Rectifyq Cybersecurity News πŸ‡²πŸ‡Ύ
172 subscribers
2 files
1.92K links
rectifyq.com
Rectifyq Cybersecurity News with approximate relevancy to Malaysia and contextualized using MISP Galaxies.

Relevancy
πŸ”΄- e.g. APT target πŸ‡²πŸ‡Ύ.
🟑- e.g. APT target Asian country.
πŸ”΅- e.g. Infostealers impact globally.
⚫- Good to know only.
Download Telegram
πŸ“ƒTitle: Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability
πŸ“…Date: 2026-05-26
πŸ”—References:
https://cloud.google.com/blog/topics/threat-intelligence/knowledgedeliver-viewstate-deserialization-vulnerability

πŸ”–Rectifyq Taxonomies:
Relevancy: ⚫ Not Relevant
Category: βš” Threat
β€’ mitre-att&ck="none-from-src"
β€’ mitre-att&ck="from-OTX"
β€’ sub-category="intrusion-analysis"
β€’ target="targeted"
β€’ samples-found-in="MalwareBazaar"
β€’ samples-found-in="Tria.ge"
β€’ action-taken="VT-comment"

πŸ”–MISP Galaxies:
β€’ producer="Mandiant"
β€’ target-information="Japan"
mitre-attack-pattern=['T1036.005', 'T1204.002', 'T1566.002', 'T1222.001', 'T1082', 'T1106', 'T1190', 'T1070.006', 'T1505.003', 'T1087', 'T1083', 'T1057', 'T1059.001', 'T1547.001', 'T1027.005', 'T1068', 'T1027', 'T1573', 'T1059.003', 'T1071.001']

MISP event uuid: 7d11ee85-edb4-4c0d-8857-1c31a3bbf632
πŸ“ƒTitle: Laravel Lang Compromised with RCE Backdoor Across 700+ Versions
πŸ“…Date: 2026-05-23
πŸ”—References:
https://socket.dev/blog/laravel-lang-compromise

πŸ”–Rectifyq Taxonomies:
Relevancy: πŸ”΅ Potentially Relevant
Category: βš” Threat
β€’ mitre-att&ck="none-from-src"
β€’ mitre-att&ck="from-OTX"
β€’ sub-category="campaign-analysis"
β€’ topic="supply-chain"
β€’ target="broad-based"
β€’ no-samples-in="MalwareBazaar"
β€’ no-samples-in="Tria.ge"
β€’ action-taken="VT-comment"

πŸ”–MISP Galaxies:
β€’ producer="37ebf9d7-5e9a-466f-a42c-6e60313db868"
mitre-attack-pattern=['T1552.005', 'T1555.001', 'T1573.001', 'T1555.005', 'T1552.002', 'T1082', 'T1140', 'T1555.003', 'T1552.004', 'T1078.001', 'T1083', 'T1552.001', 'T1552.006', 'T1059.004', 'T1027', 'T1195.002', 'T1071.001', 'T1078.004', 'T1552.007']

MISP event uuid: 9fd4e771-9d30-4b3d-bdc9-9f5c6fa70541
πŸ“ƒTitle: From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5 and Confluence
πŸ“…Date: 2026-05-22
πŸ”—References:
https://www.microsoft.com/en-us/security/blog/2026/05/22/from-edge-appliance-to-enterprise-compromise-multi-stage-linux-intrusion-via-f5-and-confluence/

πŸ”–Rectifyq Taxonomies:
Relevancy: πŸ”΅ Potentially Relevant
Category: βš” Threat
β€’ mitre-att&ck="from-original-src"
β€’ mitre-att&ck="from-OTX"
β€’ sub-category="intrusion-analysis"
β€’ topic="cloud"
β€’ target="targeted"
β€’ no-samples-in="MalwareBazaar"
β€’ no-samples-in="Tria.ge"
β€’ action-taken="VT-comment"

πŸ”–MISP Galaxies:
β€’ producer="Microsoft"
mitre-attack-pattern=['T1557', 'T1222.002', 'T1021.004', 'T1071', 'T1005', 'T1190', 'T1083', 'T1059.004', 'T1187', 'T1078.002', 'T1059.006', 'T1505', 'T1105', 'T1043']

