Rectifyq Cybersecurity News π²πΎ pinned Β«πTitle: [Ransomware] Unconfirmed: Ked** π
Date: 2026-06-16 πReferences: https://www.ransomware.live/id/S2VkYWhAbm92YQ== πRectifyq Taxonomies: Relevancy: π΄ Highly Relevant Category: π₯ Data Breach - TA-category="Ransomware" πMISP Galaxies: - target-inforβ¦Β»
πTitle: [Ransomware] Unconfirmed: THL PRO**** MAN******* SDN* BHD*
π Date: 2026-06-18
πReferences: https://www.ransomware.live/id/VEhMIFBST0pFQ1QgTUFOQUdFTUVOVCBTRE4uIEJIRC5AcWlsaW4=
πRectifyq Taxonomies:
Relevancy: π΄ Highly Relevant
Category: π₯ Data Breach
- TA-category="Ransomware"
πMISP Galaxies:
- target-information="Malaysia"
- sector="Business Services"
- ransomware="Qilin"
mitre-attack-pattern=[]
MISP event uuid: 33ac9a5c-438c-41fe-8d33-117f0ba8dc5e
π Date: 2026-06-18
πReferences: https://www.ransomware.live/id/VEhMIFBST0pFQ1QgTUFOQUdFTUVOVCBTRE4uIEJIRC5AcWlsaW4=
πRectifyq Taxonomies:
Relevancy: π΄ Highly Relevant
Category: π₯ Data Breach
- TA-category="Ransomware"
πMISP Galaxies:
- target-information="Malaysia"
- sector="Business Services"
- ransomware="Qilin"
mitre-attack-pattern=[]
MISP event uuid: 33ac9a5c-438c-41fe-8d33-117f0ba8dc5e
Ransomware.live
Victim: THL PROJECT MANAGEMENT SDN. BHD. β qilin
Ransomware.live discovered on 2026-06-18 that THL PROJECT MANAGEMENT SDN. BHD. has been claimed by Qilin ransomware group
Rectifyq Cybersecurity News π²πΎ pinned Β«πTitle: [Ransomware] Unconfirmed: THL PRO**** MAN******* SDN* BHD* π
Date: 2026-06-18 πReferences: https://www.ransomware.live/id/VEhMIFBST0pFQ1QgTUFOQUdFTUVOVCBTRE4uIEJIRC5AcWlsaW4= πRectifyq Taxonomies: Relevancy: π΄ Highly Relevant Category: π₯ Data Breachβ¦Β»
πTitle: [Ransomware] Unconfirmed: mli******** UPD******** DAT* DUM* 10G*
π Date: 2026-06-19
πReferences: https://www.ransomware.live/id/bWxpdC5jb20ubXkgVVBEQVRFLUZVTEwgREFUQSBEVU1QIDEwR0JAc3Rvcm1vdXM=
πRectifyq Taxonomies:
Relevancy: π΄ Highly Relevant
Category: π₯ Data Breach
- TA-category="Ransomware"
πMISP Galaxies:
- target-information="Malaysia"
- sector="Public Sector"
- ransomware="stormous"
mitre-attack-pattern=[]
MISP event uuid: b0f890ec-80ba-4072-98d8-68d21c5d3ae3
π Date: 2026-06-19
πReferences: https://www.ransomware.live/id/bWxpdC5jb20ubXkgVVBEQVRFLUZVTEwgREFUQSBEVU1QIDEwR0JAc3Rvcm1vdXM=
πRectifyq Taxonomies:
Relevancy: π΄ Highly Relevant
Category: π₯ Data Breach
- TA-category="Ransomware"
πMISP Galaxies:
- target-information="Malaysia"
- sector="Public Sector"
- ransomware="stormous"
mitre-attack-pattern=[]
MISP event uuid: b0f890ec-80ba-4072-98d8-68d21c5d3ae3
Ransomware.live
Victim: mlit.com.my UPDATE-FULL DATA DUMP 10GB β stormous
Ransomware.live discovered on 2026-06-19 that mlit.com.my UPDATE-FULL DATA DUMP 10GB has been claimed by Stormous ransomware group
