
&lt;p&gt;Need help integrating our MISP feeds into your SIEM? Our engineering team is on standby.
📧 &lt;strong&gt;&lt;a href=&quot;mailto:support@rectifyq.com&quot; class=&quot;external&quot;&gt;support@rectifyq.com&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/strong&gt;
🛠️ Check out our &lt;a href=&quot;./API-Documentation&quot; class=&quot;internal&quot; data-slug=&quot;API-Documentation&quot;&gt;API-Documentation&lt;/a&gt; first!&lt;/p&gt;
&lt;/div&gt;
&lt;/blockquote&gt;
&lt;blockquote class=&quot;callout danger&quot; data-callout=&quot;danger&quot;&gt;
&lt;div class=&quot;callout-title&quot;&gt;
                  &lt;div class=&quot;callout-icon&quot;&gt;&lt;/div&gt;
                  &lt;div class=&quot;callout-title-inner&quot;&gt;&lt;p&gt; &lt;strong&gt;Report a Local Incident&lt;/strong&gt;&lt;/p&gt;&lt;/div&gt;
                  
                &lt;/div&gt;
&lt;div class=&quot;callout-content&quot;&gt;
&lt;p&gt;Found a new APK scam or a phishing domain targeting a Malaysian bank? Let’s analyze it together.
&lt;em&gt;Note: We are a private CTI entity. For official government reporting, please also contact &lt;a href=&quot;https://www.nacsa.gov.my&quot; class=&quot;external&quot;&gt;NACSA&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; or &lt;a href=&quot;https://www.mycert.org.my&quot; class=&quot;external&quot;&gt;Cyber999&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;.&lt;/em&gt;
📧 &lt;strong&gt;&lt;a href=&quot;mailto:phishing@rectifyq.com&quot; class=&quot;external&quot;&gt;phishing@rectifyq.com&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;/div&gt;
&lt;/blockquote&gt;
&lt;hr&gt;
&lt;h2 id=&quot;community--socials&quot;&gt;Community &amp;#x26; Socials&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#community--socials&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;We believe in “connecting the dots” together. Follow our latest deep dives and technical breakdowns on our social channels:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Medium:&lt;/strong&gt; &lt;a href=&quot;https://medium.com/@rectifyq&quot; class=&quot;external&quot;&gt;Rectifyq Lab&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; (Deep technical TTP breakdowns)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LinkedIn:&lt;/strong&gt; &lt;a href=&quot;https://linkedin.com/company/rectifyq&quot; class=&quot;external&quot;&gt;Rectifyq Malaysia&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; (CISO-level updates &amp;#x26; news)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Telegram:&lt;/strong&gt; &lt;a href=&quot;https://t.me/rectifyq&quot; class=&quot;external&quot;&gt;t.me/rectifyq&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; (Real-time local IoC alerts)&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;
&lt;p&gt;&lt;strong&gt;Looking for data right now?&lt;/strong&gt; Search our &lt;a href=&quot;./MY-Threat-Landscape&quot; class=&quot;internal alias&quot; data-slug=&quot;MY-Threat-Landscape&quot;&gt;MY Threat Landscape&lt;/a&gt;.&lt;/p&gt; ]]></description>
    <pubDate>Thu, 12 Feb 2026 08:32:17 GMT</pubDate>
  </item><item>
    <title>Resources</title>
    <link>https://rectifyq.com/resources</link>
    <guid>https://rectifyq.com/resources</guid>
    <description><![CDATA[ &lt;h1 id=&quot;the-rectifyq-toolbox&quot;&gt;The Rectifyq Toolbox&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#the-rectifyq-toolbox&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h1&gt;
&lt;p&gt;To move from “collecting data” to “producing intelligence,” you need the right tools and a structured approach. This page centralizes the resources we use at Rectifyq to track and analyze the Malaysian threat landscape.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;notion&quot;&gt;📕Notion&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#notion&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;🗓️&lt;a href=&quot;https://rectifyq.notion.site/Malaysia-Cybersecurity-Events-e5b7d360750c42cd8d35de22ab0ff8e1&quot; class=&quot;external&quot;&gt;Malaysia Cybersecurity Events&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;br&gt;
🔁&lt;a href=&quot;https://rectifyq.notion.site/Subscription-Comparison-2aaba5ae66c780f4902dc59212d57fae&quot; class=&quot;external&quot;&gt;Cybersecurity Subscription Comparison&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;br&gt;
💼&lt;a href=&quot;https://rectifyq.notion.site/Certification-Comparison-and-Action-Plan-CCAP-1ac3036cc51647679fb217433dc90f0a&quot; class=&quot;external&quot;&gt;Certification Comparison and Action Plan (CCAP)&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;github-repos&quot;&gt;💻Github Repos&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#github-repos&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;h3 id=&quot;collections&quot;&gt;Collections&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#collections&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/rectifyq/Collections/blob/main/Computer-Crime-Act-1997-Cases/Computer-Crime-Act-1997-Cases.csv&quot; class=&quot;external&quot;&gt;List of Computer Crime Act 1997 Cases&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/rectifyq/Collections/tree/main/Phishing-Targeting-Malaysia&quot; class=&quot;external&quot;&gt;List of Phishing Targeting Malaysia&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/rectifyq/Collections/tree/main/Diamond-Models&quot; class=&quot;external&quot;&gt;Diamond Models created&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id=&quot;ctfd-to-misp-importer&quot;&gt;CTFd to MISP Importer&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#ctfd-to-misp-importer&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/rectifyq/ctfd-to-misp&quot; class=&quot;external&quot;&gt;CTFd-to-MISP&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;
&lt;h2 id=&quot;misp-feed-free-integration---tlpclear-only&quot;&gt;💬MISP Feed (Free Integration - TLP:Clear only)&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#misp-feed-free-integration---tlpclear-only&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;h3 id=&quot;global-misp-events&quot;&gt;🌏Global MISP events&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#global-misp-events&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;MISP 2024 - &lt;a href=&quot;https://feeds.rectifyq.com/MISP2024&quot; class=&quot;external&quot;&gt;https://feeds.rectifyq.com/MISP2024&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;MISP 2025 - &lt;a href=&quot;https://feeds.rectifyq.com/MISP2025&quot; class=&quot;external&quot;&gt;https://feeds.rectifyq.com/MISP2025&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;MISP 2026 - soon&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id=&quot;-misp-my&quot;&gt;🇲🇾 MISP MY&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#-misp-my&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;MISP MY - soon&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id=&quot;miscelleanous&quot;&gt;📦Miscelleanous&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#miscelleanous&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;MISP CTFs - soon&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;
&lt;h1 id=&quot;malaysia-cybersecurity-ecosystem&quot;&gt;Malaysia Cybersecurity Ecosystem&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#malaysia-cybersecurity-ecosystem&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h1&gt;
&lt;pre&gt;&lt;button class=&quot;expand-button&quot; aria-label=&quot;Expand mermaid diagram&quot; data-view-component&gt;&lt;svg width=&quot;16&quot; height=&quot;16&quot; viewBox=&quot;0 0 16 16&quot; fill=&quot;currentColor&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M3.72 3.72a.75.75 0 011.06 1.06L2.56 7h10.88l-2.22-2.22a.75.75 0 011.06-1.06l3.5 3.5a.75.75 0 010 1.06l-3.5 3.5a.75.75 0 11-1.06-1.06l2.22-2.22H2.56l2.22 2.22a.75.75 0 11-1.06 1.06l-3.5-3.5a.75.75 0 010-1.06l3.5-3.5z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/button&gt;&lt;code class=&quot;mermaid&quot; data-clipboard=&quot;&amp;#x22;flowchart TB\n    direction RL\n    subgraph CTF\n        direction RL\n        C1[Wargames.my]\n        C2[GCTF]\n        C3[Bahtera Siber]\n        C4[Sherpasec CTF]\n        C5[I-Hack]\n        C6[ABOH]\n        C7[UTPHax]\n        C8[Hack@10]\n        C9[SunCTF]\n        C10[KPMG]\n        C11[iCTFF]\n    end\n    subgraph Community\n        direction RL\n        M1[Rawsec]\n        M2[Sherpasec]\n        M3[Offsec]\n        M4[ISC2]\n        M5[OWASP KL]\n        M6[MyOPECS]\n    end\n    subgraph Conferences\n        direction RL\n        F1[CyberDSA]\n        F2[Cydes]\n        F3[NanoSec]\n        F4[5GOT]\n\n    end\n\n\n    click M1 \&amp;#x22;https://mcco.org.my/\&amp;#x22; _blank\n    click M2 \&amp;#x22;https://sherpasec.org/\&amp;#x22; _blank\n    click M3 \&amp;#x22;https://www.linkedin.com/groups/14716092/\&amp;#x22; _blank\n    click M4 \&amp;#x22;https://www.isc2chapter.my/\&amp;#x22; _blank\n    click M5 \&amp;#x22;https://owasp.org/www-chapter-kuala-lumpur/\&amp;#x22; _blank\n    click M6 \&amp;#x22;https://t.me/+HZLe3mJs9MxlNzRl\&amp;#x22; _blank\n\n    click C1 \&amp;#x22;https://wargames.my\&amp;#x22; _blank\n    click C2 \&amp;#x22;https://girls-in-ctf.online/\&amp;#x22; _blank\n    click C3 \&amp;#x22;https://x.com/bahterasiber\&amp;#x22; _blank\n    click C4 \&amp;#x22;https://sherpasec.org/sherpactf/\&amp;#x22; _blank\n    click C5 \&amp;#x22;https://news.uitm.edu.my/2024/07/ihack-2024-and-siber-siaga-2024-malaysia-takes-strides-in-cybersecurity-education-and-awareness/\&amp;#x22; _blank\n    click C6 \&amp;#x22;https://www.linkedin.com/posts/apumalaysia_the-asean-battle-of-hackers-aboh-2023-activity-7147881717654036481-ViCf/\&amp;#x22; _blank\n    click C7 \&amp;#x22;https://utphax.github.io/\&amp;#x22; _blank\n    click C8 \&amp;#x22;https://linktr.ee/hackaten\&amp;#x22; _blank\n    click C9 \&amp;#x22;https://www.linkedin.com/company/csc-sunway/\&amp;#x22; _blank\n    click C10 \&amp;#x22;https://www.youtube.com/watch?v=xSIKCjKj2gY\&amp;#x22; _blank\n    click C11 \&amp;#x22;https://www.ictff.com.my/\&amp;#x22; _blank\n\n    click F1 \&amp;#x22;https://www.cyberdsa.com/\&amp;#x22; _blank\n    click F2 \&amp;#x22;https://cydes.my/\&amp;#x22; _blank\n    click F3 \&amp;#x22;https://nanosec.asia/\&amp;#x22; _blank\n    click F4 \&amp;#x22;https://5got.asia/\&amp;#x22; _blank\n&amp;#x22;&quot;&gt;flowchart TB
    direction RL
    subgraph CTF
        direction RL
        C1[Wargames.my]
        C2[GCTF]
        C3[Bahtera Siber]
        C4[Sherpasec CTF]
        C5[I-Hack]
        C6[ABOH]
        C7[UTPHax]
        C8[Hack@10]
        C9[SunCTF]
        C10[KPMG]
        C11[iCTFF]
    end
    subgraph Community
        direction RL
        M1[Rawsec]
        M2[Sherpasec]
        M3[Offsec]
        M4[ISC2]
        M5[OWASP KL]
        M6[MyOPECS]
    end
    subgraph Conferences
        direction RL
        F1[CyberDSA]
        F2[Cydes]
        F3[NanoSec]
        F4[5GOT]

    end


    click M1 &quot;https://mcco.org.my/&quot; _blank
    click M2 &quot;https://sherpasec.org/&quot; _blank
    click M3 &quot;https://www.linkedin.com/groups/14716092/&quot; _blank
    click M4 &quot;https://www.isc2chapter.my/&quot; _blank
    click M5 &quot;https://owasp.org/www-chapter-kuala-lumpur/&quot; _blank
    click M6 &quot;https://t.me/+HZLe3mJs9MxlNzRl&quot; _blank

    click C1 &quot;https://wargames.my&quot; _blank
    click C2 &quot;https://girls-in-ctf.online/&quot; _blank
    click C3 &quot;https://x.com/bahterasiber&quot; _blank
    click C4 &quot;https://sherpasec.org/sherpactf/&quot; _blank
    click C5 &quot;https://news.uitm.edu.my/2024/07/ihack-2024-and-siber-siaga-2024-malaysia-takes-strides-in-cybersecurity-education-and-awareness/&quot; _blank
    click C6 &quot;https://www.linkedin.com/posts/apumalaysia_the-asean-battle-of-hackers-aboh-2023-activity-7147881717654036481-ViCf/&quot; _blank
    click C7 &quot;https://utphax.github.io/&quot; _blank
    click C8 &quot;https://linktr.ee/hackaten&quot; _blank
    click C9 &quot;https://www.linkedin.com/company/csc-sunway/&quot; _blank
    click C10 &quot;https://www.youtube.com/watch?v=xSIKCjKj2gY&quot; _blank
    click C11 &quot;https://www.ictff.com.my/&quot; _blank

    click F1 &quot;https://www.cyberdsa.com/&quot; _blank
    click F2 &quot;https://cydes.my/&quot; _blank
    click F3 &quot;https://nanosec.asia/&quot; _blank
    click F4 &quot;https://5got.asia/&quot; _blank