MISP event uuid: fd752467-0d11-47e9-a740-deaf9985264d
πŸ“ƒTitle: Fast and Furious - Nimbus Manticore Operations During the Iranian Conflict
πŸ“…Date: 2026-05-22
πŸ”—References:
https://research.checkpoint.com/2026/fast-and-furious-nimbus-manticore-operations-during-the-iranian-conflict/

πŸ”–Rectifyq Taxonomies:
Relevancy: ⚫ Not Relevant
Category: βš” Threat
β€’ mitre-att&ck="none-from-src"
β€’ mitre-att&ck="from-OTX"
β€’ sub-category="campaign-analysis"
β€’ topic="geopolitical"
β€’ TA-category="APT"
β€’ target="broad-based"
β€’ no-samples-in="MalwareBazaar"
β€’ samples-found-in="Tria.ge"
β€’ action-taken="VT-comment"

πŸ”–MISP Galaxies:
β€’ producer="Check Point"
β€’ target-information="United States"
β€’ target-information="Australia"
β€’ target-information="Saudi Arabia"
β€’ target-information="Israel"
β€’ target-information="United Arab Emirates"
β€’ threat-actor="UNC1549"
β€’ country="iran"
mitre-attack-pattern=['T1053.005', 'T1033', 'T1132.001', 'T1036.005', 'T1204.002', 'T1573.001', 'T1566.002', 'T1566.001', 'T1082', 'T1106', 'T1140', 'T1083', 'T1057', 'T1041', 'T1027', 'T1059.003', 'T1189', 'T1071.001', 'T1574.002', 'T1105']

MISP event uuid: 5795b1d1-efb3-404b-91f4-3cc22a56ccd9
πŸ“ƒTitle: Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns
πŸ“…Date: 2026-05-22
πŸ”—References:
https://unit42.paloaltonetworks.com/tracking-iran-apt-screening-serpens/

πŸ”–Rectifyq Taxonomies:
Relevancy: ⚫ Not Relevant
Category: βš” Threat
β€’ mitre-att&ck="none-from-src"
β€’ mitre-att&ck="from-OTX"
β€’ sub-category="TA-profile"
β€’ topic="geopolitical"
β€’ TA-category="APT"
β€’ target="broad-based"
β€’ no-samples-in="MalwareBazaar"
β€’ samples-found-in="Tria.ge"
β€’ action-taken="VT-comment"

πŸ”–MISP Galaxies:
β€’ producer="Palo Alto"
β€’ target-information="United States"
β€’ target-information="Israel"
β€’ target-information="United Arab Emirates"
β€’ country="iran"
β€’ threat-actor="UNC1549"
mitre-attack-pattern=['T1053.005', 'T1036.005', 'T1204.002', 'T1566.001', 'T1082', 'T1106', 'T1140', 'T1055', 'T1218', 'T1083', 'T1036.004', 'T1057', 'T1041', 'T1547.001', 'T1562.001', 'T1027', 'T1059.003', 'T1070.004', 'T1071.001', 'T1574.002']

MISP event uuid: cbfd6ef2-719f-4544-af73-580b5f764c5c
πŸ“ƒTitle: Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload
πŸ“…Date: 2026-05-22
πŸ”—References:
https://securelist.com/cloud-atlas-2026/119895/

πŸ”–Rectifyq Taxonomies:
Relevancy: ⚫ Not Relevant
Category: βš” Threat
β€’ mitre-att&ck="none-from-src"
β€’ mitre-att&ck="from-OTX"
β€’ sub-category="TA-profile"
β€’ TA-category="APT"
β€’ target="broad-based"
β€’ no-samples-in="MalwareBazaar"
β€’ no-samples-in="Tria.ge"
β€’ action-taken="VT-comment"

πŸ”–MISP Galaxies:
β€’ producer="Kaspersky"
β€’ target-information="Belarus"
β€’ target-information="Russia"
β€’ threat-actor="Inception Framework"
β€’ sector="Diplomacy"
β€’ sector="Government, Administration"
mitre-attack-pattern=['T1003.002', 'T1074.001', 'T1087.002', 'T1204.002', 'T1566.001', 'T1005', 'T1140', 'T1055', 'T1572', 'T1090', 'T1482', 'T1059.001', 'T1547.001', 'T1078', 'T1027', 'T1573', 'T1071.001', 'T1018', 'T1021.001', 'T1558.003']