Rectifyq Cybersecurity News π²πΎ pinned Β«πTitle: [Ransomware] Unconfirmed: mli******** UPD******** DAT* DUM* 10G* π
Date: 2026-06-19 πReferences: https://www.ransomware.live/id/bWxpdC5jb20ubXkgVVBEQVRFLUZVTEwgREFUQSBEVU1QIDEwR0JAc3Rvcm1vdXM= πRectifyq Taxonomies: Relevancy: π΄ Highly Relevant Category:β¦Β»
πTitle: [Ransomware] Unconfirmed: SGS Mal*****
π Date: 2026-06-18
πReferences: https://www.ransomware.live/id/U0dTIE1hbGF5c2lhQHRoZWdlbnRsZW1lbg==
πRectifyq Taxonomies:
Relevancy: π΄ Highly Relevant
Category: π₯ Data Breach
- TA-category="Ransomware"
πMISP Galaxies:
- target-information="Malaysia"
- sector="Business Services"
- ransomware="the gentlemen"
mitre-attack-pattern=[]
MISP event uuid: e6de9568-7c3f-4928-82f0-9032c5256af9
π Date: 2026-06-18
πReferences: https://www.ransomware.live/id/U0dTIE1hbGF5c2lhQHRoZWdlbnRsZW1lbg==
πRectifyq Taxonomies:
Relevancy: π΄ Highly Relevant
Category: π₯ Data Breach
- TA-category="Ransomware"
πMISP Galaxies:
- target-information="Malaysia"
- sector="Business Services"
- ransomware="the gentlemen"
mitre-attack-pattern=[]
MISP event uuid: e6de9568-7c3f-4928-82f0-9032c5256af9
Ransomware.live
Victim: SGS Malaysia β thegentlemen
Ransomware.live discovered on 2026-06-20 that SGS Malaysia has been claimed by Thegentlemen ransomware group
Rectifyq Cybersecurity News π²πΎ pinned Β«πTitle: [Ransomware] Unconfirmed: SGS Mal***** π
Date: 2026-06-18 πReferences: https://www.ransomware.live/id/U0dTIE1hbGF5c2lhQHRoZWdlbnRsZW1lbg== πRectifyq Taxonomies: Relevancy: π΄ Highly Relevant Category: π₯ Data Breach - TA-category="Ransomware" πMISPβ¦Β»
πTitle: Targeted espionage against Cambodian government entities
π Date: 2026-06-10
πReferences:
https://www.acronis.com/en/tru/posts/behind-khmer-shadow-targeted-espionage-against-cambodian-government-entities/
πRectifyq Taxonomies:
Relevancy: β« Not Relevant
Category: β Threat
β’ mitre-att&ck="none-from-src"
β’ mitre-att&ck="from-OTX"
β’ sub-category="campaign-analysis"
β’ topic="geopolitical"
β’ target="targeted"
β’ no-samples-in="MalwareBazaar"
β’ samples-found-in="Tria.ge"
β’ action-taken="VT-comment"
πMISP Galaxies:
β’ target-information="Cambodia"
β’ producer="8545fbf3-a246-4938-96a9-85a24651ebde"
β’ sector="Government, Administration"
mitre-attack-pattern=['T1053.005', 'T1071.004', 'T1036.005', 'T1204.002', 'T1497.001', 'T1566.001', 'T1106', 'T1140', 'T1055', 'T1562.002', 'T1055.012', 'T1027', 'T1573.002', 'T1134', 'T1027.002', 'T1071.001', 'T1574.002', 'T1055.001']
MISP event uuid: a95dd958-71be-430e-b83e-eeb6eaa34c3e
π Date: 2026-06-10
πReferences:
https://www.acronis.com/en/tru/posts/behind-khmer-shadow-targeted-espionage-against-cambodian-government-entities/
πRectifyq Taxonomies:
Relevancy: β« Not Relevant