&lt;/code&gt;&lt;div id=&quot;mermaid-container&quot; role=&quot;dialog&quot;&gt;&lt;div id=&quot;mermaid-space&quot;&gt;&lt;div class=&quot;mermaid-content&quot;&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/pre&gt; ]]></description>
    <pubDate>Thu, 12 Feb 2026 08:32:17 GMT</pubDate>
  </item><item>
    <title>2026-02-12 LockBit strikes with new 5.0 version, targeting Windows, Linux and ESXI systems</title>
    <link>https://rectifyq.com/MY-Threat-Landscape/threat-lists/db240f3d-7cc8-4a58-9b99-69e778ab7a5d</link>
    <guid>https://rectifyq.com/MY-Threat-Landscape/threat-lists/db240f3d-7cc8-4a58-9b99-69e778ab7a5d</guid>
    <description><![CDATA[ &lt;p&gt;📃Title: LockBit strikes with new 5.0 version, targeting Windows, Linux and ESXI systems&lt;br&gt;
📅Date: 2026-02-12&lt;br&gt;
🔗References:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.acronis.com/en/tru/posts/lockbit-strikes-with-new-50-version-targeting-windows-linux-and-esxi-systems&quot; class=&quot;external&quot;&gt;https://www.acronis.com/en/tru/posts/lockbit-strikes-with-new-50-version-targeting-windows-linux-and-esxi-systems&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;blockquote class=&quot;callout abstract&quot; data-callout=&quot;abstract&quot;&gt;
&lt;div class=&quot;callout-title&quot;&gt;
                  &lt;div class=&quot;callout-icon&quot;&gt;&lt;/div&gt;
                  &lt;div class=&quot;callout-title-inner&quot;&gt;&lt;p&gt; &lt;strong&gt;Description&lt;/strong&gt;&lt;/p&gt;&lt;/div&gt;
                  
                &lt;/div&gt;
&lt;div class=&quot;callout-content&quot;&gt;
&lt;p&gt;LockBit 5.0, the latest version of the notorious ransomware, has been released with support for Windows, Linux, and ESXi systems. This update brings improved defense evasion, faster encryption, and enhanced modularity. The Windows variant employs extensive anti-analysis techniques, while Linux and ESXi versions remain unpacked. All variants share a common encryption scheme using XChaCha20 and Curve25519. LockBit 5.0 demonstrates a focus on enterprise and infrastructure targets, including explicit support for Proxmox virtualization. The group’s data leak site reveals a primary focus on the U.S. business sector, with victims spanning various industries. LockBit’s infrastructure has shown connections to SmokeLoader, suggesting possible cooperation or infrastructure reuse among malware operators.&lt;/p&gt;
&lt;/div&gt;
&lt;/blockquote&gt;
&lt;p&gt;🔖Rectifyq Taxonomies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;relevancy: 🔴 Highly Relevant&lt;/li&gt;
&lt;li&gt;category: &lt;a href=&quot;../.././../tags/⚔Threat&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/⚔Threat&quot;&gt;⚔Threat&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;sub-category: &lt;a href=&quot;../.././../tags/malware-analysis&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/malware-analysis&quot;&gt;malware-analysis&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;target: &lt;a href=&quot;../.././../tags/broad-based&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/broad-based&quot;&gt;broad-based&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;MY-relevancy: &lt;a href=&quot;../.././../tags/relevant&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/relevant&quot;&gt;relevant&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;🔖MISP Galaxies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;target-information=“United States”&lt;/li&gt;
&lt;li&gt;ransomware=“lockbit5”&lt;/li&gt;
&lt;li&gt;malpedia=“SmokeLoader”&lt;/li&gt;
&lt;li&gt;target-information=“Argentina”&lt;/li&gt;
&lt;li&gt;target-information=“Bolivia”&lt;/li&gt;
&lt;li&gt;target-information=“Brazil”&lt;/li&gt;
&lt;li&gt;target-information=“China”&lt;/li&gt;
&lt;li&gt;target-information=“Czech Republic”&lt;/li&gt;
&lt;li&gt;target-information=“Egypt”&lt;/li&gt;
&lt;li&gt;target-information=“Estonia”&lt;/li&gt;
&lt;li&gt;target-information=“France”&lt;/li&gt;
&lt;li&gt;target-information=“Germany”&lt;/li&gt;
&lt;li&gt;target-information=“India”&lt;/li&gt;
&lt;li&gt;target-information=“Ireland”&lt;/li&gt;
&lt;li&gt;target-information=“Italy”&lt;/li&gt;
&lt;li&gt;target-information=“Kuwait”&lt;/li&gt;
&lt;li&gt;target-information=“Malaysia”&lt;/li&gt;
&lt;li&gt;target-information=“Mexico”&lt;/li&gt;
&lt;li&gt;target-information=“Singapore”&lt;/li&gt;
&lt;li&gt;target-information=“South Africa”&lt;/li&gt;
&lt;li&gt;target-information=“Spain”&lt;/li&gt;
&lt;li&gt;target-information=“Thailand”&lt;/li&gt;
&lt;li&gt;target-information=“Turkey”&lt;/li&gt;
&lt;li&gt;target-information=“United Arab Emirates”&lt;/li&gt;
&lt;li&gt;target-information=“United Kingdom”&lt;/li&gt;
&lt;li&gt;mitre-attack-pattern=[‘T1489’, ‘T1553.002’, ‘T1082’, ‘T1071’, ‘T1140’, ‘T1036’, ‘T1055’, ‘T1562.002’, ‘T1112’, ‘T1070.001’, ‘T1222’, ‘T1083’, ‘T1497’, ‘T1480’, ‘T1078’, ‘T1027’, ‘T1486’, ‘T1573’, ‘T1490’]&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;MISP event uuid: &lt;a href=&quot;https://mispmy.rectifyq.com/events/view/db240f3d-7cc8-4a58-9b99-69e778ab7a5d&quot; class=&quot;external&quot;&gt;db240f3d-7cc8-4a58-9b99-69e778ab7a5d&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2 id=&quot;indicator-of-compromise-iocs&quot;&gt;Indicator of Compromise (IoCs)&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#indicator-of-compromise-iocs&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;pre&gt;&lt;code&gt;type,value,comment
domain, lockbit7z2jwcskxpbokpemdxmltipntwlkmidcll2qirbu7ykg46eyd.onion, &#039;&#039;
domain, lockbit7z2mmiz3ryxafn5kapbvbbiywsxwovasfkgf5dqqp5kxlajad.onion, &#039;&#039;
domain, lockbit7z2og4jlsmdy7dzty3g42eu3gh2sx2b6ywtvhrjtss7li4fyd.onion, &#039;&#039;
domain, lockbit7z355oalq4hiy5p7de64l6rsqutwlvydqje56uvevcc57r6qd.onion, &#039;&#039;
domain, lockbit7z36ynytxwjzuoao46ck7b3753gpedary3qvuizn3iczhe4id.onion, &#039;&#039;
domain, lockbit7z37ntefjdbjextn6tmdkry4j546ejnru5cejeguitiopvhad.onion, &#039;&#039;
domain, lockbit7z3azdoxdpqxzliszutufbc2fldagztdu47xyucp25p4xtqad.onion, &#039;&#039;
domain, lockbit7z3ddvg5vuez2vznt73ljqgwx5tnuqaa2ye7lns742yiv2zyd.onion, &#039;&#039;
domain, lockbit7z3hv7ev5knxbrhsvv2mmu2rddwqizdz4vwfvxt5izrq6zqqd.onion, &#039;&#039;
domain, lockbit7z3ujnkhxwahhjduh5me2updvzxewhhc5qvk2snxezoi5drad.onion, &#039;&#039;
domain, lockbit7z4bsm63m3dagp5xglyacr4z4bwytkvkkwtn6enmuo5fi5iyd.onion, &#039;&#039;
domain, lockbit7z4cgxvictidwfxpuiov4scdw34nxotmbdjyxpkvkg34mykyd.onion, &#039;&#039;
domain, lockbit7z4k5zer5fbqi2vdq5sx2vuggatwyqvoodrkhubxftyrvncid.onion, &#039;&#039;
domain, lockbit7z4ndl6thsct34yd47jrzdkpnfg3acfvpacuccb45pnars2ad.onion, &#039;&#039;
domain, lockbit7z55tuwaflw2c7torcryobdvhkcgvivhflyndyvcrexafssad.onion, &#039;&#039;
domain, lockbit7z57mkicfkuq44j6yrpu5finwvjllczkkp2uvdedsdonjztyd.onion, &#039;&#039;
domain, lockbit7z5ehshj6gzpetw5kso3onts6ty7wrnneya5u4aj3vzkeoaqd.onion, &#039;&#039;
domain, lockbit7z5hwf6ywfuzipoa42tjlmal3x5suuccngsamsgklww2xgyqd.onion, &#039;&#039;
domain, lockbit7z5ltrhzv46lsg447o3cx2637dloc3qt4ugd3gr2xdkkkeayd.onion, &#039;&#039;
domain, lockbit7z6choojah4ipvdpzzfzxxchjbecnmtn4povk6ifdvx2dpnid.onion, &#039;&#039;
domain, lockbit7z6dqziutocr43onmvpth32njp4abfocfauk2belljjpobxyd.onion, &#039;&#039;
domain, lockbit7z6f3gu6rjvrysn5gjbsqj3hk3bvsg64ns6pjldqr2xhvhsyd.onion, &#039;&#039;
domain, lockbit7z6qinyhhmibvycu5kwmcvgrbpvtztkvvmdce5zwtucaeyrqd.onion, &#039;&#039;
domain, lockbit7z6rzyojiye437jp744d4uwtff7aq7df7gh2jvwqtv525c4yd.onion, &#039;&#039;
domain, lockbitfbinpwhbyomxkiqtwhwiyetrbkb4hnqmshaonqxmsrqwg7yad.onion, &#039;&#039;
domain, lockbitsuppyx2jegaoyiw44ica5vdho63m5ijjlmfb7omq3tfr3qhyd.onion, &#039;&#039;
domain, rodericwalter.com, &#039;&#039;
ip-dst, 205.185.116.233, &#039;LockBit exposed server&#039;
domain, karma0.xyz, &#039;LockBit exposed server&#039;
url, http://lockbitfbinpwhbyomxkiqtwhwiyetrbkb4hnqmshaonqxmsrqwg7yad.onion/, &#039;Data leak site&#039;
url, http://lockbitsuppyx2jegaoyiw44ica5vdho63m5ijjlmfb7omq3tfr3qhyd.onion, &#039;Threat actor chat link&#039;
url, http://lockbit7z2jwcskxpbokpemdxmltipntwlkmidcll2qirbu7ykg46eyd.onion/, &#039;Leaked data mirrors&#039;
url, http://lockbit7z2mmiz3ryxafn5kapbvbbiywsxwovasfkgf5dqqp5kxlajad.onion/, &#039;Leaked data mirrors&#039;
url, http://lockbit7z2og4jlsmdy7dzty3g42eu3gh2sx2b6ywtvhrjtss7li4fyd.onion/, &#039;Leaked data mirrors&#039;
url, http://lockbit7z355oalq4hiy5p7de64l6rsqutwlvydqje56uvevcc57r6qd.onion/, &#039;Leaked data mirrors&#039;
url, http://lockbit7z36ynytxwjzuoao46ck7b3753gpedary3qvuizn3iczhe4id.onion/, &#039;Leaked data mirrors&#039;
url, http://lockbit7z37ntefjdbjextn6tmdkry4j546ejnru5cejeguitiopvhad.onion/, &#039;Leaked data mirrors&#039;
url, http://lockbit7z3azdoxdpqxzliszutufbc2fldagztdu47xyucp25p4xtqad.onion/, &#039;Leaked data mirrors&#039;
url, http://lockbit7z3ddvg5vuez2vznt73ljqgwx5tnuqaa2ye7lns742yiv2zyd.onion/, &#039;Leaked data mirrors&#039;
url, http://lockbit7z3hv7ev5knxbrhsvv2mmu2rddwqizdz4vwfvxt5izrq6zqqd.onion/, &#039;Leaked data mirrors&#039;
url, http://lockbit7z3ujnkhxwahhjduh5me2updvzxewhhc5qvk2snxezoi5drad.onion/, &#039;Leaked data mirrors&#039;
url, http://lockbit7z4bsm63m3dagp5xglyacr4z4bwytkvkkwtn6enmuo5fi5iyd.onion/, &#039;Leaked data mirrors&#039;
url, http://lockbit7z4cgxvictidwfxpuiov4scdw34nxotmbdjyxpkvkg34mykyd.onion/, &#039;Leaked data mirrors&#039;
url, http://lockbit7z4k5zer5fbqi2vdq5sx2vuggatwyqvoodrkhubxftyrvncid.onion/, &#039;Leaked data mirrors&#039;
url, http://lockbit7z4ndl6thsct34yd47jrzdkpnfg3acfvpacuccb45pnars2ad.onion/, &#039;Leaked data mirrors&#039;
url, http://lockbit7z55tuwaflw2c7torcryobdvhkcgvivhflyndyvcrexafssad.onion/, &#039;Leaked data mirrors&#039;
url, http://lockbit7z57mkicfkuq44j6yrpu5finwvjllczkkp2uvdedsdonjztyd.onion/, &#039;Leaked data mirrors&#039;
url, http://lockbit7z5ehshj6gzpetw5kso3onts6ty7wrnneya5u4aj3vzkeoaqd.onion/, &#039;Leaked data mirrors&#039;
url, http://lockbit7z5hwf6ywfuzipoa42tjlmal3x5suuccngsamsgklww2xgyqd.onion/, &#039;Leaked data mirrors&#039;
url, http://lockbit7z5ltrhzv46lsg447o3cx2637dloc3qt4ugd3gr2xdkkkeayd.onion/, &#039;Leaked data mirrors&#039;
url, http://lockbit7z6choojah4ipvdpzzfzxxchjbecnmtn4povk6ifdvx2dpnid.onion/, &#039;Leaked data mirrors&#039;
url, http://lockbit7z6dqziutocr43onmvpth32njp4abfocfauk2belljjpobxyd.onion/, &#039;Leaked data mirrors&#039;
url, http://lockbit7z6f3gu6rjvrysn5gjbsqj3hk3bvsg64ns6pjldqr2xhvhsyd.onion/, &#039;Leaked data mirrors&#039;
url, http://lockbit7z6qinyhhmibvycu5kwmcvgrbpvtztkvvmdce5zwtucaeyrqd.onion/, &#039;Leaked data mirrors&#039;
url, http://lockbit7z6rzyojiye437jp744d4uwtff7aq7df7gh2jvwqtv525c4yd.onion/, &#039;Leaked data mirrors&#039;

