TL;DR
- 4 Ransomware & Breach Claims: New group Payload claimed a Malaysian hospitality organization, joining Nova, Qilin, Stormous, and The Gentlemen in targeting local entities across the public and private sectors.
- Infrastructure & Gov Incidents: NACSA issued critical advisories following the Health Ministry website compromise (Mushr00w), while a separate attack (MelayuSpiritual) disrupted Flexi Parking operations in Selangor.
- Active Regional Campaigns: MyCERT flagged active Android banking trojans, and researchers noted Malaysia-specific targeting by TA4922 and SharpPanda.
Ransomware & Breach Claims
A total of four ransomware claims targeting Malaysian organizations were tracked this month.
| Date | Threat Group | Claimed Victim | Reference |
|---|---|---|---|
| Jul 03 | krybit | Ma** Ho** Fur******* Sd* Bh* | Ransomware.live |
| Jul 07 | the gentlemen | Qua***** Log****** Sdn Bhd | Ransomware.live |
| Jul 17 | krybit | Pus** Reh********* PER**** | Ransomware.live |
| Jul 23 | Qilin | Sun*** Ber*** | Ransomware.live |
Incidents & Advisories
- FortiBleed Credential Compromise: Threat actors are leveraging credentials from prior compromises (FG-IR-26-060, FG-IR-25-647) and brute-forcing (
T1589.001,T1110) FortiGate devices lacking MFA. Unpatched or unverified FortiGates remain the primary ransomware affiliate front door. [Source] - Govt Agency Defacements: NACSA urged immediate patching following Health Ministry website compromises (
T1491,T1505.003,T1190) attributed to Mushr00w. [Source] - Logistics Disruption: Electronic payment operations for Flexi Parking in Selangor were severely degraded following a cyber attack (
T1491) by MelayuSpiritual, exposing user records. [Source]
Threat Intelligence & Research
Malaysia-Specific Targeting
- SharpPanda (Pelagos Intel): Artifact loaders were observed utilizing localized political/policy lures, indicating direct context for Malaysia-focused analysis. [Read]
- Android Banking Trojans (MyCERT): Multi-variant malware campaigns (Delivery4U / KerjaExpress / MaxTag) are actively targeting Malaysian online banking users. [Advisory]
- Phantom Casino (Syntx): Local gambling operators successfully hijacked Malaysian government web domains to construct SEO-driven casino funnels. [Read]
- Travel Phishing Surge (Check Point): Cybercriminals are exploiting travel spikes by creating spoofed “presale price” deal sites for Malaysian resorts to steal deposits. [Read]
Global Campaigns with Local Impact
- TA4922 Expansion (Proofpoint): The suspected Chinese crime group continues to scale operations, heavily prioritizing Malaysia alongside Taiwan, Japan, and Singapore. [Read]
- Havoc Stager via MS Defender (LevelBlue): A stager DLL bypassing Microsoft Defender DLP was discovered operating on Malaysia-registered infrastructure. [Read]
- Legacy WinRAR Flaws (Trend Micro): Attacks against Ukrainian entities were traced back to command servers hosted on a Malaysian VPS provider (Evoxt, AS149440). [Read]
- AryStinger Botnet (Qianxin): Over 4,000 legacy routers have been co-opted globally, with 3.5% of the compromised nodes located in Malaysia. [Read]
- Claude.ai Malvertising (Trend Micro): Abused shared chat features in Google Ads heavily targeted traffic in Malaysia, Taiwan, and Japan. [Read]
- WhatsApp VBS Campaigns (Kaspersky): Malicious VBS scripts distributed via WhatsApp are broadly affecting users in Malaysia and other regions. [Read]
- Maritime Sanctions Evasion (Recorded Future): Cyber-tracking exposed a bulk carrier detained in Port Kelang under the Tokyo MOU. [Read]
Community Events 📅
Wrapped (July 2026)
- [Jul 04 – 05] Cyber Skills Level Up! (CLSU) — Free student event at UTP by RE:HACK and CYBERHAX UTP.
- [Jul 04] Day In the Life of an Incident Responder — Session organized by APU FSECSS.
- [Jul 04] Malware Analysis and Reverse Engineering — Practical, hands-on evening course by Valere Labs.
- [Jul 07 – 09] NACSA Cyber Security Summit (NCSS) — National summit co-organized by NACSA and AIS.
- [Jul 18] The Amazing CyberConnect Forum — Interactive forum by UTAR FICT and Kampar Cybersecurity Club.
- [Jul 29 - 30] ISA Malaysia Section – Digital & OT Cybersecurity Forum 2026 — Conference on OT Security.
Upcoming (August – September 2026)
- [Aug 01 – 02] Red Teaming L1 Workshop — Practical internal network and AD attack labs. [Register]
- [Aug 12] MYCyber Leaders Summit 2026 — Summit for Cybersecurity leaders. [Register]
- [Sep 06] SUNCTF 2026 — Sunway University SunCTF2026 [Register]
- [Sep 10] Cyber Security Summit (Exito) — Summit for Cybersecurity leaders. [Register]
- [Sep 22-24] Parallel Pulse Training 2026 — Cybersecurity technical trainings. [Register]
timeline title June 2026 at a glance Week 1 : Payload claims hospitality entity (Jun 8) : LIGA CTF goes online Week 2 : Threat group claims by The Gentlemen & Stormous : SherpaSec Meetup @ UNITEN Week 3 : Ransomware claims by Nova, Qilin & The Gentlemen : NACSA alerts on Health Ministry compromise Week 4 : Flexi Parking cyber attack disrupts Selangor