Category: β Threat
β’ mitre-att&ck="none-from-src"
β’ mitre-att&ck="from-OTX"
β’ sub-category="campaign-analysis"
β’ topic="geopolitical"
β’ target="targeted"
β’ no-samples-in="MalwareBazaar"
β’ samples-found-in="Tria.ge"
β’ action-taken="VT-comment"
πMISP Galaxies:
β’ target-information="Cambodia"
β’ producer="8545fbf3-a246-4938-96a9-85a24651ebde"
β’ sector="Government, Administration"
mitre-attack-pattern=['T1053.005', 'T1071.004', 'T1036.005', 'T1204.002', 'T1497.001', 'T1566.001', 'T1106', 'T1140', 'T1055', 'T1562.002', 'T1055.012', 'T1027', 'T1573.002', 'T1134', 'T1027.002', 'T1071.001', 'T1574.002', 'T1055.001']
MISP event uuid: a95dd958-71be-430e-b83e-eeb6eaa34c3e
Acronis
Behind Khmer Shadow: Targeted espionage against Cambodian government entities
Acronis Threat Research Unit (TRU) has identified two espionage-focused campaigns targeting Cambodian government entities in the defense and public works sectors. TRU has assessed with moderate confidence that the activity is espionage-motivated and likelyβ¦
πTitle: From external espionage to domestic targeting
π Date: 2026-06-11
πReferences:
https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/
πRectifyq Taxonomies:
Relevancy: π΅ Potentially Relevant
Category: β Threat
β’ mitre-att&ck="from-original-src"
β’ mitre-att&ck="from-OTX"
β’ sub-category="TA-profile"
β’ TA-category="APT"
β’ target="broad-based"
β’ samples-found-in="MalwareBazaar"
β’ samples-found-in="Tria.ge"
β’ action-taken="VT-comment"
πMISP Galaxies:
β’ producer="ESET"
β’ threat-actor="APT32"
β’ country="vietnam"
mitre-attack-pattern=['T1553.002', 'T1082', 'T1190', 'T1036', 'T1055', 'T1021', 'T1059', 'T1204', 'T1041', 'T1027', 'T1573', 'T1195.002', 'T1570', 'T1071.001', 'T1574.002', 'T1105']
MISP event uuid: 9707a436-2783-4260-9a91-00590fb630a2
π Date: 2026-06-11
πReferences:
https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/
πRectifyq Taxonomies:
Relevancy: π΅ Potentially Relevant
Category: β Threat
β’ mitre-att&ck="from-original-src"
β’ mitre-att&ck="from-OTX"
β’ sub-category="TA-profile"
β’ TA-category="APT"
β’ target="broad-based"
β’ samples-found-in="MalwareBazaar"
β’ samples-found-in="Tria.ge"
β’ action-taken="VT-comment"
πMISP Galaxies:
β’ producer="ESET"
β’ threat-actor="APT32"
β’ country="vietnam"
mitre-attack-pattern=['T1553.002', 'T1082', 'T1190', 'T1036', 'T1055', 'T1021', 'T1059', 'T1204', 'T1041', 'T1027', 'T1573', 'T1195.002', 'T1570', 'T1071.001', 'T1574.002', 'T1105']
MISP event uuid: 9707a436-2783-4260-9a91-00590fb630a2
Welivesecurity
OceanLotus: From external espionage to domestic targeting
ESET researchers show how OceanLotus, a Vietnam-aligned APT group, has put an increasing focus on domestic espionage between 2024 and 2026.