Full IOCs available in Rectifyq&#039;s MISP```
&lt;/code&gt;&lt;/pre&gt; ]]></description>
    <pubDate>Thu, 12 Feb 2026 00:00:00 GMT</pubDate>
  </item><item>
    <title>Contribute</title>
    <link>https://rectifyq.com/contribute</link>
    <guid>https://rectifyq.com/contribute</guid>
    <description><![CDATA[ &lt;h1 id=&quot;-join-the-mission&quot;&gt;🤝 Join the Mission&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#-join-the-mission&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h1&gt;
&lt;p&gt;Cyber Threat Intelligence (CTI) is a team sport. At &lt;strong&gt;Rectifyq&lt;/strong&gt;, we believe that collective defense is the best defense—especially within our local Malaysian landscape.&lt;/p&gt;
&lt;p&gt;Whether you are a seasoned CTI practitioner or a student just starting your journey, your analysis helps make the digital space safer for everyone.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id=&quot;-how-you-can-help&quot;&gt;🔍 How You Can Help&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#-how-you-can-help&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;You don’t need a formal invitation to contribute. If you find something interesting using the data on the &lt;strong&gt;Rectifyq website&lt;/strong&gt; or our &lt;strong&gt;MISP instance&lt;/strong&gt;, we want to see your insights!&lt;/p&gt;
&lt;h3 id=&quot;areas-of-focus&quot;&gt;Areas of Focus&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#areas-of-focus&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;We are particularly interested in reports covering:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;👤 Threat Actor Profiles:&lt;/strong&gt; Deep dives into groups targeting Malaysian infrastructure or local industries.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;🦠 Malware Analysis:&lt;/strong&gt; Reverse engineering or behavioral analysis of samples found in the wild locally.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;🚨 Incident Analysis:&lt;/strong&gt; Post-mortem or technical breakdowns of recent Malaysian cyber incidents.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;🔓 Leak Data Analysis:&lt;/strong&gt; Investigating data breaches, credential dumps, or PII leaks affecting Malaysian citizens.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;🎣 Phishing Analysis:&lt;/strong&gt; Tracking local phishing kits, SMS scams (Smishing), or brand impersonation campaigns.&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;
&lt;h2 id=&quot;-the-workflow&quot;&gt;🛠 The Workflow&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#-the-workflow&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Contributing is straightforward:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Analyze:&lt;/strong&gt; Use the indicators (IoCs) and telemetry available on our website or MISP.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Report:&lt;/strong&gt; Create a technical write-up, a Gist, a PDF, or even a detailed social media thread.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Notify:&lt;/strong&gt; This is the most important part! Let us know you’ve published something so we can amplify your work.&lt;/li&gt;
&lt;/ol&gt;
&lt;blockquote class=&quot;callout tip&quot; data-callout=&quot;tip&quot;&gt;
&lt;div class=&quot;callout-title&quot;&gt;
                  &lt;div class=&quot;callout-icon&quot;&gt;&lt;/div&gt;
                  &lt;div class=&quot;callout-title-inner&quot;&gt;&lt;p&gt;TIP&lt;/p&gt;&lt;/div&gt;
                  
                &lt;/div&gt;
&lt;div class=&quot;callout-content&quot;&gt;
&lt;p&gt;&lt;strong&gt;Where to find us?&lt;/strong&gt;
Reach out to us via &lt;strong&gt;X (Twitter)&lt;/strong&gt;, &lt;strong&gt;LinkedIn&lt;/strong&gt;, or any of our official social media channels. We’d love to feature your work or link it back to our intelligence feeds.&lt;/p&gt;
&lt;/div&gt;
&lt;/blockquote&gt;
&lt;hr&gt;
&lt;h2 id=&quot;-for-students&quot;&gt;🎓 For Students&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#-for-students&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;If you’re a student using Rectifyq data for your final year project or personal research, don’t be shy! Contributing a report is a fantastic way to build your portfolio and get noticed by the local cybersecurity community.&lt;/p&gt; ]]></description>
    <pubDate>Thu, 12 Feb 2026 00:00:00 GMT</pubDate>
  </item><item>
    <title>2026-02-05 The Shadow Campaigns Uncovering Global Espionage</title>
    <link>https://rectifyq.com/MY-Threat-Landscape/threat-lists/14c1cdc4-4306-4f92-9f44-7d6b5ea0d20e</link>
    <guid>https://rectifyq.com/MY-Threat-Landscape/threat-lists/14c1cdc4-4306-4f92-9f44-7d6b5ea0d20e</guid>
    <description><![CDATA[ &lt;p&gt;📃Title: The Shadow Campaigns: Uncovering Global Espionage&lt;br&gt;
📅Date: 2026-02-05&lt;br&gt;
🔗References:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://unit42.paloaltonetworks.com/shadow-campaigns-uncovering-global-espionage&quot; class=&quot;external&quot;&gt;https://unit42.paloaltonetworks.com/shadow-campaigns-uncovering-global-espionage&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;blockquote class=&quot;callout abstract&quot; data-callout=&quot;abstract&quot;&gt;
&lt;div class=&quot;callout-title&quot;&gt;
                  &lt;div class=&quot;callout-icon&quot;&gt;&lt;/div&gt;
                  &lt;div class=&quot;callout-title-inner&quot;&gt;&lt;p&gt; &lt;strong&gt;Description&lt;/strong&gt;&lt;/p&gt;&lt;/div&gt;
                  
                &lt;/div&gt;
&lt;div class=&quot;callout-content&quot;&gt;
&lt;p&gt;This investigation reveals a new cyberespionage group tracked as TGR-STA-1030, believed to be a state-aligned actor operating from Asia. Over the past year, the group has compromised government and critical infrastructure organizations in 37 countries, targeting ministries, law enforcement agencies, and departments related to economic, trade, and diplomatic functions. The group employs sophisticated phishing and exploitation techniques, leveraging various tools and infrastructure to maintain persistent access. Their activities span across the Americas, Europe, Asia, Oceania, and Africa, with a focus on countries exploring certain economic partnerships. The group’s operations often coincide with significant geopolitical events and economic interests, particularly in sectors like rare earth minerals and international trade agreements.&lt;/p&gt;
&lt;/div&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;img src=&quot;https://raw.githubusercontent.com/rectifyq/Collections/refs/heads/main/Diamond-Models/2026/260208-ShadowCampaign/260208-ShadowCampaign.png&quot; alt=&quot;&quot;&gt;&lt;/p&gt;
&lt;p&gt;🔖Rectifyq Taxonomies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;relevancy: 🔴 Highly Relevant&lt;/li&gt;
&lt;li&gt;category: &lt;a href=&quot;../.././../tags/⚔Threat&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/⚔Threat&quot;&gt;⚔Threat&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;sub-category: &lt;a href=&quot;../.././../tags/TA-profile&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/TA-profile&quot;&gt;TA-profile&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;target: &lt;a href=&quot;../.././../tags/targeted&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/targeted&quot;&gt;targeted&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;MY-relevancy: &lt;a href=&quot;../.././../tags/relevant&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/relevant&quot;&gt;relevant&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;action-taken: &lt;a href=&quot;../.././../tags/diamond-model&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/diamond-model&quot;&gt;diamond-model&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;🔖MISP Galaxies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;producer &lt;a href=&quot;../.././../tags/Palo-Alto&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/Palo-Alto&quot;&gt;Palo-Alto&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;target-information=“United States”&lt;/li&gt;
&lt;li&gt;target-information=“United Kingdom”&lt;/li&gt;
&lt;li&gt;target-information=“Singapore”&lt;/li&gt;
&lt;li&gt;target-information=“Brazil”&lt;/li&gt;
&lt;li&gt;target-information=“Mexico”&lt;/li&gt;
&lt;li&gt;target-information=“Panama”&lt;/li&gt;
&lt;li&gt;target-information=“Cyprus”&lt;/li&gt;
&lt;li&gt;target-information=“Czech Republic”&lt;/li&gt;
&lt;li&gt;target-information=“Germany”&lt;/li&gt;
&lt;li&gt;target-information=“Greece”&lt;/li&gt;
&lt;li&gt;target-information=“Italy”&lt;/li&gt;
&lt;li&gt;target-information=“Poland”&lt;/li&gt;
&lt;li&gt;target-information=“Portugal”&lt;/li&gt;
&lt;li&gt;target-information=“Serbia”&lt;/li&gt;
&lt;li&gt;target-information=“Afghanistan”&lt;/li&gt;
&lt;li&gt;target-information=“Bangladesh”&lt;/li&gt;
&lt;li&gt;target-information=“British Indian Ocean Territory”&lt;/li&gt;
&lt;li&gt;target-information=“India”&lt;/li&gt;
&lt;li&gt;target-information=“Indonesia”&lt;/li&gt;
&lt;li&gt;target-information=“Japan”&lt;/li&gt;
&lt;li&gt;target-information=“Malaysia”&lt;/li&gt;
&lt;li&gt;target-information=“Mongolia”&lt;/li&gt;
&lt;li&gt;target-information=“Papua New Guinea”&lt;/li&gt;
&lt;li&gt;target-information=“Saudi Arabia”&lt;/li&gt;
&lt;li&gt;target-information=“Sri Lanka”&lt;/li&gt;
&lt;li&gt;target-information=“Taiwan”&lt;/li&gt;
&lt;li&gt;target-information=“Thailand”&lt;/li&gt;
&lt;li&gt;target-information=“Uzbekistan”&lt;/li&gt;
&lt;li&gt;target-information=“Djibouti”&lt;/li&gt;
&lt;li&gt;target-information=“Ethiopia”&lt;/li&gt;
&lt;li&gt;target-information=“Namibia”&lt;/li&gt;
&lt;li&gt;target-information=“Niger”&lt;/li&gt;
&lt;li&gt;target-information=“Nigeria”&lt;/li&gt;
&lt;li&gt;target-information=“Zambia”&lt;/li&gt;
&lt;li&gt;target-information=“Bolivia”&lt;/li&gt;
&lt;li&gt;target-information=“Venezuela”&lt;/li&gt;
&lt;li&gt;sector=“Government, Administration”&lt;/li&gt;
&lt;li&gt;sector=“Finance”&lt;/li&gt;
&lt;li&gt;malpedia=“Cobalt Strike”&lt;/li&gt;
&lt;li&gt;online-service=“4605654f-8487-4d17-bfbb-bbcc223281d5”&lt;/li&gt;
&lt;li&gt;online-service=“3b16bb5a-eb4f-4603-a909-bebc5df4a46d”&lt;/li&gt;
&lt;li&gt;malpedia=“Havoc”&lt;/li&gt;
&lt;li&gt;malpedia=“Sliver”&lt;/li&gt;
&lt;li&gt;malpedia=“SparkRAT”&lt;/li&gt;
&lt;li&gt;malpedia=“Vshell”&lt;/li&gt;
&lt;li&gt;mitre-attack-pattern=[‘T1204.002’, ‘T1584.003’, ‘T1190’, ‘T1583.001’, ‘T1021.002’, ‘T1505.003’, ‘T1583.004’, ‘T1090’, ‘T1059’, ‘T1583.003’, ‘T1102’, ‘T1588.002’, ‘T1566’, ‘T1078’, ‘T1027’, ‘T1584.004’, ‘T1105’, ‘T1021.001’, ‘T1204.001’, ‘T1584.001’]&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;MISP event uuid: &lt;a href=&quot;https://mispmy.rectifyq.com/events/view/14c1cdc4-4306-4f92-9f44-7d6b5ea0d20e&quot; class=&quot;external&quot;&gt;14c1cdc4-4306-4f92-9f44-7d6b5ea0d20e&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2 id=&quot;indicator-of-compromise-iocs&quot;&gt;Indicator of Compromise (IoCs)&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#indicator-of-compromise-iocs&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;pre&gt;&lt;code&gt;type,value,comment
ip-dst, 138.197.44.208, &#039;&#039;
ip-dst, 157.230.34.45, &#039;&#039;
ip-dst, 188.127.251.171, &#039;&#039;
ip-dst, 188.166.210.146, &#039;&#039;
sha256, 7808b1e01ea790548b472026ac783c73a033bb90bbe548bf3006abfbcb48c52d, &#039;ShadowGuard No sample in VT\r\nLast check:07/02/2026&#039;
ip-dst, 142.91.105.172, &#039;&#039;
ip-dst, 146.190.152.219, &#039;&#039;
ip-dst, 157.245.194.54, &#039;&#039;
ip-dst, 159.203.164.101, &#039;&#039;
ip-dst, 178.128.109.37, &#039;&#039;
ip-dst, 178.128.60.22, &#039;&#039;
ip-dst, 208.85.21.30, &#039;&#039;
domain, 888910.xyz, &#039;&#039;
domain, abwxjp5.me, &#039;&#039;
domain, brackusi0n.live, &#039;&#039;
domain, dog3rj.tech, &#039;&#039;
domain, emezonhe.me, &#039;&#039;
domain, gouvn.me, &#039;&#039;
domain, msonline.help, &#039;&#039;
domain, pickupweb.me, &#039;&#039;
domain, pr0fu5a.me, &#039;&#039;
domain, q74vn.live, &#039;&#039;
domain, servgate.me, &#039;&#039;
domain, zamstats.me, &#039;&#039;
domain, zrheblirsy.me, &#039;&#039;
ip-dst, 159.65.156.200, &#039;&#039;
url, https://raw.githubusercontent.com/padeqav/WordPress/refs/heads/master/wp-includes/images/admin-bar-sprite.png, &#039;the malware downloads the following files from GitHub&#039;
url, https://raw.githubusercontent.com/padeqav/WordPress/refs/heads/master/wp-includes/images/Linux.jpg, &#039;the malware downloads the following files from GitHub&#039;
url, https://raw.githubusercontent.com/padeqav/WordPress/refs/heads/master/wp-includes/images/Windows.jpg, &#039;the malware downloads the following files from GitHub&#039;