MISP event uuid: 7f23650f-d187-4f77-8965-5a32f48fdd80
πŸ“ƒTitle: RemotePE: The Lazarus RAT that lives in memory
πŸ“…Date: 2026-05-25
πŸ”—References:
https://blog.fox-it.com/2026/05/22/remotepe-the-lazarus-rat-that-lives-in-memory/

πŸ”–Rectifyq Taxonomies:
Relevancy: πŸ”΅ Potentially Relevant
Category: βš” Threat
β€’ mitre-att&ck="from-original-src"
β€’ mitre-att&ck="from-OTX"
β€’ sub-category="malware-analysis"
β€’ TA-category="APT"
β€’ target="broad-based"
β€’ samples-found-in="MalwareBazaar"
β€’ samples-found-in="Tria.ge"
β€’ action-taken="VT-comment"

πŸ”–MISP Galaxies:
β€’ threat-actor="Lazarus Group"
mitre-attack-pattern=['T1543.003', 'T1082', 'T1106', 'T1005', 'T1140', 'T1055', 'T1560', 'T1562.006', 'T1083', 'T1036.004', 'T1497', 'T1057', 'T1562.001', 'T1027', 'T1573', 'T1132', 'T1027.002', 'T1071.001', 'T1574.002', 'T1480.001']

MISP event uuid: 97638d90-a35a-4490-80dd-f2e3d548c42e
Rectifyq Cybersecurity News πŸ‡²πŸ‡Ύ pinned Β«πŸ“ƒTitle: Premium Deception: Uncovering a Global Android Carrier Billing Fraud Campaign πŸ“…Date: 2026-05-20 πŸ”—References: https://zimperium.com/blog/premium-deception-uncovering-a-global-android-carrier-billing-fraud-campaign πŸ”–Rectifyq Taxonomies: Relevancy:…»
Rectifyq Cybersecurity News πŸ‡²πŸ‡Ύ pinned Β«πŸ“ƒTitle: KerjaExpress Campaign - Android Banking Trojan Targeting Malaysian Financial Institutions πŸ“…Date: 2026-05-23 πŸ”—References: πŸ”–Rectifyq Taxonomies: Relevancy: πŸ”΄ Highly Relevant Category: βš” Threat β€’ sub-category="campaign-analysis" β€’ topic="mobile-attack"…»
πŸ“ƒTitle: MTNew-v3Campaign Advanced Banking Trojan Targeting Malaysian Financial Sector
πŸ“…Date: 2026-05-24
πŸ”—References:

πŸ”–Rectifyq Taxonomies:
Relevancy: πŸ”΄ Highly Relevant
Category: βš” Threat
β€’ sub-category="malware-analysis"
β€’ topic="mobile-attack"
β€’ target="broad-based"
β€’ no-samples-in="MalwareBazaar"
β€’ no-samples-in="Tria.ge"
β€’ action-taken="VT-comment"

πŸ”–MISP Galaxies:
β€’ target-information="Malaysia"
β€’ sector="Finance"
mitre-attack-pattern=['T1660', 'T1476', 'T1406.002', 'T1437', 'T1437.001', 'T1406', 'T1417.001', 'T1412', 'T1513', 'T1429', 'T1446']

MISP event uuid: c3e3d1a1-2a9e-420d-b8f0-16a801149af0
πŸ“ƒTitle: MaxTag Malware Family
πŸ“…Date: 2026-05-25
πŸ”—References:

πŸ”–Rectifyq Taxonomies:
Relevancy: πŸ”΄ Highly Relevant
Category: βš” Threat
β€’ sub-category="malware-analysis"
β€’ topic="mobile-attack"
β€’ target="broad-based"
β€’ no-samples-in="MalwareBazaar"
β€’ no-samples-in="Tria.ge"
β€’ action-taken="VT-comment"

