Rectifyq Cybersecurity News ๐Ÿ‡ฒ๐Ÿ‡พ
172 subscribers
2 files
1.92K links
rectifyq.com
Rectifyq Cybersecurity News with approximate relevancy to Malaysia and contextualized using MISP Galaxies.

Relevancy
๐Ÿ”ด- e.g. APT target ๐Ÿ‡ฒ๐Ÿ‡พ.
๐ŸŸก- e.g. APT target Asian country.
๐Ÿ”ต- e.g. Infostealers impact globally.
โšซ- Good to know only.
Download Telegram
๐Ÿ“ƒTitle: [Ransomware] Unconfirmed: Sha******** Met***
๐Ÿ“…Date: 2026-05-29
๐Ÿ”—References: https://www.ransomware.live/id/U2hhbnBvb3JuYW0gTWV0YWxzQGxhbWFzaHR1

๐Ÿ”–Rectifyq Taxonomies:
Relevancy: ๐Ÿ”ด Highly Relevant
Category: ๐Ÿ’ฅ Data Breach
- TA-category="Ransomware"

๐Ÿ”–MISP Galaxies:
- target-information="Malaysia"
- sector="Manufacturing"
- ransomware="lamashtu"
mitre-attack-pattern=[]

MISP event uuid: f2f56dd8-e0fe-45c7-9e83-de9237df5602
Rectifyq Cybersecurity News ๐Ÿ‡ฒ๐Ÿ‡พ pinned ยซ๐Ÿ“ƒTitle: [Ransomware] Unconfirmed: Sha******** Met*** ๐Ÿ“…Date: 2026-05-29 ๐Ÿ”—References: https://www.ransomware.live/id/U2hhbnBvb3JuYW0gTWV0YWxzQGxhbWFzaHR1 ๐Ÿ”–Rectifyq Taxonomies: Relevancy: ๐Ÿ”ด Highly Relevant Category: ๐Ÿ’ฅ Data Breach - TA-category="Ransomware"โ€ฆยป
๐Ÿ“ƒTitle: New burrowing techniques
๐Ÿ“…Date: 2026-05-20
๐Ÿ”—References:
https://www.welivesecurity.com/en/eset-research/webworm-new-burrowing-techniques/

๐Ÿ”–Rectifyq Taxonomies:
Relevancy: ๐Ÿ”ต Potentially Relevant
Category: โš” Threat
โ€ข mitre-att&ck="from-original-src"
โ€ข sub-category="TA-profile"
โ€ข sub-category="campaign-analysis"
โ€ข target="broad-based"
โ€ข TA-category="APT"
โ€ข samples-found-in="MalwareBazaar"
โ€ข samples-found-in="Tria.ge"
โ€ข action-taken="VT-comment"

๐Ÿ”–MISP Galaxies:
โ€ข producer="ESET"
โ€ข target-information="Belgium"
โ€ข target-information="Czech Republic"
โ€ข target-information="Hungary"
โ€ข target-information="Italy"
โ€ข target-information="Nigeria"
โ€ข target-information="Poland"
โ€ข target-information="Serbia"
โ€ข target-information="South Africa"
โ€ข target-information="Spain"
โ€ข threat-actor="Webworm"
โ€ข online-service="7347d685-8e08-4ed9-9f34-264e5e4b567a"
โ€ข online-service="3b16bb5a-eb4f-4603-a909-bebc5df4a46d"
mitre-attack-pattern=['T1550.001', 'T1573.002', 'T1102.002', 'T1078.004', 'T1021.007', 'T1005', 'T1027.013', 'T1041', 'T1567.002', 'T1090.002', 'T1070.004', 'T1090.001', 'T1074.001', 'T1112', 'T1090.003', 'T1547.001', 'T1074.002', 'T1053.005', 'T1583.004', 'T1132.001', 'T1070.006', 'T1608.002', 'T1583.003', 'T1588.006', 'T1595.002', 'T1071.001', 'T1584.006', 'T1059.003', 'T1595.003']

MISP event uuid: 55a58703-da62-4330-bd76-3189d2635e28
๐Ÿ“ƒTitle: PureLogs: Delivery via PawsRunner Steganography
๐Ÿ“…Date: 2026-05-15
๐Ÿ”—References:
https://www.fortinet.com/blog/threat-research/purelogs-delivery-via-pawsrunner-steganography