Full IOCs available in Rectifyq&#039;s MISP```
&lt;/code&gt;&lt;/pre&gt; ]]></description>
    <pubDate>Thu, 05 Feb 2026 00:00:00 GMT</pubDate>
  </item><item>
    <title>2026-02-02 Cross-Border Cryptocurrency Investment Scam Leveraging Social Messaging Channels and Fake Regulatory Credentials</title>
    <link>https://rectifyq.com/MY-Threat-Landscape/threat-lists/020ceb62-7009-41fe-b22f-1ddd6806e4ea</link>
    <guid>https://rectifyq.com/MY-Threat-Landscape/threat-lists/020ceb62-7009-41fe-b22f-1ddd6806e4ea</guid>
    <description><![CDATA[ &lt;p&gt;📃Title: Cross-Border Cryptocurrency Investment Scam Leveraging Social Messaging Channels and Fake Regulatory Credentials&lt;br&gt;
📅Date: 2026-02-02&lt;br&gt;
🔗References:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cloudsek.com/blog/cross-border-cryptocurrency-investment-scam-leveraging-social-messaging-channels-and-fake-regulatory-credentials&quot; class=&quot;external&quot;&gt;https://www.cloudsek.com/blog/cross-border-cryptocurrency-investment-scam-leveraging-social-messaging-channels-and-fake-regulatory-credentials&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;🔖Rectifyq Taxonomies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;relevancy: 🔴 Highly Relevant&lt;/li&gt;
&lt;li&gt;category: &lt;a href=&quot;../.././../tags/⚔Threat&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/⚔Threat&quot;&gt;⚔Threat&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;sub-category: &lt;a href=&quot;../.././../tags/campaign-analysis&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/campaign-analysis&quot;&gt;campaign-analysis&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;topic: &lt;a href=&quot;../.././../tags/crypto-related&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/crypto-related&quot;&gt;crypto-related&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;target: &lt;a href=&quot;../.././../tags/broad-based&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/broad-based&quot;&gt;broad-based&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;MY-relevancy: &lt;a href=&quot;../.././../tags/relevant&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/relevant&quot;&gt;relevant&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;topic: &lt;a href=&quot;../.././../tags/mobile-attack&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/mobile-attack&quot;&gt;mobile-attack&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;🔖MISP Galaxies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;producer &lt;a href=&quot;../.././../tags/CloudSEK&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/CloudSEK&quot;&gt;CloudSEK&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;target-information=“Malaysia”&lt;/li&gt;
&lt;li&gt;country=“china”&lt;/li&gt;
&lt;li&gt;financial-fraud=“Fake Website”&lt;/li&gt;
&lt;li&gt;financial-fraud=“Phishing”&lt;/li&gt;
&lt;li&gt;financial-fraud=“Compromised Account Credentials”&lt;/li&gt;
&lt;li&gt;financial-fraud=“Compromised Personally Identifiable Information (PII)”&lt;/li&gt;
&lt;li&gt;financial-fraud=“Virtual Currency Fraud”&lt;/li&gt;
&lt;li&gt;financial-fraud=“Cryptocurrency Exchange”&lt;/li&gt;
&lt;li&gt;financial-fraud=“Social Media Scams”&lt;/li&gt;
&lt;li&gt;financial-fraud=“Fake App”&lt;/li&gt;
&lt;li&gt;financial-fraud=“Scam”&lt;/li&gt;
&lt;li&gt;mitre-attack-pattern=[]&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;MISP event uuid: &lt;a href=&quot;https://mispmy.rectifyq.com/events/view/020ceb62-7009-41fe-b22f-1ddd6806e4ea&quot; class=&quot;external&quot;&gt;020ceb62-7009-41fe-b22f-1ddd6806e4ea&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2 id=&quot;indicator-of-compromise-iocs&quot;&gt;Indicator of Compromise (IoCs)&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#indicator-of-compromise-iocs&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;pre&gt;&lt;code&gt;type,value,comment
domain, zhguihc.com, &#039;cloned domain&#039;
domain, zhguize.com, &#039;cloned domain&#039;
hostname, rtqs.zhguiwe.com, &#039;&#039;
hostname, udesk.zhgui.com, &#039;Embeds Udesk customer service integrations&#039;
ip-dst, 52.77.125.17, &#039;backend management consoles&#039;
ip-dst, 188.114.96.3, &#039;replicate the scam login and investment page&#039;
ip-dst, 172.67.191.67, &#039;replicate the scam login and investment page&#039;
ip-dst, 104.21.84.186, &#039;replicate the scam login and investment page&#039;
domain, zhgui.com, &#039;&#039;
ip-dst, 172.67.145.192, &#039;&#039;
domain, zhguiro.com, &#039;&#039;
ip-dst, 18.164.237.46, &#039;&#039;
domain, zhguiwd.com, &#039;&#039;
ip-dst, 18.164.246.64, &#039;&#039;
domain, zhguiyv.com, &#039;&#039;
ip-dst, 18.66.63.105, &#039;&#039;
domain, zhguitn.com, &#039;&#039;
ip-dst, 104.21.48.1, &#039;&#039;
domain, zhguivx.com, &#039;&#039;
ip-dst, 18.164.246.111, &#039;&#039;
domain, zhguimj.com, &#039;&#039;
domain, zhguioe.com, &#039;&#039;
ip-dst, 104.21.84.95, &#039;&#039;
domain, zhguiqt.com, &#039;&#039;
ip-dst, 172.67.149.149, &#039;&#039;
domain, zhguisp.com, &#039;&#039;
domain, zhguicx.com, &#039;&#039;
sha256, 1ca2e500f792fdce9128e8f26fd0a5c10b3f06f1047ce5217e5789db9b33681b, &#039;favicon hash No sample in VT\r\nLast check:09/02/2026&#039;
url, https://www.knightkron.com, &#039;domains replicate identical ZHGUI interfaces&#039;
url, https://www.sydmonet.com, &#039;domains replicate identical ZHGUI interfaces&#039;
url, https://52.77.125.17/home/login, &#039;Presents an internal “Management Console” login page&#039;
url, https://udesk.zhgui.com/, &#039;Exposes an end-user login page with Chinese-language error messages and the same JavaScript resources&#039;
url, https://52.74.11.35/, &#039;Exposes an end-user login page with Chinese-language error messages and the same JavaScript resources&#039;
ip-dst, 18.66.112.81, &#039;&#039;
hostname, rtqs.zhguibn.com, &#039;&#039;
ip-dst, 18.244.18.3, &#039;&#039;
url, https://1884145.s5.udesk.cn/im_client/?web_plugin_id=350&amp;#x26;language=en-us&amp;#x26;im_user_key=66666, &#039;&#039;
url, https://1884145.udeskglobal.com/sim, &#039;&#039;
email-src, support@zhgui.org, &#039;&#039;
url, https://msb.fincen.gov/msb.registration.letter.php?ID=28612373, &#039;&#039;
url, https://doc.zhgui.com/ZHGUI-Whitepaper-EN.pdf, &#039;&#039;
domain, zhguiqz.com, &#039;&#039;
url, https://www.wikifx.me/en/newsdetail/202510231334676397.html, &#039;&#039;
url, https://apps.apple.com/us/app/zhguige/id6747241718, &#039;&#039;
url, https://klse.i3investor.com/web/blog/detail/ZHGUIscam/2025-07-25-story-h499657939-ZHGUI_Exchange_Reminder_Beware_of_On_Chain_Data_Forgery_Traps_and_Stay_A, &#039;&#039;
url, https://www.zhgui.org, &#039;&#039;
url, https://www.facebook.com/ZHGUI.Official, &#039;&#039;
url, https://www.facebook.com/ZHGUI.Global/, &#039;&#039;
url, https://x.com/ZHGUI_, &#039;&#039;
url, https://x.com/ZHGUI_global, &#039;&#039;
url, https://t.me/lease_choobot, &#039;&#039;
url, https://www.facebook.com/share/p/1KCg4dA3k9/, &#039;&#039;
url, https://www.linkedin.com/posts/ivanblinde_web3-defi-innovation-activity-7337856604559634432-IjRC, &#039;LinkedIn Promotion Post (Likely Fraudulent)&#039;