πŸ”–MISP Galaxies:
β€’ target-information="Malaysia"
β€’ sector="Finance"
mitre-attack-pattern=['T1429', 'T1412', 'T1417', 'T1516', 'T1411', 'T1461', 'T1444', 'T1406', 'T1582', 'T1603', 'T1513', 'T1481']

MISP event uuid: dcc49ea4-0a45-434b-ad1e-44d68b14b954
πŸ“ƒTitle: The GHOST STADIUM Score: Billions At Stake At The World’s Largest Football Tournament
πŸ“…Date: 2026-05-27
πŸ”—References:
https://www.group-ib.com/blog/ghost-stadium-football-fraud/

πŸ”–Rectifyq Taxonomies:
Relevancy: πŸ”΅ Potentially Relevant
Category: βš” Threat
β€’ mitre-att&ck="none-from-src"
β€’ mitre-att&ck="from-OTX"
β€’ sub-category="TA-profile"
β€’ sub-category="campaign-analysis"
β€’ TA-category="Cybercrime"
β€’ target="broad-based"
β€’ no-samples-in="MalwareBazaar"
β€’ no-samples-in="Tria.ge"
β€’ action-taken="VT-comment"

πŸ”–MISP Galaxies:
β€’ producer="Group-IB"
β€’ target-information="United States"
β€’ target-information="Argentina"
β€’ target-information="Brazil"
β€’ target-information="Canada"
β€’ target-information="Colombia"
β€’ target-information="Mexico"
mitre-attack-pattern=['T1056.001', 'T1539', 'T1588.004', 'T1566.002', 'T1598.003', 'T1586.002', 'T1583.001', 'T1185', 'T1555.003', 'T1003.001', 'T1102', 'T1566', 'T1078', 'T1585.001', 'T1027', 'T1573', 'T1598', 'T1189', 'T1071.001', 'T1590.001']

MISP event uuid: e4437cb1-34ec-4e07-b01f-92303168362f
πŸ“ƒTitle: From poisoned search results to GPU mining: A cryptojacking campaign abusing ScreenConnect and Microsoft .NET utilities
πŸ“…Date: 2026-05-26
πŸ”—References:
https://www.microsoft.com/en-us/security/blog/2026/05/26/poisoned-search-results-gpu-mining-cryptojacking-campaign-abusing-screenconnect-microsoft-net-utilities/

πŸ”–Rectifyq Taxonomies:
Relevancy: πŸ”΅ Potentially Relevant
Category: βš” Threat
β€’ mitre-att&ck="none-from-src"
β€’ mitre-att&ck="from-OTX"
β€’ sub-category="campaign-analysis"
β€’ topic="crypto-related"
β€’ target="broad-based"
β€’ no-samples-in="MalwareBazaar"
β€’ samples-found-in="Tria.ge"
β€’ action-taken="VT-comment"

πŸ”–MISP Galaxies:
β€’ producer="Microsoft"
mitre-attack-pattern=['T1053.005', 'T1036.005', 'T1497.001', 'T1082', 'T1218.007', 'T1140', 'T1219', 'T1547.009', 'T1497.003', 'T1112', 'T1059.001', 'T1547.001', 'T1562.001', 'T1055.012', 'T1027', 'T1573', 'T1189', 'T1071.001', 'T1574.002', 'T1105']

MISP event uuid: 375002f5-d1e7-4371-93ed-5a833e8595b0
πŸ“ƒTitle: Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet
πŸ“…Date: 2026-05-26
πŸ”—References:
https://www.trendmicro.com/en_us/research/26/e/smart-contracts-for-command-and-control.html

πŸ”–Rectifyq Taxonomies:
Relevancy: πŸ”΅ Potentially Relevant
Category: βš” Threat
β€’ mitre-att&ck="none-from-src"
β€’ mitre-att&ck="from-OTX"
β€’ sub-category="campaign-analysis"
β€’ topic="web3"
β€’ topic="crypto-related"
β€’ target="broad-based"
β€’ no-samples-in="MalwareBazaar"
β€’ no-samples-in="Tria.ge"
β€’ action-taken="VT-comment"