πTitle: Sniper's Nest: From Brand Impersonation to Browser Hijacking and CPA Fraud
π Date: 2026-06-11
πReferences:
https://www.group-ib.com/blog/inside-sniperdz-phaas-ecosystem/
πRectifyq Taxonomies:
Relevancy: π΅ Potentially Relevant
Category: β Threat
β’ mitre-att&ck="none-from-src"
β’ mitre-att&ck="from-OTX"
β’ sub-category="tool-profile"
β’ target="broad-based"
β’ TA-category="Cybercrime"
β’ sub-category="infra-profile"
β’ no-samples-in="MalwareBazaar"
β’ no-samples-in="Tria.ge"
β’ action-taken="VT-comment"
πMISP Galaxies:
β’ producer="Group-IB"
β’ target-information="Algeria"
mitre-attack-pattern=[]
MISP event uuid: 7a3ded92-0934-49f2-956c-0623538fbdb6
π Date: 2026-06-11
πReferences:
https://www.group-ib.com/blog/inside-sniperdz-phaas-ecosystem/
πRectifyq Taxonomies:
Relevancy: π΅ Potentially Relevant
Category: β Threat
β’ mitre-att&ck="none-from-src"
β’ mitre-att&ck="from-OTX"
β’ sub-category="tool-profile"
β’ target="broad-based"
β’ TA-category="Cybercrime"
β’ sub-category="infra-profile"
β’ no-samples-in="MalwareBazaar"
β’ no-samples-in="Tria.ge"
β’ action-taken="VT-comment"
πMISP Galaxies:
β’ producer="Group-IB"
β’ target-information="Algeria"
mitre-attack-pattern=[]
MISP event uuid: 7a3ded92-0934-49f2-956c-0623538fbdb6
Group-IB
Sniperβs Nest: From Brand Impersonation to Browser Hijacking and CPA Fraud
This blog provides a deep-dive into SniperDz, a centralised PhaaS platform with more than 80 ready-made phishing templates impersonating over 30 global brands, and uncovers the hidden infrastructure behind this sophisticated and highly-organized fraud ecosystem.
πTitle: Cyber-Enabled Maritime Sanctions Evasion
π Date: 2026-06-11
πReferences:
https://www.recordedfuture.com/research/media_12cb79eec13b6af7520af3c1ae6768c0f4b25e945.gif?width=1200&format=pjpg&optimize=medium
https://www.recordedfuture.com/research/cyber-maritime-sanctions-evasion
πRectifyq Taxonomies:
Relevancy: π΄ Highly Relevant
Category: β Threat
β’ mitre-att&ck="none-from-src"
β’ mitre-att&ck="from-OTX"
β’ sub-category="infra-profile"
β’ sub-category="campaign-analysis"
β’ topic="geopolitical"
β’ target="broad-based"
β’ no-samples-in="MalwareBazaar"
β’ no-samples-in="Tria.ge"
β’ action-taken="VT-comment"
πMISP Galaxies:
β’ producer="Recorded Future"
mitre-attack-pattern=[]
MISP event uuid: 64d4b916-e459-44a4-80d0-636de8f9c850
π Date: 2026-06-11
πReferences:
https://www.recordedfuture.com/research/media_12cb79eec13b6af7520af3c1ae6768c0f4b25e945.gif?width=1200&format=pjpg&optimize=medium
https://www.recordedfuture.com/research/cyber-maritime-sanctions-evasion
πRectifyq Taxonomies:
Relevancy: π΄ Highly Relevant
Category: β Threat
β’ mitre-att&ck="none-from-src"
β’ mitre-att&ck="from-OTX"
β’ sub-category="infra-profile"
β’ sub-category="campaign-analysis"
β’ topic="geopolitical"
β’ target="broad-based"
β’ no-samples-in="MalwareBazaar"
β’ no-samples-in="Tria.ge"
β’ action-taken="VT-comment"
πMISP Galaxies:
β’ producer="Recorded Future"
mitre-attack-pattern=[]