๐Ÿ”–Rectifyq Taxonomies:
Relevancy: ๐Ÿ”ต Potentially Relevant
Category: โš” Threat
โ€ข mitre-att&ck="none-from-src"
โ€ข sub-category="campaign-analysis"
โ€ข target="broad-based"
โ€ข no-samples-in="MalwareBazaar"
โ€ข no-samples-in="Tria.ge"
โ€ข action-taken="VT-comment"

๐Ÿ”–MISP Galaxies:
โ€ข producer="Fortinet"
โ€ข malpedia="PureLogs Stealer"
mitre-attack-pattern=[]

MISP event uuid: 3c80a5eb-e55b-46df-87f5-aa09ba9bb5d2
๐Ÿ“ƒTitle: The Worm That Keeps on Digging: Latest Wave
๐Ÿ“…Date: 2026-05-19
๐Ÿ”—References:
https://www.wiz.io/blog/mini-shai-hulud-teampcp-hits-antv-supply-chain

๐Ÿ”–Rectifyq Taxonomies:
Relevancy: ๐Ÿ”ต Potentially Relevant
Category: โš” Threat
โ€ข mitre-att&ck="none-from-src"
โ€ข mitre-att&ck="from-OTX"
โ€ข sub-category="campaign-analysis"
โ€ข topic="supply-chain"
โ€ข target="broad-based"
โ€ข samples-found-in="MalwareBazaar"
โ€ข samples-found-in="Tria.ge"
โ€ข action-taken="VT-comment"

๐Ÿ”–MISP Galaxies:
โ€ข producer="Wiz Blog"
โ€ข malpedia="Shai-Hulud"
โ€ข online-service="3b16bb5a-eb4f-4603-a909-bebc5df4a46d"
mitre-attack-pattern=['T1059.007', 'T1539', 'T1555.003', 'T1552.004', 'T1552.001', 'T1567.001', 'T1552.006', 'T1102.003', 'T1574.010', 'T1195.002', 'T1102.002', 'T1059.006', 'T1543.001', 'T1071.001', 'T1543.002', 'T1105', 'T1102.001']

MISP event uuid: a8121f4e-198f-47f3-a649-0b881e64d745
๐Ÿ“ƒTitle: Fresh mischief and digital shenanigans
๐Ÿ“…Date: 2026-05-14
๐Ÿ”—References:
https://www.welivesecurity.com/en/eset-research/frostyneighbor-fresh-mischief-digital-shenanigans/

๐Ÿ”–Rectifyq Taxonomies:
Relevancy: โšซ Not Relevant
Category: โš” Threat
โ€ข mitre-att&ck="from-original-src"
โ€ข mitre-att&ck="from-OTX"
โ€ข sub-category="campaign-analysis"
โ€ข TA-category="APT"
โ€ข target="broad-based"
โ€ข samples-found-in="MalwareBazaar"
โ€ข samples-found-in="Tria.ge"
โ€ข action-taken="VT-comment"

๐Ÿ”–MISP Galaxies:
โ€ข producer="ESET"
โ€ข target-information="Lithuania"
โ€ข target-information="Poland"
โ€ข target-information="Ukraine"
โ€ข threat-actor="FrostyNeighbor"
โ€ข region="151 - Eastern Europe"
โ€ข sector="Government, Administration"
โ€ข sector="Military"
โ€ข malpedia="Cobalt Strike"
โ€ข malpedia="PicassoLoader"
mitre-attack-pattern=['T1053.005', 'T1583', 'T1036.005', 'T1204.002', 'T1566.001', 'T1082', 'T1059', 'T1608', 'T1057', 'T1041', 'T1060', 'T1588.002', 'T1027', 'T1071.001', 'T1027.009']

MISP event uuid: 62c6b987-cf0c-4a4b-9c57-a5a107789688
๐Ÿ“ƒTitle: Ghost CMS Mass Compromised via CVE-2026-26980, Now Fueling ClickFix Attacks
๐Ÿ“…Date: 2026-05-21
๐Ÿ”—References:
https://blog.xlab.qianxin.com/ghost-cms-mass-compromised-via-cve-2026-26980-now-fueling-clickfix-attacks/