Full IOCs available in Rectifyq&#039;s MISP```
&lt;/code&gt;&lt;/pre&gt; ]]></description>
    <pubDate>Mon, 02 Feb 2026 00:00:00 GMT</pubDate>
  </item><item>
    <title>Ransomware Tracker</title>
    <link>https://rectifyq.com/MY-Threat-Landscape/ransomware</link>
    <guid>https://rectifyq.com/MY-Threat-Landscape/ransomware</guid>
    <description><![CDATA[ &lt;h1 id=&quot;ransomware-tracker&quot;&gt;Ransomware Tracker&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#ransomware-tracker&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h1&gt;
&lt;h2 id=&quot;timeline-of-my-organizations-in-alleged-ransomware-cases&quot;&gt;Timeline of MY organizations in alleged Ransomware cases&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#timeline-of-my-organizations-in-alleged-ransomware-cases&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;pre&gt;&lt;button class=&quot;expand-button&quot; aria-label=&quot;Expand mermaid diagram&quot; data-view-component&gt;&lt;svg width=&quot;16&quot; height=&quot;16&quot; viewBox=&quot;0 0 16 16&quot; fill=&quot;currentColor&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M3.72 3.72a.75.75 0 011.06 1.06L2.56 7h10.88l-2.22-2.22a.75.75 0 011.06-1.06l3.5 3.5a.75.75 0 010 1.06l-3.5 3.5a.75.75 0 11-1.06-1.06l2.22-2.22H2.56l2.22 2.22a.75.75 0 11-1.06 1.06l-3.5-3.5a.75.75 0 010-1.06l3.5-3.5z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/button&gt;&lt;code class=&quot;mermaid&quot; data-clipboard=&quot;&amp;#x22;timeline\n    title Alleged Ransomware cases on Malaysian organizations\n    2018 : Med** Pri** Ber*** (Television Broadcast)\n    2021 : GDe****** Ber*** (Logistic)\n         : Mer********* Asi* Sdn Bhd (Payment)\n         : Jab**** Per******** Ban*** dan Des* Neg*** Sel***** (Government, Administration)\n         : TLP Ter***** Sdn Bhd (Logistic)\n         : UM* Hol***** Ber*** (Multi-sector)\n    2022 : Asi* Pac**** Uni******* Sdn* Bhd* (Academia - University)\n         : Sho******* Sdn Bhd (Marketing)\n         : UCS* Edu****** Sdn* Bhd* (Academia - University)\n         : Aut**** Hir***** Saf*** Sdn Bhd (Automotive)\n         : Age*** Pek****** Mel***** Sdn Bhd (Employment)\n         : Air**** Gro** (Civil Aviation)\n    2023 : Mat*** Edu**** Sdn Bhd* (Education)\n         : ViT*** Cor******** Ber*** (Electronic)\n         : Kil*** Ti* Ca* (Se** Sdn Bhd (Manufacturing)\n         : Sun**** Pha*********** Sdn Bhd (Pharmacy)\n         : TF AM* Mic************* (Electronic)\n         : Age*** Kau******* dan Pen******* Kre*** (Government, Administration)\n         : Fia*** Hol***** Ber*** (Multi-sector)\n         : Isk***** Reg***** Dev******** Aut****** (Government, Administration)\n         : Hon* Kon* Sa Sa (M) Sdn***** (Online marketplace)\n         : Lei* Hin* Gro** (Ka** San*** Mal****** (Logistic)\n         : Asi* Pac**** Uni******* Sdn* Bhd* (Academia - University)\n         : Pla********** (M) Sdn Bhd* (Manufacturing)\n         : Pen**** Sol***** Sdn* Bhd* (IT)\n         : Pra****** Mal***** Ber*** (Transport)\n         : Waw**** Den**** Sdn Bhd (Construction)\n         : May*** Man********** (M) Sdn Bhd (Manufacturing)\n         : Ala* Flo** Sdn Bhd (Environment)\n         : Nat***** Ant*********** Cri** Cen*** (NF*** (Government, Administration)\n         : Ind** Wat** Kon******* Sdn Bhd (Environment)\n         : Ken** Cor******** (M) Sdn Bhd (Agriculture)\n         : Tra******* Int********** Ins****** Bro**** Sdn Bhd (Insurance)\n    2024 : Har****** Hol***** Ber*** (Manufacturing)\n         : HOE Pha************ Sdn Bhd (Pharmacy)\n         : IJM Cor******** Ber*** (Multi-sector)\n         : Fre***** Int********** Sdn* Bhd* (Manufacturing)\n         : Rek*** Sdn* Bhd* (Technology)\n         : Kov** Sdn Bhd (eCommerce)\n         : Mal****** Ind******* Dev******** Fin**** Ber*** (MI*** (Finance)\n         : MH* Dis********* Sdn Bhd (Retail)\n         : CAR***** HES* Ope****** Com**** Sdn Bhd (Oil and Gas)\n         : iCa***** Lim**** (Automotive)\n         : Pra****** Mal***** Ber*** (Transport)\n         : Ban* Ker****** Rak*** Mal***** Ber*** (Bank)\n         : REX**** PC Sdn Bhd (Retail)\n         : Duo****** Bio**** Ber*** (Pharmacy)\n         : FG* Hol***** Ber*** (Agriculture)\n         : CAR*** Est*** Sdn Bhd (Pharmacy)\n         : Phe** Uni* Tru*** Ber*** (Investment)\n         : Sou***** Aci** (M) Ber*** (Chemical)\n         : Del** Hol***** (M) Sdn Bhd (Security systems)\n         : MI* Ind******* Sdn Bhd (Engineering)\n         : Maj*** Aga** Isl** Mel*** (Government, Administration)\n    2025 : Mal**** Air**** Sdn Bhd* (Civil Aviation)\n         : Kov** Sdn Bhd (eCommerce)\n         : Rek*** Sdn* Bhd* (Technology)\n         : CAR* CO* MY Sdn* Bhd* (IT)\n         : Tho** Si* Sdn Bhd (Retail)\n         : Ran**** Ber****** Sdn Bhd (Engineering)\n         : Aeo****** Int******** Sdn Bhd (Game)\n         : Swi** Hau**** Ber*** (Logistic)\n         : Rai**** As**** Cor******** (Railway)\n         : Maj*** Per******** Amp*** Jay* (Government, Administration)\n         : Mal***** Air***** Hol***** Ber*** (Civil Aviation)\n         : Naz* TTD* Sdn Bhd (Automotive)\n         : TF AM* Mic************* (Electronic)\n         : MS Sup*** Cha** Sol****** (Ma******* Sdn Bhd (Logistic)\n         : Agr***** Hol***** Sdn Bhd (Agriculture)\n         : Dew** Ban****** Kua** Lum*** (Government, Administration)\n         : MS* Met** Ind******* Sdn Bhd (Manufacturing)\n         : Eve******* Cor******** Ber*** (Engineering)\n         : War**** TC Hol***** Ber*** (Multi-sector)\n         : Ta* Cho** Mot** Hol***** Ber*** (Automotive)\n         : Cus*** Foo* Ing******** Sdn Bhd (Food)\n         : HC* Cap**** Gro**(Development)\n         : Pal***** Man******* Sdn Bhd (Investment)\n         : EAS* Des*** Arc****** Sdn* Bhd (Consulting)\n         : SF* Tec******* (M) Sdn Bhd (Electric)\n         : Reg**** Spe******* Hos***** (Health)\n         : Mei****** (Ma******* Sdn Bhd (Engineering)\n         : Fed**** Aut* Hol***** Ber*** (Automotive)\n         : Sil******* Axi* Ltd Gro** (IT)\n         : CyP*** Res****** Ber*** (Energy)\n         : Hei**** Pad* Ber*** (IT)\n         : YP* (Ma******* Sdn Bhd (Manufacturing)\n         : XO* Com Sdn Bhd (Telecoms)\n         : MFE* For***** Tec******* Sdn Bhd (Construction)\n         : Sou***** Lio* Sdn* Bhd* (Manufacturing)\n         : PJS* Con******** Sdn Bhd (Consulting)\n         : Ori***** Cas*** Sdn Bhd (Manufacturing)\n         : Ber**** Air Sdn* Bhd* (Civil Aviation)\n    2026 : Sun*** Gro** Ber*** (Manufacturer)\n         : Bin* Dar****** Ber*** (Construction)\n         : PTS Gol***** Ind******* Sdn Bhd (Manufacturing)\n         : RED**** Dig**** Ber*** (Telecoms)\n         : Che***** Kon******* Sdn Bhd (Engineering)\n         : Per**** Petr***** Ber*** (Oil and Gas)\n         : WRP Asi* Pac**** Sdn Bhd (Manufacturing)\n         : Kon**** Nas***** Ber*** (Logistic)\n         : PLU* Mal***** Ber*** (Infrastructure)\n         : WCT Hol***** Ber*** (Construction)\n         : Mal***** Air***** (Civil Aviation)\n         : Gol*** Cla* Ind******* Sdn Bhd (Manufacturing)&amp;#x22;&quot;&gt;timeline
    title Alleged Ransomware cases on Malaysian organizations
    2018 : Med** Pri** Ber*** (Television Broadcast)
    2021 : GDe****** Ber*** (Logistic)
         : Mer********* Asi* Sdn Bhd (Payment)
         : Jab**** Per******** Ban*** dan Des* Neg*** Sel***** (Government, Administration)
         : TLP Ter***** Sdn Bhd (Logistic)
         : UM* Hol***** Ber*** (Multi-sector)
    2022 : Asi* Pac**** Uni******* Sdn* Bhd* (Academia - University)
         : Sho******* Sdn Bhd (Marketing)
         : UCS* Edu****** Sdn* Bhd* (Academia - University)
         : Aut**** Hir***** Saf*** Sdn Bhd (Automotive)
         : Age*** Pek****** Mel***** Sdn Bhd (Employment)
         : Air**** Gro** (Civil Aviation)
    2023 : Mat*** Edu**** Sdn Bhd* (Education)
         : ViT*** Cor******** Ber*** (Electronic)
         : Kil*** Ti* Ca* (Se** Sdn Bhd (Manufacturing)
         : Sun**** Pha*********** Sdn Bhd (Pharmacy)
         : TF AM* Mic************* (Electronic)
         : Age*** Kau******* dan Pen******* Kre*** (Government, Administration)
         : Fia*** Hol***** Ber*** (Multi-sector)
         : Isk***** Reg***** Dev******** Aut****** (Government, Administration)
         : Hon* Kon* Sa Sa (M) Sdn***** (Online marketplace)
         : Lei* Hin* Gro** (Ka** San*** Mal****** (Logistic)
         : Asi* Pac**** Uni******* Sdn* Bhd* (Academia - University)
         : Pla********** (M) Sdn Bhd* (Manufacturing)
         : Pen**** Sol***** Sdn* Bhd* (IT)
         : Pra****** Mal***** Ber*** (Transport)
         : Waw**** Den**** Sdn Bhd (Construction)
         : May*** Man********** (M) Sdn Bhd (Manufacturing)
         : Ala* Flo** Sdn Bhd (Environment)
         : Nat***** Ant*********** Cri** Cen*** (NF*** (Government, Administration)
         : Ind** Wat** Kon******* Sdn Bhd (Environment)
         : Ken** Cor******** (M) Sdn Bhd (Agriculture)
         : Tra******* Int********** Ins****** Bro**** Sdn Bhd (Insurance)
    2024 : Har****** Hol***** Ber*** (Manufacturing)
         : HOE Pha************ Sdn Bhd (Pharmacy)
         : IJM Cor******** Ber*** (Multi-sector)
         : Fre***** Int********** Sdn* Bhd* (Manufacturing)
         : Rek*** Sdn* Bhd* (Technology)
         : Kov** Sdn Bhd (eCommerce)
         : Mal****** Ind******* Dev******** Fin**** Ber*** (MI*** (Finance)
         : MH* Dis********* Sdn Bhd (Retail)
         : CAR***** HES* Ope****** Com**** Sdn Bhd (Oil and Gas)
         : iCa***** Lim**** (Automotive)
         : Pra****** Mal***** Ber*** (Transport)
         : Ban* Ker****** Rak*** Mal***** Ber*** (Bank)
         : REX**** PC Sdn Bhd (Retail)
         : Duo****** Bio**** Ber*** (Pharmacy)
         : FG* Hol***** Ber*** (Agriculture)
         : CAR*** Est*** Sdn Bhd (Pharmacy)
         : Phe** Uni* Tru*** Ber*** (Investment)
         : Sou***** Aci** (M) Ber*** (Chemical)
         : Del** Hol***** (M) Sdn Bhd (Security systems)
         : MI* Ind******* Sdn Bhd (Engineering)
         : Maj*** Aga** Isl** Mel*** (Government, Administration)
    2025 : Mal**** Air**** Sdn Bhd* (Civil Aviation)
         : Kov** Sdn Bhd (eCommerce)
         : Rek*** Sdn* Bhd* (Technology)
         : CAR* CO* MY Sdn* Bhd* (IT)
         : Tho** Si* Sdn Bhd (Retail)
         : Ran**** Ber****** Sdn Bhd (Engineering)
         : Aeo****** Int******** Sdn Bhd (Game)
         : Swi** Hau**** Ber*** (Logistic)
         : Rai**** As**** Cor******** (Railway)
         : Maj*** Per******** Amp*** Jay* (Government, Administration)
         : Mal***** Air***** Hol***** Ber*** (Civil Aviation)
         : Naz* TTD* Sdn Bhd (Automotive)
         : TF AM* Mic************* (Electronic)
         : MS Sup*** Cha** Sol****** (Ma******* Sdn Bhd (Logistic)
         : Agr***** Hol***** Sdn Bhd (Agriculture)
         : Dew** Ban****** Kua** Lum*** (Government, Administration)
         : MS* Met** Ind******* Sdn Bhd (Manufacturing)
         : Eve******* Cor******** Ber*** (Engineering)
         : War**** TC Hol***** Ber*** (Multi-sector)
         : Ta* Cho** Mot** Hol***** Ber*** (Automotive)
         : Cus*** Foo* Ing******** Sdn Bhd (Food)
         : HC* Cap**** Gro**(Development)
         : Pal***** Man******* Sdn Bhd (Investment)
         : EAS* Des*** Arc****** Sdn* Bhd (Consulting)
         : SF* Tec******* (M) Sdn Bhd (Electric)
         : Reg**** Spe******* Hos***** (Health)
         : Mei****** (Ma******* Sdn Bhd (Engineering)
         : Fed**** Aut* Hol***** Ber*** (Automotive)
         : Sil******* Axi* Ltd Gro** (IT)
         : CyP*** Res****** Ber*** (Energy)
         : Hei**** Pad* Ber*** (IT)
         : YP* (Ma******* Sdn Bhd (Manufacturing)
         : XO* Com Sdn Bhd (Telecoms)
         : MFE* For***** Tec******* Sdn Bhd (Construction)
         : Sou***** Lio* Sdn* Bhd* (Manufacturing)
         : PJS* Con******** Sdn Bhd (Consulting)
         : Ori***** Cas*** Sdn Bhd (Manufacturing)
         : Ber**** Air Sdn* Bhd* (Civil Aviation)
    2026 : Sun*** Gro** Ber*** (Manufacturer)
         : Bin* Dar****** Ber*** (Construction)
         : PTS Gol***** Ind******* Sdn Bhd (Manufacturing)
         : RED**** Dig**** Ber*** (Telecoms)
         : Che***** Kon******* Sdn Bhd (Engineering)
         : Per**** Petr***** Ber*** (Oil and Gas)
         : WRP Asi* Pac**** Sdn Bhd (Manufacturing)
         : Kon**** Nas***** Ber*** (Logistic)
         : PLU* Mal***** Ber*** (Infrastructure)
         : WCT Hol***** Ber*** (Construction)
         : Mal***** Air***** (Civil Aviation)
         : Gol*** Cla* Ind******* Sdn Bhd (Manufacturing)
&lt;/code&gt;&lt;div id=&quot;mermaid-container&quot; role=&quot;dialog&quot;&gt;&lt;div id=&quot;mermaid-space&quot;&gt;&lt;div class=&quot;mermaid-content&quot;&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/pre&gt;
&lt;p&gt;p.s. This is based on Ransomware Group claims or news, unless the organization confirmed it then it is only a claim.&lt;/p&gt;
&lt;h2 id=&quot;top-10-ransomware-group-impacting-malaysian-organziations&quot;&gt;Top 10 Ransomware Group impacting Malaysian Organziations&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#top-10-ransomware-group-impacting-malaysian-organziations&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;pre&gt;&lt;button class=&quot;expand-button&quot; aria-label=&quot;Expand mermaid diagram&quot; data-view-component&gt;&lt;svg width=&quot;16&quot; height=&quot;16&quot; viewBox=&quot;0 0 16 16&quot; fill=&quot;currentColor&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M3.72 3.72a.75.75 0 011.06 1.06L2.56 7h10.88l-2.22-2.22a.75.75 0 011.06-1.06l3.5 3.5a.75.75 0 010 1.06l-3.5 3.5a.75.75 0 11-1.06-1.06l2.22-2.22H2.56l2.22 2.22a.75.75 0 11-1.06 1.06l-3.5-3.5a.75.75 0 010-1.06l3.5-3.5z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/button&gt;&lt;code class=&quot;mermaid&quot; data-clipboard=&quot;&amp;#x22;pie title Ransomware Victim (by sector)\n    \&amp;#x22;Lockbit3\&amp;#x22; : 21\n    \&amp;#x22;Qilin\&amp;#x22; : 14\n    \&amp;#x22;Ransomhub\&amp;#x22; : 7\n    \&amp;#x22;Direwolf\&amp;#x22; : 7\n    \&amp;#x22;Akira\&amp;#x22; : 5\n    \&amp;#x22;The Gentlemen\&amp;#x22; : 5\n    \&amp;#x22;BlackCat\&amp;#x22; : 4\n    \&amp;#x22;Hunters\&amp;#x22; : 4\n    \&amp;#x22;Babuk\&amp;#x22; : 4\n    \&amp;#x22;Lockbit\&amp;#x22; : 3&amp;#x22;&quot;&gt;pie title Ransomware Victim (by sector)
    &quot;Lockbit3&quot; : 21
    &quot;Qilin&quot; : 14
    &quot;Ransomhub&quot; : 7
    &quot;Direwolf&quot; : 7
    &quot;Akira&quot; : 5
    &quot;The Gentlemen&quot; : 5
    &quot;BlackCat&quot; : 4
    &quot;Hunters&quot; : 4
    &quot;Babuk&quot; : 4
    &quot;Lockbit&quot; : 3
&lt;/code&gt;&lt;div id=&quot;mermaid-container&quot; role=&quot;dialog&quot;&gt;&lt;div id=&quot;mermaid-space&quot;&gt;&lt;div class=&quot;mermaid-content&quot;&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/pre&gt;
&lt;h2 id=&quot;top-10-sectors-affected-by-ransomware&quot;&gt;Top 10 sectors affected by Ransomware&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#top-10-sectors-affected-by-ransomware&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;pre&gt;&lt;button class=&quot;expand-button&quot; aria-label=&quot;Expand mermaid diagram&quot; data-view-component&gt;&lt;svg width=&quot;16&quot; height=&quot;16&quot; viewBox=&quot;0 0 16 16&quot; fill=&quot;currentColor&quot;&gt;&lt;path fill-rule=&quot;evenodd&quot; d=&quot;M3.72 3.72a.75.75 0 011.06 1.06L2.56 7h10.88l-2.22-2.22a.75.75 0 011.06-1.06l3.5 3.5a.75.75 0 010 1.06l-3.5 3.5a.75.75 0 11-1.06-1.06l2.22-2.22H2.56l2.22 2.22a.75.75 0 11-1.06 1.06l-3.5-3.5a.75.75 0 010-1.06l3.5-3.5z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/button&gt;&lt;code class=&quot;mermaid&quot; data-clipboard=&quot;&amp;#x22;pie title Ransomware Victim (by sector)\n    \&amp;#x22;Manufacturing\&amp;#x22; : 12\n    \&amp;#x22;Government, Administration\&amp;#x22; : 7\n    \&amp;#x22;Logistic\&amp;#x22; : 6\n    \&amp;#x22;Engineering\&amp;#x22; : 5\n    \&amp;#x22;Automotive\&amp;#x22; : 5\n    \&amp;#x22;Civil Aviation\&amp;#x22; : 5\n    \&amp;#x22;Pharmacy\&amp;#x22; : 4\n    \&amp;#x22;Multi-sector\&amp;#x22; : 4\n    \&amp;#x22;IT\&amp;#x22; : 4\n    \&amp;#x22;Construction\&amp;#x22; : 4&amp;#x22;&quot;&gt;pie title Ransomware Victim (by sector)
    &quot;Manufacturing&quot; : 12
    &quot;Government, Administration&quot; : 7
    &quot;Logistic&quot; : 6
    &quot;Engineering&quot; : 5
    &quot;Automotive&quot; : 5
    &quot;Civil Aviation&quot; : 5
    &quot;Pharmacy&quot; : 4
    &quot;Multi-sector&quot; : 4
    &quot;IT&quot; : 4
    &quot;Construction&quot; : 4
&lt;/code&gt;&lt;div id=&quot;mermaid-container&quot; role=&quot;dialog&quot;&gt;&lt;div id=&quot;mermaid-space&quot;&gt;&lt;div class=&quot;mermaid-content&quot;&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/pre&gt;
&lt;h2 id=&quot;full-breakdown-ransomware-victim-by-sector&quot;&gt;Full breakdown Ransomware victim by sector:&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#full-breakdown-ransomware-victim-by-sector&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;

















































































































































