MISP event uuid: 64d4b916-e459-44a4-80d0-636de8f9c850
πTitle: Threat Actors Target FIFA World Cup 2026
π Date: 2026-06-11
πReferences:
https://www.cloudsek.com/blog/chinese-origin-threat-actors-target-fifa-world-cup-2026
πRectifyq Taxonomies:
Relevancy: π΅ Potentially Relevant
Category: β Threat
β’ mitre-att&ck="none-from-src"
β’ mitre-att&ck="from-OTX"
β’ sub-category="campaign-analysis"
β’ TA-category="Cybercrime"
β’ target="broad-based"
β’ no-samples-in="MalwareBazaar"
β’ no-samples-in="Tria.ge"
β’ action-taken="VT-comment"
πMISP Galaxies:
β’ producer="CloudSEK"
β’ country="china"
mitre-attack-pattern=['T1557', 'T1583', 'T1539', 'T1114', 'T1566.002', 'T1586.002', 'T1583.001', 'T1589', 'T1185', 'T1557.001', 'T1589.002', 'T1584', 'T1586', 'T1590', 'T1566', 'T1110', 'T1078', 'T1589.001', 'T1598', 'T1590.001']
MISP event uuid: 1bbbb25e-72ad-415c-b7ef-5710bea4bb60
π Date: 2026-06-11
πReferences:
https://www.cloudsek.com/blog/chinese-origin-threat-actors-target-fifa-world-cup-2026
πRectifyq Taxonomies:
Relevancy: π΅ Potentially Relevant
Category: β Threat
β’ mitre-att&ck="none-from-src"
β’ mitre-att&ck="from-OTX"
β’ sub-category="campaign-analysis"
β’ TA-category="Cybercrime"
β’ target="broad-based"
β’ no-samples-in="MalwareBazaar"
β’ no-samples-in="Tria.ge"
β’ action-taken="VT-comment"
πMISP Galaxies:
β’ producer="CloudSEK"
β’ country="china"
mitre-attack-pattern=['T1557', 'T1583', 'T1539', 'T1114', 'T1566.002', 'T1586.002', 'T1583.001', 'T1589', 'T1185', 'T1557.001', 'T1589.002', 'T1584', 'T1586', 'T1590', 'T1566', 'T1110', 'T1078', 'T1589.001', 'T1598', 'T1590.001']
MISP event uuid: 1bbbb25e-72ad-415c-b7ef-5710bea4bb60
Cloudsek
Chinese Origin Threat Actors Target FIFA World Cup 2026 | CloudSEK
As the FIFA World Cup 2026 begins, a highly sophisticated, Chinese-origin threat operation is targeting global football fans. Utilizing pixel-perfect website clones, a multi-tenant reseller network, and an active Man-in-the-Middle framework, these actorsβ¦
πTitle: Threat Actors Weaponize AI Hype to Deliver AsyncRAT
π Date: 2026-06-11
πReferences:
https://www.fortinet.com/blog/threat-research/threat-actors-weaponize-ai-hype-to-deliver-asyncrat
πRectifyq Taxonomies:
Relevancy: π΅ Potentially Relevant
Category: β Threat
β’ mitre-att&ck="none-from-src"
β’ mitre-att&ck="from-OTX"
β’ sub-category="malware-analysis"
β’ sub-category="campaign-analysis"
β’ topic="ai"
β’ target="broad-based"
β’ no-samples-in="MalwareBazaar"
β’ no-samples-in="Tria.ge"
β’ action-taken="VT-comment"
πMISP Galaxies:
β’ producer="Fortinet"
β’ malpedia="AsyncRAT"
mitre-attack-pattern=['T1053.005', 'T1113', 'T1218.011', 'T1573.001', 'T1082', 'T1106', 'T1140', 'T1112', 'T1497', 'T1204', 'T1059.001', 'T1566', 'T1562.001', 'T1055.012', 'T1027', 'T1059.003', 'T1070.004', 'T1071.001', 'T1059.005']
MISP event uuid: a72101e4-904d-4526-b9e3-6e902513f24b
π Date: 2026-06-11
πReferences:
https://www.fortinet.com/blog/threat-research/threat-actors-weaponize-ai-hype-to-deliver-asyncrat
