TL;DR

  • 4 Ransomware & Breach Claims: New group Payload claimed a Malaysian hospitality organization, joining Nova, Qilin, Stormous, and The Gentlemen in targeting local entities across the public and private sectors.
  • Infrastructure & Gov Incidents: NACSA issued critical advisories following the Health Ministry website compromise (Mushr00w), while a separate attack (MelayuSpiritual) disrupted Flexi Parking operations in Selangor.
  • Active Regional Campaigns: MyCERT flagged active Android banking trojans, and researchers noted Malaysia-specific targeting by TA4922 and SharpPanda.

Ransomware & Breach Claims

A total of four ransomware claims targeting Malaysian organizations were tracked this month.

DateThreat GroupClaimed VictimReference
Jul 03krybitMa** Ho** Fur******* Sd* Bh*Ransomware.live
Jul 07the gentlemenQua***** Log****** Sdn BhdRansomware.live
Jul 17krybitPus** Reh********* PER****Ransomware.live
Jul 23QilinSun*** Ber***Ransomware.live

Incidents & Advisories

  • FortiBleed Credential Compromise: Threat actors are leveraging credentials from prior compromises (FG-IR-26-060, FG-IR-25-647) and brute-forcing (T1589.001, T1110) FortiGate devices lacking MFA. Unpatched or unverified FortiGates remain the primary ransomware affiliate front door. [Source]
  • Govt Agency Defacements: NACSA urged immediate patching following Health Ministry website compromises (T1491, T1505.003, T1190) attributed to Mushr00w. [Source]
  • Logistics Disruption: Electronic payment operations for Flexi Parking in Selangor were severely degraded following a cyber attack (T1491) by MelayuSpiritual, exposing user records. [Source]

Threat Intelligence & Research

Malaysia-Specific Targeting

  • SharpPanda (Pelagos Intel): Artifact loaders were observed utilizing localized political/policy lures, indicating direct context for Malaysia-focused analysis. [Read]
  • Android Banking Trojans (MyCERT): Multi-variant malware campaigns (Delivery4U / KerjaExpress / MaxTag) are actively targeting Malaysian online banking users. [Advisory]
  • Phantom Casino (Syntx): Local gambling operators successfully hijacked Malaysian government web domains to construct SEO-driven casino funnels. [Read]
  • Travel Phishing Surge (Check Point): Cybercriminals are exploiting travel spikes by creating spoofed “presale price” deal sites for Malaysian resorts to steal deposits. [Read]

Global Campaigns with Local Impact

  • TA4922 Expansion (Proofpoint): The suspected Chinese crime group continues to scale operations, heavily prioritizing Malaysia alongside Taiwan, Japan, and Singapore. [Read]
  • Havoc Stager via MS Defender (LevelBlue): A stager DLL bypassing Microsoft Defender DLP was discovered operating on Malaysia-registered infrastructure. [Read]
  • Legacy WinRAR Flaws (Trend Micro): Attacks against Ukrainian entities were traced back to command servers hosted on a Malaysian VPS provider (Evoxt, AS149440). [Read]
  • AryStinger Botnet (Qianxin): Over 4,000 legacy routers have been co-opted globally, with 3.5% of the compromised nodes located in Malaysia. [Read]
  • Claude.ai Malvertising (Trend Micro): Abused shared chat features in Google Ads heavily targeted traffic in Malaysia, Taiwan, and Japan. [Read]
  • WhatsApp VBS Campaigns (Kaspersky): Malicious VBS scripts distributed via WhatsApp are broadly affecting users in Malaysia and other regions. [Read]
  • Maritime Sanctions Evasion (Recorded Future): Cyber-tracking exposed a bulk carrier detained in Port Kelang under the Tokyo MOU. [Read]

Community Events 📅

Wrapped (July 2026)

  • [Jul 04 – 05] Cyber Skills Level Up! (CLSU) — Free student event at UTP by RE:HACK and CYBERHAX UTP.
  • [Jul 04] Day In the Life of an Incident Responder — Session organized by APU FSECSS.
  • [Jul 04] Malware Analysis and Reverse Engineering — Practical, hands-on evening course by Valere Labs.
  • [Jul 07 – 09] NACSA Cyber Security Summit (NCSS) — National summit co-organized by NACSA and AIS.
  • [Jul 18] The Amazing CyberConnect Forum — Interactive forum by UTAR FICT and Kampar Cybersecurity Club.
  • [Jul 29 - 30] ISA Malaysia Section – Digital & OT Cybersecurity Forum 2026 — Conference on OT Security.

Upcoming (August – September 2026)

  • [Aug 01 – 02] Red Teaming L1 Workshop — Practical internal network and AD attack labs. [Register]
  • [Aug 12] MYCyber Leaders Summit 2026 — Summit for Cybersecurity leaders. [Register]
  • [Sep 06] SUNCTF 2026 — Sunway University SunCTF2026 [Register]
  • [Sep 10] Cyber Security Summit (Exito) — Summit for Cybersecurity leaders. [Register]
  • [Sep 22-24] Parallel Pulse Training 2026 — Cybersecurity technical trainings. [Register]

timeline
    title June 2026 at a glance
    Week 1 : Payload claims hospitality entity (Jun 8)
           : LIGA CTF goes online
    Week 2 : Threat group claims by The Gentlemen & Stormous
           : SherpaSec Meetup @ UNITEN
    Week 3 : Ransomware claims by Nova, Qilin & The Gentlemen
           : NACSA alerts on Health Ministry compromise
    Week 4 : Flexi Parking cyber attack disrupts Selangor