&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Sector&lt;/th&gt;&lt;th&gt;Count&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;Manufacturing&lt;/td&gt;&lt;td&gt;12&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Government, Administration&lt;/td&gt;&lt;td&gt;7&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Logistic&lt;/td&gt;&lt;td&gt;6&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Engineering&lt;/td&gt;&lt;td&gt;5&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Automotive&lt;/td&gt;&lt;td&gt;5&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Civil Aviation&lt;/td&gt;&lt;td&gt;5&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Pharmacy&lt;/td&gt;&lt;td&gt;4&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Multi-sector&lt;/td&gt;&lt;td&gt;4&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;IT&lt;/td&gt;&lt;td&gt;4&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Construction&lt;/td&gt;&lt;td&gt;4&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Agriculture&lt;/td&gt;&lt;td&gt;3&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Retail&lt;/td&gt;&lt;td&gt;3&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Electronic&lt;/td&gt;&lt;td&gt;3&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Academia - University&lt;/td&gt;&lt;td&gt;3&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Technology&lt;/td&gt;&lt;td&gt;2&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Telecoms&lt;/td&gt;&lt;td&gt;2&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Oil and Gas&lt;/td&gt;&lt;td&gt;2&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Investment&lt;/td&gt;&lt;td&gt;2&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Environment&lt;/td&gt;&lt;td&gt;2&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;eCommerce&lt;/td&gt;&lt;td&gt;2&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Consulting&lt;/td&gt;&lt;td&gt;2&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Transport&lt;/td&gt;&lt;td&gt;2&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Bank&lt;/td&gt;&lt;td&gt;1&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Railway&lt;/td&gt;&lt;td&gt;1&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Online marketplace&lt;/td&gt;&lt;td&gt;1&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Finance&lt;/td&gt;&lt;td&gt;1&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Health&lt;/td&gt;&lt;td&gt;1&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Television Broadcast&lt;/td&gt;&lt;td&gt;1&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Marketing&lt;/td&gt;&lt;td&gt;1&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Manufacturer&lt;/td&gt;&lt;td&gt;1&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Development&lt;/td&gt;&lt;td&gt;1&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Energy&lt;/td&gt;&lt;td&gt;1&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Insurance&lt;/td&gt;&lt;td&gt;1&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Employment&lt;/td&gt;&lt;td&gt;1&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Chemical&lt;/td&gt;&lt;td&gt;1&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Payment&lt;/td&gt;&lt;td&gt;1&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Security systems&lt;/td&gt;&lt;td&gt;1&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Electric&lt;/td&gt;&lt;td&gt;1&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Food&lt;/td&gt;&lt;td&gt;1&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Education&lt;/td&gt;&lt;td&gt;1&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Game&lt;/td&gt;&lt;td&gt;1&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Infrastructure&lt;/td&gt;&lt;td&gt;1&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
&lt;p&gt;The NCII sectors are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Government&lt;/li&gt;
&lt;li&gt;Banking and finance&lt;/li&gt;
&lt;li&gt;Transportation&lt;/li&gt;
&lt;li&gt;Defence and national security&lt;/li&gt;
&lt;li&gt;Information, communication and digital&lt;/li&gt;
&lt;li&gt;Healthcare services&lt;/li&gt;
&lt;li&gt;Water, sewerage and waste management&lt;/li&gt;
&lt;li&gt;Energy&lt;/li&gt;
&lt;li&gt;Agriculture and plantation&lt;/li&gt;
&lt;li&gt;Trade, industry and economy&lt;/li&gt;
&lt;li&gt;Science, technology and innovation&lt;/li&gt;
&lt;/ul&gt; ]]></description>
    <pubDate>Thu, 29 Jan 2026 00:00:00 GMT</pubDate>
  </item><item>
    <title>Sources</title>
    <link>https://rectifyq.com/Threat-Intelligence-Platform-(TIP)/source</link>
    <guid>https://rectifyq.com/Threat-Intelligence-Platform-(TIP)/source</guid>
    <description><![CDATA[ &lt;h2 id=&quot;general-sources&quot;&gt;General sources&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#general-sources&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Alienvault OTX (LevelBlue Inc)&lt;/li&gt;
&lt;li&gt;X (twitter)&lt;/li&gt;
&lt;li&gt;URLScan.io&lt;/li&gt;
&lt;li&gt;Triage&lt;/li&gt;
&lt;li&gt;MyCERT advisories&lt;/li&gt;
&lt;li&gt;Cybersecurity vendors article&lt;/li&gt;
&lt;li&gt;Cybersecurity news&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cfr.org/global-conflict-tracker&quot; class=&quot;external&quot;&gt;https://www.cfr.org/global-conflict-tracker&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.cfr.org/cyber-operations/&quot; class=&quot;external&quot;&gt;https://www.cfr.org/cyber-operations/&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://thestraitsintelligence.com/&quot; class=&quot;external&quot;&gt;https://thestraitsintelligence.com/&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://globalthreatmap.up.railway.app/&quot; class=&quot;external&quot;&gt;https://globalthreatmap.up.railway.app/&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;local-cyberheroes&quot;&gt;Local cyberheroes&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#local-cyberheroes&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://blog.xanda.org/&quot; class=&quot;external&quot;&gt;https://blog.xanda.org/&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://blog.khairulazam.net/&quot; class=&quot;external&quot;&gt;https://blog.khairulazam.net/&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://fareedfauzi.github.io/&quot; class=&quot;external&quot;&gt;https://fareedfauzi.github.io/&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://rz.my/&quot; class=&quot;external&quot;&gt;https://rz.my/&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://mokhdzanifaeq.github.io/&quot; class=&quot;external&quot;&gt;https://mokhdzanifaeq.github.io/&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://7imbitz.github.io/&quot; class=&quot;external&quot;&gt;https://7imbitz.github.io/&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://ap0k4l1p5.github.io/&quot; class=&quot;external&quot;&gt;https://ap0k4l1p5.github.io/&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://blog.apnic.net/author/adli-w/&quot; class=&quot;external&quot;&gt;https://blog.apnic.net/author/adli-w/&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://www.data0.net/&quot; class=&quot;external&quot;&gt;https://www.data0.net/&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://thestraitsintelligence.com/&quot; class=&quot;external&quot;&gt;https://thestraitsintelligence.com/&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;private-sources&quot;&gt;Private sources&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#private-sources&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;HS - Malaysia Spamtrap Project&lt;/li&gt;
&lt;li&gt;Rectifyq’s MISPs Project&lt;/li&gt;
&lt;/ul&gt; ]]></description>
    <pubDate>Thu, 29 Jan 2026 00:00:00 GMT</pubDate>
  </item><item>
    <title>MISP Style Guide</title>
    <link>https://rectifyq.com/Threat-Intelligence-Platform-(TIP)/style-guide</link>
    <guid>https://rectifyq.com/Threat-Intelligence-Platform-(TIP)/style-guide</guid>
    <description><![CDATA[ &lt;h1 id=&quot;rectifyqs-misp-style-guide&quot;&gt;Rectifyq’s MISP Style Guide&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#rectifyqs-misp-style-guide&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h1&gt;
&lt;h2 id=&quot;traffic-light-protocol-tlp&quot;&gt;Traffic Light Protocol (TLP)&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#traffic-light-protocol-tlp&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;






