๐Ÿ”–Rectifyq Taxonomies:
Relevancy: ๐Ÿ”ต Potentially Relevant
Category: โš” Threat
โ€ข mitre-att&ck="none-from-src"
โ€ข mitre-att&ck="from-OTX"
โ€ข sub-category="intrusion-analysis"
โ€ข sub-category="critical-vuln"
โ€ข sub-category="campaign-analysis"
โ€ข target="broad-based"
โ€ข samples-found-in="MalwareBazaar"
โ€ข samples-found-in="Tria.ge"
โ€ข action-taken="VT-comment"

๐Ÿ”–MISP Galaxies:
mitre-attack-pattern=['T1218.011', 'T1132.001', 'T1059.007', 'T1140', 'T1190', 'T1583.001', 'T1055', 'T1102', 'T1583.006', 'T1204', 'T1059.001', 'T1212', 'T1547.001', 'T1566', 'T1027', 'T1573', 'T1059.003', 'T1071.001', 'T1105']

MISP event uuid: 63a2d681-adb1-4ca3-a1ae-f2d332ea8de5
๐Ÿ“ƒTitle: SEO poisoning campaign leverages Gemini and Claude Code impersonation to deliver infostealer
๐Ÿ“…Date: 2026-05-21
๐Ÿ”—References:
https://blog.eclecticiq.com/seo-poisoning-campaign-leverages-gemini-and-claude-code-impersonation-to-deliver-infostealer

๐Ÿ”–Rectifyq Taxonomies:
Relevancy: ๐Ÿ”ต Potentially Relevant
Category: โš” Threat
โ€ข mitre-att&ck="from-original-src"
โ€ข sub-category="campaign-analysis"
โ€ข topic="ai"
โ€ข target="broad-based"
โ€ข samples-found-in="MalwareBazaar"
โ€ข samples-found-in="Tria.ge"
โ€ข action-taken="VT-comment"

๐Ÿ”–MISP Galaxies:
โ€ข producer="EclecticIQ"
โ€ข target-information="United States"
โ€ข target-information="United Kingdom"
mitre-attack-pattern=['T1552.001', 'T1555.003', 'T1552.002', 'T1005', 'T1140', 'T1562.001', 'T1189', 'T1573', 'T1041', 'T1083', 'T1562.006', 'T1105', 'T1204.002', 'T1204.001', 'T1027', 'T1059.001', 'T1057', 'T1608.006', 'T1539', 'T1218', 'T1497.001', 'T1071.001', 'T1555.004']

MISP event uuid: 6c37649e-5ce2-4c1b-8fb0-c90e251a93a2
๐Ÿ“ƒTitle: Politicians to Ditch Signal for Homegrown Apps
๐Ÿ“…Date: 2026-05-21
๐Ÿ”—References:
https://news.risky.biz/srsly-risky-biz-politicians-to-ditch-signal-for-homegrown-apps/

๐Ÿ”–Rectifyq Taxonomies:
Relevancy: ๐Ÿ”ต Potentially Relevant
Category: โš” Threat
โ€ข mitre-att&ck="none-from-src"
โ€ข mitre-att&ck="from-OTX"
โ€ข sub-category="report"
โ€ข target="broad-based"
โ€ข no-samples-in="MalwareBazaar"
โ€ข no-samples-in="Tria.ge"
โ€ข action-taken="VT-comment"

๐Ÿ”–MISP Galaxies:
โ€ข target-information="United States"
โ€ข target-information="Belgium"
โ€ข target-information="France"
โ€ข target-information="Germany"
โ€ข target-information="Poland"
โ€ข target-information="United Kingdom"
mitre-attack-pattern=['T1557', 'T1539', 'T1114', 'T1530', 'T1552', 'T1185', 'T1534', 'T1566', 'T1056', 'T1213']

MISP event uuid: 73a9fa17-bb23-41c0-90a6-f3aa48fc2617
๐Ÿ“ƒTitle: Misconfigured, Enrolled and Dormant: Anatomy of a P2Pinfect Kubernetes Compromise
๐Ÿ“…Date: 2026-05-20
๐Ÿ”—References:
https://www.fortinet.com/blog/threat-research/misconfigured-enrolled-and-dormant-anatomy-of-a-p2pinfect-kubernetes-compromise