πŸ”–MISP Galaxies:
β€’ producer="Trend Micro"
β€’ target-information="Switzerland"
β€’ malpedia="SectopRAT"
mitre-attack-pattern=['T1539', 'T1036.005', 'T1204.002', 'T1497.001', 'T1140', 'T1185', 'T1555.003', 'T1055.002', 'T1102', 'T1059.001', 'T1055.012', 'T1027', 'T1012', 'T1518.001', 'T1059.006', 'T1189', 'T1071.001', 'T1105', 'T1056.004']

MISP event uuid: ead1cc2e-5a16-47f9-b9e0-6e8cd5ff1dfc
πŸ“ƒTitle: Phishing Campaign Deploys JavaScript-Driven PureLogs Variant to Steal Sensitive Data
πŸ“…Date: 2026-05-26
πŸ”—References:
https://www.fortinet.com/blog/threat-research/phishing-campaign-deploys-javascript-driven-purelogs-variant-to-steal-sensitive-data

πŸ”–Rectifyq Taxonomies:
Relevancy: πŸ”΅ Potentially Relevant
Category: βš” Threat
β€’ mitre-att&ck="none-from-src"
β€’ mitre-att&ck="from-OTX"
β€’ sub-category="campaign-analysis"
β€’ target="broad-based"
β€’ topic="crypto-related"
β€’ samples-found-in="MalwareBazaar"
β€’ samples-found-in="Tria.ge"
β€’ action-taken="VT-comment"

πŸ”–MISP Galaxies:
β€’ producer="Fortinet"
β€’ malpedia="PureLogs Stealer"
mitre-attack-pattern=['T1113', 'T1033', 'T1218.011', 'T1059.007', 'T1539', 'T1566.001', 'T1115', 'T1082', 'T1005', 'T1140', 'T1555', 'T1055', 'T1218', 'T1555.003', 'T1041', 'T1059.001', 'T1566', 'T1055.012', 'T1027', 'T1573', 'T1027.002', 'T1071.001', 'T1105']

MISP event uuid: 75c62da8-6ae9-45ed-bdaa-1558105b9bf4
πŸ“ƒTitle: Pinduoduo (ζ‹Όε€šε€š) Android APK Static Analysis & Verdict
πŸ“…Date: 2026-05-27
πŸ”—References:

πŸ”–Rectifyq Taxonomies:
Relevancy: πŸ”΅ Potentially Relevant
Category: βš” Threat
β€’ sub-category="malware-analysis"
β€’ topic="mobile-attack"
β€’ target="broad-based"
β€’ no-samples-in="MalwareBazaar"
β€’ no-samples-in="Tria.ge"
β€’ action-taken="VT-comment"

πŸ”–MISP Galaxies:
mitre-attack-pattern=['T1437', 'T1544', 'T1521', 'T1417', 'T1430', 'T1429', 'T1424', 'T1406', 'T1512', 'T1636.003']

MISP event uuid: 9c3282c7-b7dd-4fcd-bb2f-427f58b9f7b8
πŸ“ƒTitle: Windows and macOS Malware Spreads via Fake β€œClaude Code” Google Ads
πŸ“…Date: 2026-03-11
πŸ”—References:
https://www.bitdefender.com/en-us/blog/labs/fake-claude-code-google-ads-malware

πŸ”–Rectifyq Taxonomies:
Relevancy: 🟑 Somewhat Relevant
Category: βš” Threat
β€’ sub-category="campaign-analysis"
β€’ topic="ai"
β€’ target="broad-based"
β€’ mitre-att&ck="none-from-src"
β€’ samples-found-in="MalwareBazaar"
β€’ samples-found-in="Tria.ge"
β€’ action-taken="VT-comment"

πŸ”–MISP Galaxies:
β€’ target-information="Malaysia"
β€’ producer="Bitdefender"
mitre-attack-pattern=['T1170', 'T1218.005']

MISP event uuid: 19961acf-73c8-4594-8698-6294f9b2d5ca
πŸ“ƒTitle: InstallFix and Claude Code: How Fake Install Pages Lead to Real Compromise
πŸ“…Date: 2026-05-05
πŸ”—References:
https://www.trendmicro.com/en_us/research/26/e/installfix-and-claude-code.html