&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;TLP&lt;/th&gt;&lt;th&gt;Formal Definition&lt;/th&gt;&lt;th&gt;Rectifyq’s audience&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;🔴 tlp:red&lt;/td&gt;&lt;td&gt;For the eyes and ears of individual recipients only, no further disclosure.&lt;/td&gt;&lt;td&gt;Rectifyq + specific recipients&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;🟠 tlp:amber&lt;/td&gt;&lt;td&gt;Limited disclosure, recipients can only spread this on a need-to-know basis within their organization and its clients.&lt;/td&gt;&lt;td&gt;Rectifyq + Cyberheroes&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;🟢 tlp:green&lt;/td&gt;&lt;td&gt;Limited disclosure, recipients can spread this within their community.&lt;/td&gt;&lt;td&gt;Rectifyq + Cyberheroes + Cybervigilantes&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;⚪ tlp:clear&lt;/td&gt;&lt;td&gt;Information can be shared publicly in accordance with the law.&lt;/td&gt;&lt;td&gt;Everyone&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
&lt;h2 id=&quot;severity-definition&quot;&gt;Severity definition&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#severity-definition&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;&lt;th width=&quot;106.5999755859375&quot;&gt;Severity&lt;/th&gt;&lt;th width=&quot;327.39990234375&quot;&gt;Description&lt;/th&gt;&lt;th&gt;Example&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;High&lt;/td&gt;&lt;td&gt;&lt;ul&gt;&lt;li&gt;&lt;font style=&quot;color:red;&quot;&gt;State sponsored TA&lt;/font&gt;&lt;/li&gt;&lt;li&gt;&lt;font style=&quot;color:red;&quot;&gt;APT + targeted&lt;/font&gt;&lt;/li&gt;&lt;li&gt;&lt;font style=&quot;color:red;&quot;&gt;Custom malware/tool + targeted&lt;/font&gt;&lt;/li&gt;&lt;li&gt;&lt;font style=&quot;color:blue;&quot;&gt;0day + exploited in wild&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/td&gt;&lt;td&gt;&lt;ul&gt;&lt;li&gt;Lazarus APT (North Korea)&lt;/li&gt;&lt;li&gt;FIN7 + target company A&lt;/li&gt;&lt;li&gt;Custom and targeting company A&lt;/li&gt;&lt;li&gt;Currently being exploited&lt;/li&gt;&lt;/ul&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Medium&lt;/td&gt;&lt;td&gt;&lt;ul&gt;&lt;li&gt;&lt;font style=&quot;color:red;&quot;&gt;APT + broad-based&lt;/font&gt;&lt;/li&gt;&lt;li&gt;&lt;font style=&quot;color:red;&quot;&gt;Ransomware (Threat &amp;#x26;&lt;/font&gt; &lt;font style=&quot;color:orange;&quot;&gt;Data Breach)&lt;/font&gt;&lt;/li&gt;&lt;li&gt;&lt;font style=&quot;color:red;&quot;&gt;Tool Profile&lt;/font&gt;&lt;/li&gt;&lt;li&gt;&lt;font style=&quot;color:red;&quot;&gt;Supply chain related&lt;/font&gt;&lt;/li&gt;&lt;li&gt;&lt;font style=&quot;color:blue;&quot;&gt;0day + POC&lt;/font&gt;&lt;/li&gt;&lt;li&gt;&lt;font style=&quot;color:blue;&quot;&gt;Critical/High/Branded Vulnerability&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/td&gt;&lt;td&gt;&lt;ul&gt;&lt;li&gt;FIN7 + Multiple countries&lt;/li&gt;&lt;li&gt;Any ransomware related&lt;/li&gt;&lt;li&gt;Any tool profiles&lt;/li&gt;&lt;li&gt;Any supply chain related&lt;/li&gt;&lt;li&gt;No actual case reported yet&lt;/li&gt;&lt;li&gt;Vuln focused w malware sample(s) exploiting it&lt;/li&gt;&lt;/ul&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Low&lt;/td&gt;&lt;td&gt;&lt;ul&gt;&lt;li&gt;&lt;font style=&quot;color:red;&quot;&gt;Cybercrime - broad-based&lt;/font&gt;&lt;/li&gt;&lt;li&gt;&lt;font style=&quot;color:red;&quot;&gt;Commodity malware&lt;/font&gt;&lt;/li&gt;&lt;li&gt;&lt;font style=&quot;color:orange;&quot;&gt;Infostealer leaks&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/td&gt;&lt;td&gt;&lt;ul&gt;&lt;li&gt;Phishing, clickfix, defacements campaigns&lt;/li&gt;&lt;li&gt;Infostealer, clickfix, etc&lt;/li&gt;&lt;li&gt;Lumma stealer, redline, vidar, etc&lt;/li&gt;&lt;/ul&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Undefined&lt;/td&gt;&lt;td&gt;&lt;ul&gt;&lt;li&gt;News article&lt;/li&gt;&lt;li&gt;Indictment&lt;/li&gt;&lt;li&gt;Achievement&lt;/li&gt;&lt;li&gt;To be removed&lt;/li&gt;&lt;/ul&gt;&lt;/td&gt;&lt;td&gt;Other articles that may still be interesting to be recorded.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;APT definition - Advanced Persistence Threat. Not only limited to State Sponsored.&lt;/p&gt;
&lt;h2 id=&quot;category&quot;&gt;Category&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#category&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th width=&quot;124&quot;&gt;Category&lt;/th&gt;&lt;th&gt;Descriptio&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;font style=&quot;color:red;&quot;&gt;Threat&lt;/font&gt;&lt;/td&gt;&lt;td&gt;In-depth analysis of specific cyber threats. The focus is on technical details, including &lt;strong&gt;Indicators of Compromise (IOCs)&lt;/strong&gt; and the &lt;strong&gt;Tactics, Techniques, and Procedures (TTPs)&lt;/strong&gt; utilized by threat actors.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;font style=&quot;color:orange;&quot;&gt;Data Breach&lt;/font&gt;&lt;/td&gt;&lt;td&gt;Articles covering confirmed or alleged incidents of &lt;strong&gt;unauthorized data access or exfiltration&lt;/strong&gt;. Key content focuses on the scope of the &lt;strong&gt;compromised data&lt;/strong&gt;, affected entities, or reports concerning &lt;strong&gt;ransomware victim claims&lt;/strong&gt;.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;font style=&quot;color:blue;&quot;&gt;Vulnerability&lt;/font&gt;&lt;/td&gt;&lt;td&gt;Articles that details the vulnerability&#039;s impact, and its exploitation status (e.g., availability of a Proof-of-Concept (POC) or active exploitation in the wild).&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
&lt;h2 id=&quot;sub-category&quot;&gt;Sub-category&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#sub-category&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th width=&quot;174&quot;&gt;Sub-category&lt;/th&gt;&lt;th&gt;Description&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;font style=&quot;color:red;&quot;&gt;Threat Actor Profile&lt;/font&gt;&lt;/td&gt;&lt;td&gt;A detailed report on a specific Threat Actor (who they are), how they attack, what tools they use, and all the past campaigns we think they are responsible for.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;font style=&quot;color:red;&quot;&gt;Tool Profile&lt;/font&gt;&lt;/td&gt;&lt;td&gt;A report that focuses on a single hacking &lt;strong&gt;tool&lt;/strong&gt; (or a normal tool that hackers abuse). It explains how it works, which hacker groups use it, and how you can detect and block it.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;font style=&quot;color:red;&quot;&gt;Malware Analysis&lt;/font&gt;&lt;/td&gt;&lt;td&gt;Deep dive analysis of malware either &lt;strong&gt;static, dynamic or reverse engineer&lt;/strong&gt; the malware sample(s) to understand how it works, capabilities, potential attributions and other intelligence requirements.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;font style=&quot;color:red;&quot;&gt;Intrusion Analysis (Incident Analysis)&lt;/font&gt;&lt;/td&gt;&lt;td&gt;A close-up look at one single successful attack on &lt;strong&gt;only against specific target (usually one)&lt;/strong&gt;. It maps out the entire story, from how the hacker first got in until they achieved their final goal (like stealing data).&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;font style=&quot;color:red;&quot;&gt;Campaign Analysis&lt;/font&gt;&lt;/td&gt;&lt;td&gt;A report that looks at several related attacks against &lt;em&gt;multiple&lt;/em&gt; targets. It helps connect the dots to see a bigger picture of what a hacker group is trying to achieve strategically.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;font style=&quot;color:orange;&quot;&gt;Leaks Forum&lt;/font&gt;&lt;/td&gt;&lt;td&gt;Reports focused on illegal underground forums where hackers post and try to sell or share data they claim to have stolen from a company.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;font style=&quot;color:orange;&quot;&gt;Leaks Infostealer&lt;/font&gt;&lt;/td&gt;&lt;td&gt;An analysis focused on finding stolen data logs (like passwords) from &quot;Infostealer&quot; malware that are linked to a specific company or organization.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;font style=&quot;color:blue;&quot;&gt;Zero-day&lt;/font&gt;&lt;/td&gt;&lt;td&gt;Unpatched Exploits: High-priority indicators for vulnerabilities that have no official patch or were exploited before public awareness.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;font style=&quot;color:blue;&quot;&gt;Branded Vulnerability&lt;/font&gt;&lt;/td&gt;&lt;td&gt;High-Profile Bugs: Vulnerabilities with marketing names/logos (e.g., Heartbleed, PwnKit) that often see rapid, mass exploitation.&quot;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;font style=&quot;color:blue;&quot;&gt;Critical Vulnerability&lt;/font&gt;&lt;/td&gt;&lt;td&gt;High-Severity Flaws: Standard vulnerabilities that carry a high CVSS/EPSS score but may not have a brand name&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Report&lt;/td&gt;&lt;td&gt;Other related cybersecurity or intelligence reports that is relevant.&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
&lt;h2 id=&quot;threat-actor-category&quot;&gt;Threat Actor Category&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#threat-actor-category&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th width=&quot;178&quot;&gt;TA Category&lt;/th&gt;&lt;th&gt;Description&lt;/th&gt;&lt;th&gt;Example&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;APT&lt;/td&gt;&lt;td&gt;Highly sophisticated, long-term clandestine campaigns. These actors have significant resources and focus on stealth to maintain persistent access to a network for espionage or data theft. Can be State sponsored, can be cybercrime.&lt;/td&gt;&lt;td&gt;Dark Basin, Lazarus, FIN7&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;State Sponsored&lt;/td&gt;&lt;td&gt;Highly-skilled hackers funded and directed by a government of certain nation.&lt;/td&gt;&lt;td&gt;APT28 (Fancy Bear), APT34 (OilRig), Lazarus Group&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Cybercrime&lt;/td&gt;&lt;td&gt;Individuals or organized groups (Cybercriminals) whose primary motivation is financial gain.&lt;/td&gt;&lt;td&gt;FIN7&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Ransomware&lt;/td&gt;&lt;td&gt;An organized collective of cybercriminals that develops, distributes, and operates sophisticated ransomware strains, often employing the Ransomware-as-a-Service (RaaS) model and double extortion tactics.&lt;/td&gt;&lt;td&gt;LockBit, BlackCat (ALPHV), Clop&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Hacktivist&lt;/td&gt;&lt;td&gt;Hackers motivated by a political, social, or ideological cause, using hacking as a form of protest.&lt;/td&gt;&lt;td&gt;Anonymous, LulzSec, OpIsrael&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
&lt;h2 id=&quot;target&quot;&gt;Target&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#target&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th width=&quot;177&quot;&gt;Target&lt;/th&gt;&lt;th&gt;Details&lt;/th&gt;&lt;th&gt;&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;Broad-based&lt;/td&gt;&lt;td&gt;&lt;ul&gt;&lt;li&gt;Commodity&lt;/li&gt;&lt;li&gt;Opportunistic&lt;/li&gt;&lt;/ul&gt;&lt;/td&gt;&lt;td&gt;&lt;ul&gt;&lt;li&gt;Everyone is a target, no exclusion&lt;/li&gt;&lt;li&gt;Everyone is a target, some exclusion such as specific country, locale, etc.&lt;/li&gt;&lt;li&gt;Specific Language - still broad (example targeting German/Mandarin Speaking)&lt;/li&gt;&lt;li&gt;Specific country - political events, etc.&lt;/li&gt;&lt;li&gt;Specific group of people (red-teamers, pentesters, gamers, etc.)&lt;/li&gt;&lt;/ul&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Targeted&lt;/td&gt;&lt;td&gt;Specific Target - specially crafted based on opportunity or targets Information Attack Space&lt;/td&gt;&lt;td&gt;&lt;ul&gt;&lt;li&gt;Specific Individual/Company/Organization&lt;/li&gt;&lt;/ul&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
&lt;h2 id=&quot;target--vs-victim&quot;&gt;Target  vs Victim&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#target--vs-victim&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th width=&quot;157.79998779296875&quot;&gt;Characteristics&lt;/th&gt;&lt;th&gt;Target&lt;/th&gt;&lt;th&gt;Victim&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;Inclusivity&lt;/td&gt;&lt;td&gt;All target is a victim&lt;/td&gt;&lt;td&gt;Not all victim is a target&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Details&lt;/td&gt;&lt;td&gt;Must contain specific key indicators (multiple) that directs to the target.&lt;/td&gt;&lt;td&gt;Most of the articles with specified country etc. is victim limited to their telemetry (who is their customer)&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Example&lt;/td&gt;&lt;td&gt;Based on keyword in the spear-phishing email which only relevant to the target and vulnerability exploited is opportunity TA used against the victim.  &lt;/td&gt;&lt;td&gt;Based on the telemetry of the vendor, it is found that country X has been affected in this campaign.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Defined as&lt;/td&gt;&lt;td&gt;specifically targeting&lt;/td&gt;&lt;td&gt; at least&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
&lt;h2 id=&quot;relevancy&quot;&gt;Relevancy&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#relevancy&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th width=&quot;207.4000244140625&quot;&gt;Relevancy&lt;/th&gt;&lt;th&gt;Example&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;🔴Relevant&lt;/td&gt;&lt;td&gt;APT targeting Malaysian entity.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;🟡Somewhat Relevant&lt;/td&gt;&lt;td&gt;APT target Asian country.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;🔵Potentially Relevant&lt;/td&gt;&lt;td&gt;Infostealers impact globally.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;⚫Not Relevant&lt;/td&gt;&lt;td&gt;Good to know only.&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
&lt;p&gt;&lt;sub&gt;p.s. Not relevant does not mean to be ignored, it can be use to improve our security detection or prevention from the lesson learn of the incident. It is just lower priority compared to other three as the event may specifically targeting organizations that is not related to Malaysia, or targeting specific language speakers (e.g. russian language) and etc.&lt;/sub&gt;&lt;/p&gt;
&lt;h2 id=&quot;rectifyqs-workflow&quot;&gt;Rectifyq’s Workflow&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#rectifyqs-workflow&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th width=&quot;174&quot;&gt;Workflow&lt;/th&gt;&lt;th&gt;Description&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;Check Date&lt;/td&gt;&lt;td&gt;Ensure MISP Event Date is same as the date the article was posted.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Review Severity&lt;/td&gt;&lt;td&gt;Select MISP Event severity as per above &lt;a href=&quot;#severity-definition&quot; class=&quot;internal alias&quot;&gt;severity definition&lt;/a&gt;.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Check Producer&lt;/td&gt;&lt;td&gt;Ensure correct &lt;a href=&quot;https://www.misp-galaxy.org/producer/&quot; class=&quot;external&quot;&gt;Producer&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; is tagged in MISP Event galaxy.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Check Actor&lt;/td&gt;&lt;td&gt;Add &lt;a href=&quot;https://www.misp-galaxy.org/threat-actor/&quot; class=&quot;external&quot;&gt;Threat Actor&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; tag in MISP Event Galaxy, if there is none in Galaxy, add as attribute and tag as create missing galaxy.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Check Target&lt;/td&gt;&lt;td&gt;Add &lt;a href=&quot;https://www.misp-galaxy.org/target-information/&quot; class=&quot;external&quot;&gt;Target Information&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; and &lt;a href=&quot;https://www.misp-galaxy.org/sector/&quot; class=&quot;external&quot;&gt;Sector&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt; tag in MISP Event Galaxy.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Check Tool&lt;/td&gt;&lt;td&gt;Add related tools tag in MISP Event Galaxy.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Check Malware&lt;/td&gt;&lt;td&gt;Add &lt;a href=&quot;https://www.misp-galaxy.org/malpedia/&quot; class=&quot;external&quot;&gt;Malpedia &lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;tag in MISP Event Galaxy&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Check TTP&lt;/td&gt;&lt;td&gt;Ensure MITRE ATT&amp;#x26;CK in MISP Event Galaxy is accurate, priority goes to Malaysia related event (may need to self curate if not provided by the Producer)&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Add IOC Context&lt;/td&gt;&lt;td&gt;Add comments with relevant context in each attributes. (e.g. &lt;code&gt;84c82835a5d21bbcf75a61706d8ab549&lt;/code&gt; - WannaCry Ransomware)&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Check Key Indicator&lt;/td&gt;&lt;td&gt;Add related attributes/objects with details that may be used for attribution such as:&lt;br&gt;- username:password used by TA in the infection chain&lt;br&gt;- decryption key used&lt;br&gt;- mutexes&lt;br&gt;- password for archives&lt;br&gt;- sender email addressess&lt;br&gt;- language used&lt;br&gt;- etc.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Need sample sponsor&lt;/td&gt;&lt;td&gt;Require Malware sample sponsor, either upload to Malware Bazaar (preferred) or upload directly to MISP(for sample with sensitive data)&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;To Report to&lt;/td&gt;&lt;td&gt;To report to relevant parties such as the owner, hosting provider, MyCERT, registrar or etc.&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
&lt;h2 id=&quot;topics&quot;&gt;Topics&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#topics&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;

