๐Ÿ”–Rectifyq Taxonomies:
Relevancy: ๐Ÿ”ต Potentially Relevant
Category: โš” Threat
โ€ข workflow="enrichment"
โ€ข mitre-att&ck="none-from-src"
โ€ข mitre-att&ck="from-OTX"
โ€ข sub-category="intrusion-analysis"
โ€ข topic="cloud"
โ€ข target="targeted"
โ€ข samples-found-in="MalwareBazaar"
โ€ข samples-found-in="Tria.ge"

๐Ÿ”–MISP Galaxies:
โ€ข producer="Fortinet"
โ€ข branded-vulnerability="b2c5ca09-8d99-4138-ace7-99615894ab71"
mitre-attack-pattern=['T1110.001', 'T1133', 'T1071.004', 'T1053', 'T1190', 'T1036', 'T1563', 'T1070', 'T1552.001', 'T1098', 'T1059.004', 'T1571', 'T1027', 'T1486', 'T1573', 'T1496', 'T1027.002', 'T1071.001', 'T1105', 'T1090.001']

MISP event uuid: 6e45460a-4428-4eb4-865e-3a5a170b8b01
๐Ÿ“ƒTitle: Mini Shai Hulud: Compromised @antv npm packages enable CI/CD credential theft
๐Ÿ“…Date: 2026-05-20
๐Ÿ”—References:
https://www.microsoft.com/en-us/security/blog/2026/05/20/mini-shai-hulud-compromised-antv-npm-packages-enable-ci-cd-credential-theft/

๐Ÿ”–Rectifyq Taxonomies:
Relevancy: ๐Ÿ”ต Potentially Relevant
Category: โš” Threat
โ€ข mitre-att&ck="none-from-src"
โ€ข mitre-att&ck="from-OTX"
โ€ข sub-category="campaign-analysis"
โ€ข topic="supply-chain"
โ€ข target="broad-based"
โ€ข samples-found-in="MalwareBazaar"
โ€ข samples-found-in="Tria.ge"
โ€ข action-taken="VT-comment"

๐Ÿ”–MISP Galaxies:
โ€ข producer="Microsoft"
โ€ข malpedia="Shai-Hulud"
mitre-attack-pattern=['T1132.001', 'T1059.007', 'T1548.003', 'T1069.003', 'T1195.001', 'T1036.005', 'T1140', 'T1552.004', 'T1562.006', 'T1552.001', 'T1098.001', 'T1087.004', 'T1098', 'T1068', 'T1027', 'T1195.002', 'T1567.002', 'T1071.001', 'T1105', 'T1078.004']

MISP event uuid: ce69c87f-4292-4c48-9907-0aea83122aed
๐Ÿ“ƒTitle: Operation Dragon Whistle: UNG002 Targets Chinese Academia via Weaponized Institutional Lure
๐Ÿ“…Date: 2026-05-20
๐Ÿ”—References:
https://www.seqrite.com/blog/operation-dragon-whistle-ung002-targets-chinese-academia-via-weaponized-institutional-lure/

๐Ÿ”–Rectifyq Taxonomies:
Relevancy: โšซ Not Relevant
Category: โš” Threat
โ€ข mitre-att&ck="from-original-src"
โ€ข mitre-att&ck="from-OTX"
โ€ข sub-category="intrusion-analysis"
โ€ข target="targeted"
โ€ข no-samples-in="MalwareBazaar"
โ€ข samples-found-in="Tria.ge"
โ€ข action-taken="VT-comment"

๐Ÿ”–MISP Galaxies:
โ€ข producer="Seqrite"
โ€ข target-information="China"
โ€ข malpedia="Cobalt Strike"
mitre-attack-pattern=['T1574.002', 'T1005', 'T1622', 'T1564.001', 'T1105', 'T1204.002', 'T1036', 'T1106', 'T1027', 'T1057', 'T1620', 'T1129', 'T1566.001', 'T1218', 'T1497.001', 'T1497', 'T1059.005', 'T1071.001']

