TL;DR

  • 7 Ransomware & Breach Claims: New group Payload claimed a Malaysian hospitality organization, joining Nova, Qilin, Stormous, and The Gentlemen in targeting local entities across the public and private sectors.
  • Infrastructure & Gov Incidents: NACSA issued critical advisories following the Health Ministry website compromise (Mushr00w), while a separate attack (MelayuSpiritual) disrupted Flexi Parking operations in Selangor.
  • Active Regional Campaigns: MyCERT flagged active Android banking trojans, and researchers noted Malaysia-specific targeting by TA4922 and SharpPanda.

Ransomware & Breach Claims

A total of seven ransomware claims targeting Malaysian organizations were tracked this month. Qilin’s global surge continues to keep regional pressure high, alongside emerging brands testing local waters.

DateThreat GroupClaimed VictimReference
Jun 08PayloadVil*** Hot*** in Att*********Ransomware.live
Jun 11the gentlemenUiT* Hol*****Ransomware.live
Jun 12Stormousmli********Ransomware.live
Jun 13Payloadmyi*********Ransomware.live
Jun 16novaKed**Ransomware.live
Jun 18QilinTHL PRO**** MAN******* SDN* BHD*Ransomware.live
Jun 20the gentlemenSGS Mal*****Ransomware.live

Incidents & Advisories

  • FortiBleed Credential Compromise: Threat actors are leveraging credentials from prior compromises (FG-IR-26-060, FG-IR-25-647) and brute-forcing (T1589.001, T1110) FortiGate devices lacking MFA. Unpatched or unverified FortiGates remain the primary ransomware affiliate front door. [Source]
  • Govt Agency Defacements: NACSA urged immediate patching following Health Ministry website compromises (T1491, T1505.003, T1190) attributed to Mushr00w. [Source]
  • Logistics Disruption: Electronic payment operations for Flexi Parking in Selangor were severely degraded following a cyber attack (T1491) by MelayuSpiritual, exposing user records. [Source]

Threat Intelligence & Research

Malaysia-Specific Targeting

  • SharpPanda (Pelagos Intel): Artifact loaders were observed utilizing localized political/policy lures, indicating direct context for Malaysia-focused analysis. [Read]
  • Android Banking Trojans (MyCERT): Multi-variant malware campaigns (Delivery4U / KerjaExpress / MaxTag) are actively targeting Malaysian online banking users. [Advisory]
  • Phantom Casino (Syntx): Local gambling operators successfully hijacked Malaysian government web domains to construct SEO-driven casino funnels. [Read]
  • Travel Phishing Surge (Check Point): Cybercriminals are exploiting travel spikes by creating spoofed “presale price” deal sites for Malaysian resorts to steal deposits. [Read]

Global Campaigns with Local Impact

  • TA4922 Expansion (Proofpoint): The suspected Chinese crime group continues to scale operations, heavily prioritizing Malaysia alongside Taiwan, Japan, and Singapore. [Read]
  • Havoc Stager via MS Defender (LevelBlue): A stager DLL bypassing Microsoft Defender DLP was discovered operating on Malaysia-registered infrastructure. [Read]
  • Legacy WinRAR Flaws (Trend Micro): Attacks against Ukrainian entities were traced back to command servers hosted on a Malaysian VPS provider (Evoxt, AS149440). [Read]
  • AryStinger Botnet (Qianxin): Over 4,000 legacy routers have been co-opted globally, with 3.5% of the compromised nodes located in Malaysia. [Read]
  • Claude.ai Malvertising (Trend Micro): Abused shared chat features in Google Ads heavily targeted traffic in Malaysia, Taiwan, and Japan. [Read]
  • WhatsApp VBS Campaigns (Kaspersky): Malicious VBS scripts distributed via WhatsApp are broadly affecting users in Malaysia and other regions. [Read]
  • Maritime Sanctions Evasion (Recorded Future): Cyber-tracking exposed a bulk carrier detained in Port Kelang under the Tokyo MOU. [Read]

Community Events 📅

Wrapped (June 2026)

  • LIGA CTF 2026 — Online CTF (Ongoing)
  • HackNyx CTF 2026 — Student-focused CTF organized by GMI CYSEC
  • From Risk To Resilience — Security scaling talk hosted by UiTM FSKM
  • SherpaSec June Meetup — Hosted at UNITEN; featured CTF reviews and Hacker Jeopardy

Upcoming (July – August 2026)

  • [Jul 04 – 05] Cyber Skills Level Up! (CLSU) — Free student event at UTP by RE:HACK and CYBERHAX UTP. [Register]
  • [Jul 04] Day In the Life of an Incident Responder — Session organized by APU FSECSS. [Register]
  • [Jul 04] Malware Analysis and Reverse Engineering — Practical, hands-on evening course by Valere Labs. [Info]
  • [Jul 07 – 09] NACSA Cyber Security Summit (NCSS) — National summit co-organized by NACSA and AIS. [Info]
  • [Jul 18] The Amazing CyberConnect Forum — Interactive forum by UTAR FICT and Kampar Cybersecurity Club. [Info]
  • [Aug 01 – 02] Red Teaming L1 Workshop — Practical internal network and AD attack labs. [Register]

timeline
    title June 2026 at a glance
    Week 1 : Payload claims hospitality entity (Jun 8)
           : LIGA CTF goes online
    Week 2 : Threat group claims by The Gentlemen & Stormous
           : SherpaSec Meetup @ UNITEN
    Week 3 : Ransomware claims by Nova, Qilin & The Gentlemen
           : NACSA alerts on Health Ministry compromise
    Week 4 : Flexi Parking cyber attack disrupts Selangor