&lt;table&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;Topics&lt;/th&gt;&lt;th&gt;Description&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;a href=&quot;../geopolitical&quot; class=&quot;internal&quot; data-slug=&quot;geopolitical&quot;&gt;geopolitical&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Geopolitical Related&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href=&quot;../ics-ot&quot; class=&quot;internal&quot; data-slug=&quot;ics-ot&quot;&gt;ics-ot&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Industrial Control System (ICS) and Operational Technology (OT)&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href=&quot;../mobile-attack&quot; class=&quot;internal&quot; data-slug=&quot;mobile-attack&quot;&gt;mobile-attack&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Mobile Attack&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href=&quot;../supply-chain&quot; class=&quot;internal&quot; data-slug=&quot;supply-chain&quot;&gt;supply-chain&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Supply Chain&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt; ]]></description>
    <pubDate>Thu, 29 Jan 2026 00:00:00 GMT</pubDate>
  </item><item>
    <title>2026-01-27 HoneyMyte updates CoolClient and deploys multiple stealers in recent campaigns</title>
    <link>https://rectifyq.com/MY-Threat-Landscape/threat-lists/033d1a45-804d-43ad-b916-a942ecf806fa</link>
    <guid>https://rectifyq.com/MY-Threat-Landscape/threat-lists/033d1a45-804d-43ad-b916-a942ecf806fa</guid>
    <description><![CDATA[ &lt;p&gt;📃Title: HoneyMyte updates CoolClient and deploys multiple stealers in recent campaigns&lt;br&gt;
📅Date: 2026-01-27&lt;br&gt;
🔗References:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://securelist.com/honeymyte-updates-coolclient-uses-browser-stealers-and-scripts/118664/&quot; class=&quot;external&quot;&gt;https://securelist.com/honeymyte-updates-coolclient-uses-browser-stealers-and-scripts/118664/&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;🔖Rectifyq Taxonomies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;relevancy: 🔴 Highly Relevant&lt;/li&gt;
&lt;li&gt;category: &lt;a href=&quot;../.././../tags/⚔Threat&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/⚔Threat&quot;&gt;⚔Threat&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;sub-category: &lt;a href=&quot;../.././../tags/malware-analysis&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/malware-analysis&quot;&gt;malware-analysis&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;target: &lt;a href=&quot;../.././../tags/broad-based&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/broad-based&quot;&gt;broad-based&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;MY-relevancy: &lt;a href=&quot;../.././../tags/relevant&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/relevant&quot;&gt;relevant&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;🔖MISP Galaxies:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;producer &lt;a href=&quot;../.././../tags/Kaspersky&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/Kaspersky&quot;&gt;Kaspersky&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;threat-actor &lt;a href=&quot;../.././../tags/MUSTANG-PANDA&quot; class=&quot;tag-link internal alias&quot; data-slug=&quot;tags/MUSTANG-PANDA&quot;&gt;MUSTANG-PANDA&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;sector=“Government, Administration”&lt;/li&gt;
&lt;li&gt;region=“035 - South-eastern Asia”&lt;/li&gt;
&lt;li&gt;target-information=“Malaysia”&lt;/li&gt;
&lt;li&gt;target-information=“Mongolia”&lt;/li&gt;
&lt;li&gt;target-information=“Myanmar”&lt;/li&gt;
&lt;li&gt;target-information=“Pakistan”&lt;/li&gt;
&lt;li&gt;target-information=“Russia”&lt;/li&gt;
&lt;li&gt;mitre-attack-pattern=[‘T1073’, ‘T1574.002’, ‘T1088’, ‘T1548.002’, ‘T1060’, ‘T1547.001’, ‘T1053.005’, ‘T1055’, ‘T1070’, ‘T1056.001’]&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;MISP event uuid: &lt;a href=&quot;https://mispmy.rectifyq.com/events/view/033d1a45-804d-43ad-b916-a942ecf806fa&quot; class=&quot;external&quot;&gt;033d1a45-804d-43ad-b916-a942ecf806fa&lt;svg aria-hidden=&quot;true&quot; class=&quot;external-icon&quot; style=&quot;max-width:0.8em;max-height:0.8em&quot; viewBox=&quot;0 0 512 512&quot;&gt;&lt;path d=&quot;M320 0H288V64h32 82.7L201.4 265.4 178.7 288 224 333.3l22.6-22.6L448 109.3V192v32h64V192 32 0H480 320zM32 32H0V64 480v32H32 456h32V480 352 320H424v32 96H64V96h96 32V32H160 32z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2 id=&quot;indicator-of-compromise-iocs&quot;&gt;Indicator of Compromise (IoCs)&lt;a role=&quot;anchor&quot; aria-hidden tabindex=&quot;-1&quot; data-no-popover href=&quot;#indicator-of-compromise-iocs&quot; class=&quot;internal&quot;&gt;&lt;svg width=&quot;18&quot; height=&quot;18&quot; viewBox=&quot;0 0 24 24&quot; fill=&quot;none&quot; stroke=&quot;currentColor&quot; stroke-width=&quot;2&quot; stroke-linecap=&quot;round&quot; stroke-linejoin=&quot;round&quot;&gt;&lt;path d=&quot;M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71&quot;&gt;&lt;/path&gt;&lt;path d=&quot;M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;pre&gt;&lt;code&gt;type,value,comment
md5, f518d8e5fe70d9090f6280c68a95998f, &#039;CoolClient - libngs.dll No sample in VT\r\nLast check:27/01/2026 No sample in VT\r\nLast check:28/01/2026&#039;
md5, 6b7300a8b3f4aac40eeecfd7bc47ee7c, &#039;CoolClient - time.dat No sample in VT\r\nLast check:27/01/2026 No sample in VT\r\nLast check:28/01/2026&#039;
md5, 7aa53ba3e3f8b0453ffcfba06347ab34, &#039;CoolClient plugins - ServiceMgrS.dll No sample in VT\r\nLast check:27/01/2026 No sample in VT\r\nLast check:28/01/2026&#039;
md5, a1cd59f769e9e5f6a040429847ca6eae, &#039;CoolClient plugins - FileMgrS.dll No sample in VT\r\nLast check:27/01/2026 No sample in VT\r\nLast check:28/01/2026&#039;
md5, 1bc5329969e6bf8ef2e9e49aab003f0b, &#039;CoolClient plugins - RemoteShellS.dll No sample in VT\r\nLast check:27/01/2026 No sample in VT\r\nLast check:28/01/2026&#039;
md5, 1a5a9c013ce1b65abc75d809a25d36a7, &#039;Browser login data stealer - Variant A No sample in VT\r\nLast check:27/01/2026 No sample in VT\r\nLast check:28/01/2026&#039;
md5, da6f89f15094fd3f74ba186954be6b05, &#039;Browser login data stealer - Variant C No sample in VT\r\nLast check:27/01/2026 No sample in VT\r\nLast check:28/01/2026&#039;
md5, c19bd9e6f649df1df385deef94e0e8c4, &#039;Scripts - 1.bat No sample in VT\r\nLast check:27/01/2026 No sample in VT\r\nLast check:28/01/2026&#039;
md5, 838b591722512368f81298c313e37412, &#039;Scripts - Ttraazcs32.ps1 No sample in VT\r\nLast check:27/01/2026 No sample in VT\r\nLast check:28/01/2026&#039;
md5, a4d7147f0b1ca737bfc133349841aaba, &#039;Scripts - t.ps1 No sample in VT\r\nLast check:27/01/2026 No sample in VT\r\nLast check:28/01/2026&#039;
hostname, account.hamsterxnxx.com, &#039;CoolClient C2&#039;
domain, popnike-share.com, &#039;CoolClient C2&#039;
hostname, japan.lenovoappstore.com, &#039;CoolClient C2&#039;
ip-dst, 113.23.212.15, &#039;FTP server&#039;

Full IOCs available in Rectifyq&#039;s MISP```
&lt;/code&gt;&lt;/pre&gt; ]]></description>
    <pubDate>Tue, 27 Jan 2026 00:00:00 GMT</pubDate>
  </item>
    </channel>
  </rss>