MISP event uuid: 271f7352-0846-4ffc-9841-b0e792521cbc
๐Ÿ“ƒTitle: Premium Deception: Uncovering a Global Android Carrier Billing Fraud Campaign
๐Ÿ“…Date: 2026-05-20
๐Ÿ”—References:
https://zimperium.com/blog/premium-deception-uncovering-a-global-android-carrier-billing-fraud-campaign

๐Ÿ”–Rectifyq Taxonomies:
Relevancy: ๐Ÿ”ด Highly Relevant
Category: โš” Threat
โ€ข sub-category="campaign-analysis"
โ€ข topic="mobile-attack"
โ€ข target="broad-based"
โ€ข mitre-att&ck="from-original-src"
โ€ข no-samples-in="MalwareBazaar"
โ€ข samples-found-in="Tria.ge"
โ€ข action-taken="x"
โ€ข action-taken="linkedin"

๐Ÿ”–MISP Galaxies:
โ€ข target-information="Croatia"
โ€ข target-information="Malaysia"
โ€ข target-information="Romania"
โ€ข target-information="Thailand"
โ€ข producer="Zimperium"
โ€ข online-service="b0c71d51-34fd-47b5-9eb4-dd406ffc607f"
mitre-attack-pattern=['T1412', 'T1476', 'T1646', 'T1643', 'T1417', 'T1582', 'T1603', 'T1628.001', 'T1426', 'T1422', 'T1437.001']

MISP event uuid: 441a0a60-4abf-4afc-8318-eee24dbf5b68
๐Ÿ“ƒTitle: Tracking TamperedChef Clusters via Certificate and Code Reuse
๐Ÿ“…Date: 2026-05-20
๐Ÿ”—References:
https://unit42.paloaltonetworks.com/tracking-tampered-chef-clusters/

๐Ÿ”–Rectifyq Taxonomies:
Relevancy: ๐Ÿ”ต Potentially Relevant
Category: โš” Threat
โ€ข mitre-att&ck="none-from-src"
โ€ข mitre-att&ck="from-OTX"
โ€ข sub-category="campaign-analysis"
โ€ข target="broad-based"
โ€ข no-samples-in="MalwareBazaar"
โ€ข no-samples-in="Tria.ge"
โ€ข action-taken="VT-comment"

๐Ÿ”–MISP Galaxies:
โ€ข producer="Palo Alto"
โ€ข malpedia="TamperedChef"
โ€ข target-information="Israel"
โ€ข target-information="United States"
mitre-attack-pattern=['T1053.005', 'T1113', 'T1033', 'T1539', 'T1204.002', 'T1566.002', 'T1553.002', 'T1082', 'T1140', 'T1555.003', 'T1016', 'T1083', 'T1102', 'T1057', 'T1547.001', 'T1027', 'T1518.001', 'T1027.002', 'T1071.001', 'T1105', 'T1124']

MISP event uuid: 5bc9258d-74d3-4847-aa11-ec0c8b67e156
๐Ÿ“ƒTitle: Volume Obfuscation Game: The Lead Data Brokers Out To Waste Your Time
๐Ÿ“…Date: 2026-05-20
๐Ÿ”—References:
https://www.group-ib.com/blog/lead-data-obfuscation-brokers/

๐Ÿ”–Rectifyq Taxonomies:
Relevancy: ๐Ÿ”ต Potentially Relevant
Category: โš” Threat
โ€ข mitre-att&ck="none-from-src"
โ€ข mitre-att&ck="from-OTX"
โ€ข sub-category="campaign-analysis"
โ€ข target="broad-based"
โ€ข no-samples-in="MalwareBazaar"
โ€ข no-samples-in="Tria.ge"
โ€ข action-taken="VT-comment"

๐Ÿ”–MISP Galaxies:
โ€ข producer="Group-IB"
โ€ข country="china"
โ€ข online-service="b0c71d51-34fd-47b5-9eb4-dd406ffc607f"
mitre-attack-pattern=[]

MISP event uuid: a2f1ae5e-505c-4075-a3d6-991e1637c63c
๐Ÿ“ƒTitle: Beyond Tax Returns: How Shared Malware Infrastructure Scales Brand Abuse In Indonesia
๐Ÿ“…Date: 2026-05-19
๐Ÿ”—References:
https://www.group-ib.com/blog/indonesia-tax-impersonation-goldfactory-malware/