πŸ”–Rectifyq Taxonomies:
Relevancy: πŸ”΄ Highly Relevant
Category: βš” Threat
β€’ sub-category="malware-analysis"
β€’ sub-category="campaign-analysis"
β€’ target="broad-based"
β€’ mitre-att&ck="from-original-src"
β€’ no-samples-in="MalwareBazaar"
β€’ samples-found-in="Tria.ge"
β€’ action-taken="x"
β€’ action-taken="linkedin"
β€’ action-taken="VT-comment"

πŸ”–MISP Galaxies:
β€’ producer="Trend Micro"
β€’ target-information="Malaysia"
β€’ target-information="Netherlands"
β€’ target-information="Thailand"
β€’ target-information="United States"
β€’ sector="Education"
β€’ sector="Electronic"
β€’ sector="Food"
β€’ sector="Government, Administration"
mitre-attack-pattern=['T1559.001', 'T1562', 'T1583.008', 'T1218.005', 'T1027', 'T1059.001', 'T1566.002', 'T1059.005']

MISP event uuid: e30b1a07-b830-46e2-bf69-e67eee29d4af
πŸ“ƒTitle: Exposing a Global Smishing Operation Across 19 Countries: Governments, Postal Services, and Telecoms Targeted
πŸ“…Date: 2026-05-27
πŸ”—References:
https://hunt.io/blog/massive-smishing-campaign-governments-postal-telecoms

πŸ”–Rectifyq Taxonomies:
Relevancy: ⚫ Not Relevant
Category: βš” Threat
β€’ mitre-att&ck="none-from-src"
β€’ mitre-att&ck="from-OTX"
β€’ sub-category="campaign-analysis"
β€’ topic="mobile-attack"
β€’ target="broad-based"
β€’ no-samples-in="MalwareBazaar"
β€’ no-samples-in="Tria.ge"
β€’ action-taken="VT-comment"

πŸ”–MISP Galaxies:
β€’ producer="Hunt.io"
β€’ target-information="United States"
β€’ target-information="Albania"
β€’ target-information="Armenia"
β€’ target-information="Bulgaria"
β€’ target-information="Estonia"
β€’ target-information="France"
β€’ target-information="Georgia"
β€’ target-information="Greece"
β€’ target-information="Ireland"
β€’ target-information="Kosovo"
β€’ target-information="Latvia"
β€’ target-information="Lithuania"
β€’ target-information="North Macedonia"
β€’ target-information="Montenegro"
β€’ target-information="Romania"
β€’ target-information="Slovenia"
β€’ target-information="Spain"
β€’ target-information="Trinidad and Tobago"
β€’ target-information="United Kingdom"
mitre-attack-pattern=['T1583', 'T1204.002', 'T1566.002', 'T1598.003', 'T1586.002', 'T1608.001', 'T1583.001', 'T1560', 'T1090', 'T1584', 'T1586', 'T1102', 'T1608', 'T1583.006', 'T1204', 'T1041', 'T1566', 'T1078', 'T1598', 'T1213', 'T1584.001']

MISP event uuid: 36e75fd8-359f-4f84-8258-5f35cf8ed39b
Rectifyq Cybersecurity News πŸ‡²πŸ‡Ύ pinned Β«πŸ“ƒTitle: MTNew-v3Campaign Advanced Banking Trojan Targeting Malaysian Financial Sector πŸ“…Date: 2026-05-24 πŸ”—References: πŸ”–Rectifyq Taxonomies: Relevancy: πŸ”΄ Highly Relevant Category: βš” Threat β€’ sub-category="malware-analysis" β€’ topic="mobile-attack" β€’ target="broad…»
Rectifyq Cybersecurity News πŸ‡²πŸ‡Ύ pinned Β«πŸ“ƒTitle: MaxTag Malware Family πŸ“…Date: 2026-05-25 πŸ”—References: πŸ”–Rectifyq Taxonomies: Relevancy: πŸ”΄ Highly Relevant Category: βš” Threat β€’ sub-category="malware-analysis" β€’ topic="mobile-attack" β€’ target="broad-based" β€’ no-samples-in="MalwareBazaar" β€’ no…»