๐Ÿ”–Rectifyq Taxonomies:
Relevancy: โšซ Not Relevant
Category: โš” Threat
โ€ข mitre-att&ck="from-original-src"
โ€ข mitre-att&ck="from-OTX"
โ€ข sub-category="campaign-analysis"
โ€ข TA-category="Cybercrime"
โ€ข target="broad-based"
โ€ข topic="mobile-attack"
โ€ข no-samples-in="MalwareBazaar"
โ€ข no-samples-in="Tria.ge"
โ€ข action-taken="VT-comment"

๐Ÿ”–MISP Galaxies:
โ€ข producer="Group-IB"
โ€ข target-information="Indonesia"
โ€ข target-information="Peru"
โ€ข target-information="Philippines"
โ€ข target-information="South Africa"
โ€ข target-information="Thailand"
โ€ข malpedia="Gigabud"
โ€ข sector="Bank"
โ€ข sector="Finance"
โ€ข sector="Government, Administration"
โ€ข malpedia="GoldDigger"
โ€ข malpedia="Remo"
โ€ข threat-actor="GoldFactory"
mitre-attack-pattern=['T1414', 'T1646', 'T1541', 'T1417.002', 'T1516', 'T1417.001', 'T1660', 'T1513', 'T1426', 'T1437.001', 'T1626', 'T1417', 'T1418', 'T1422']

MISP event uuid: 88e3ed61-0d4d-462b-9c4c-2298d7d7b9c3
๐Ÿ“ƒTitle: Popular node-ipc npm Package Infected with Credential Stealer
๐Ÿ“…Date: 2026-05-14
๐Ÿ”—References:
https://socket.dev/blog/node-ipc-package-compromised

๐Ÿ”–Rectifyq Taxonomies:
Relevancy: ๐Ÿ”ต Potentially Relevant
Category: โš” Threat
โ€ข mitre-att&ck="none-from-src"
โ€ข mitre-att&ck="from-OTX"
โ€ข sub-category="campaign-analysis"
โ€ข topic="supply-chain"
โ€ข target="broad-based"
โ€ข no-samples-in="MalwareBazaar"
โ€ข no-samples-in="Tria.ge"
โ€ข action-taken="VT-comment"

๐Ÿ”–MISP Galaxies:
โ€ข producer="37ebf9d7-5e9a-466f-a42c-6e60313db868"
mitre-attack-pattern=['T1195.002', 'T1078', 'T1136', 'T1098', 'T1071.004', 'T1048.003', 'T1041', 'T1567', 'T1005', 'T1552.001', 'T1552.004', 'T1087', 'T1082', 'T1083', 'T1119', 'T1074.001', 'T1560.001', 'T1027', 'T1027.002', 'T1059.007']

MISP event uuid: ba313d52-d178-491a-ab42-0a79bdd9755b
๐Ÿ“ƒTitle: Inside a Tor Backed Supply Chain Worm
๐Ÿ“…Date: 2026-05-14
๐Ÿ”—References:
https://www.cloudsek.com/blog/inside-a-tor-backed-supply-chain-worm

๐Ÿ”–Rectifyq Taxonomies:
Relevancy: ๐Ÿ”ต Potentially Relevant
Category: โš” Threat
โ€ข mitre-att&ck="none-from-src"
โ€ข mitre-att&ck="from-OTX"
โ€ข sub-category="campaign-analysis"
โ€ข topic="supply-chain"
โ€ข target="broad-based"
โ€ข no-samples-in="MalwareBazaar"
โ€ข no-samples-in="Tria.ge"
โ€ข action-taken="VT-comment"

๐Ÿ”–MISP Galaxies:
โ€ข producer="CloudSEK"
mitre-attack-pattern=['T1195.002', 'T1554', 'T1543.002', 'T1027', 'T1078.004', 'T1078.001', 'T1087.001', 'T1552.001', 'T1552.006', 'T1563', 'T1098', 'T1036.005', 'T1090.003', 'T1071.001', 'T1059.006', 'T1548.001', 'T1496', 'T1005', 'T1041']

MISP event uuid: 76c07ddc-0f70-481e-9f63-c99aef0650b6
๐Ÿ“ƒTitle: The Evolution of ClickFix: From Cleartext to Server Side Polymorphism
๐Ÿ“…Date: 2026-05-14
๐Ÿ”—References:
https://www.menlosecurity.com/blog/the-evolution-of-clickfix-from-cleartext-to-server-side-polymorphism

๐Ÿ”–Rectifyq Taxonomies:
Relevancy: ๐Ÿ”ต Potentially Relevant
Category: โš” Threat
โ€ข workflow="enrichment"
โ€ข mitre-att&ck="none-from-src"
โ€ข mitre-att&ck="from-OTX"
โ€ข sub-category="campaign-analysis"
โ€ข target="broad-based"
โ€ข no-samples-in="MalwareBazaar"
โ€ข no-samples-in="Tria.ge"

๐Ÿ”–MISP Galaxies:
โ€ข malpedia="Vidar"
โ€ข malpedia="DeerStealer"
mitre-attack-pattern=['T1204.001', 'T1566.002', 'T1059.001', 'T1027', 'T1140', 'T1071.001', 'T1105', 'T1055', 'T1112', 'T1497', 'T1070.004', 'T1082', 'T1555.003', 'T1555', 'T1539', 'T1005', 'T1041', 'T1027.002']

MISP event uuid: 6d14d444-58c0-45da-92e5-fca9cdcd7637
๐Ÿ“ƒTitle: Infostealer Campaign Using Trading App as Lure
๐Ÿ“…Date: 2026-05-20
๐Ÿ”—References:
https://hybrid-analysis.blogspot.com/2026/05/velvet-chollima-infostealer-campaign.html?m=1

๐Ÿ”–Rectifyq Taxonomies:
Relevancy: ๐Ÿ”ต Potentially Relevant
Category: โš” Threat
โ€ข mitre-att&ck="none-from-src"
โ€ข mitre-att&ck="from-OTX"
โ€ข sub-category="campaign-analysis"
โ€ข target="broad-based"
โ€ข no-samples-in="MalwareBazaar"
โ€ข samples-found-in="Tria.ge"
โ€ข action-taken="VT-comment"

๐Ÿ”–MISP Galaxies:
โ€ข producer="Hybrid Analysis"
mitre-attack-pattern=['T1566', 'T1204', 'T1036', 'T1553.002', 'T1547.001', 'T1053.005', 'T1059.001', 'T1027', 'T1105', 'T1082', 'T1012', 'T1518.001', 'T1056.001', 'T1555.003', 'T1567.001', 'T1071.001', 'T1132', 'T1497', 'T1497.001', 'T1614']

MISP event uuid: 08b137bc-104f-4dcc-a5ab-09ec9ce19b7b
๐Ÿ“ƒTitle: APT Targets Azerbaijani Oil and Gas Industry
๐Ÿ“…Date: 2026-05-13
๐Ÿ”—References:
https://businessinsights.bitdefender.com/famoussparrow-apt-targets-azerbaijani-oil-gas-industry

๐Ÿ”–Rectifyq Taxonomies:
Relevancy: โšซ Not Relevant
Category: โš” Threat
โ€ข mitre-att&ck="from-original-src"
โ€ข mitre-att&ck="from-OTX"
โ€ข sub-category="TA-profile"
โ€ข sub-category="campaign-analysis"
โ€ข TA-category="APT"
โ€ข target="broad-based"
โ€ข no-samples-in="MalwareBazaar"
โ€ข no-samples-in="Tria.ge"
โ€ข action-taken="VT-comment"

๐Ÿ”–MISP Galaxies:
โ€ข producer="Bitdefender"
โ€ข target-information="Azerbaijan"
โ€ข threat-actor="GhostEmperor"
โ€ข country="china"
โ€ข malpedia="SNAPPYBEE"
โ€ข sector="Gas"
โ€ข sector="Oil"
mitre-attack-pattern=['T1190', 'T1505.003', 'T1543.003', 'T1574.002', 'T1140', 'T1562', 'T1569.002', 'T1059.001', 'T1021.001', 'T1021.002', 'T1071.001', 'T1014']

MISP event uuid: 4513c651-0f6c-417a-8390-6a800dc28872