πRectifyq Taxonomies:
Relevancy: π΅ Potentially Relevant
Category: β Threat
β’ mitre-att&ck="none-from-src"
β’ mitre-att&ck="from-OTX"
β’ sub-category="malware-analysis"
β’ sub-category="campaign-analysis"
β’ topic="ai"
β’ target="broad-based"
β’ no-samples-in="MalwareBazaar"
β’ no-samples-in="Tria.ge"
β’ action-taken="VT-comment"
πMISP Galaxies:
β’ producer="Fortinet"
β’ malpedia="AsyncRAT"
mitre-attack-pattern=['T1053.005', 'T1113', 'T1218.011', 'T1573.001', 'T1082', 'T1106', 'T1140', 'T1112', 'T1497', 'T1204', 'T1059.001', 'T1566', 'T1562.001', 'T1055.012', 'T1027', 'T1059.003', 'T1070.004', 'T1071.001', 'T1059.005']
MISP event uuid: a72101e4-904d-4526-b9e3-6e902513f24b
Fortinet Blog
Threat Actors Weaponize AI Hype to Deliver AsyncRAT
FortiGuard Labs analyzes a multi-stage malware campaign that uses fake AI-themed documents, hidden PowerShell scripts, AutoHotkey loaders, and process injection to deploy AsyncRAT and maintain remoβ¦
πTitle: How Lookalike Domains Exploit Human Judgment
π Date: 2026-06-11
πReferences:
https://www.infoblox.com/blog/security/human-judgment-hacks-how-lookalike-domains-work/
πRectifyq Taxonomies:
Relevancy: π΅ Potentially Relevant
Category: β Threat
β’ mitre-att&ck="none-from-src"
β’ mitre-att&ck="from-OTX"
β’ sub-category="campaign-analysis"
β’ sub-category="report"
β’ target="broad-based"
β’ no-samples-in="MalwareBazaar"
β’ no-samples-in="Tria.ge"
β’ action-taken="VT-comment"
πMISP Galaxies:
β’ producer="Infoblox"
mitre-attack-pattern=['T1583', 'T1071.004', 'T1204.002', 'T1566.002', 'T1598.003', 'T1071', 'T1586.002', 'T1583.001', 'T1589', 'T1589.002', 'T1584', 'T1586', 'T1598.002', 'T1204', 'T1590', 'T1566', 'T1598', 'T1590.001', 'T1204.001', 'T1584.001']
MISP event uuid: 833736e2-fc4c-4f68-ab29-b048c427c6ee
π Date: 2026-06-11
πReferences:
https://www.infoblox.com/blog/security/human-judgment-hacks-how-lookalike-domains-work/
πRectifyq Taxonomies:
Relevancy: π΅ Potentially Relevant
Category: β Threat
β’ mitre-att&ck="none-from-src"
β’ mitre-att&ck="from-OTX"
β’ sub-category="campaign-analysis"
β’ sub-category="report"
β’ target="broad-based"
β’ no-samples-in="MalwareBazaar"
β’ no-samples-in="Tria.ge"
β’ action-taken="VT-comment"
πMISP Galaxies:
β’ producer="Infoblox"
mitre-attack-pattern=['T1583', 'T1071.004', 'T1204.002', 'T1566.002', 'T1598.003', 'T1071', 'T1586.002', 'T1583.001', 'T1589', 'T1589.002', 'T1584', 'T1586', 'T1598.002', 'T1204', 'T1590', 'T1566', 'T1598', 'T1590.001', 'T1204.001', 'T1584.001']
MISP event uuid: 833736e2-fc4c-4f68-ab29-b048c427c6ee
Infoblox Blog
Deceiving Humans: How Lookalike Domains Exploit Human Judgment
Learn how lookalike domains exploit human judgment, trust and perception to bypass security controls, and how DNS reveals attacker intent.
Rectifyq Cybersecurity News π²πΎ pinned Β«πTitle: Cyber-Enabled Maritime Sanctions Evasion π
Date: 2026-06-11 πReferences: https://www.recordedfuture.com/research/media_12cb79eec13b6af7520af3c1ae6768c0f4b25e945.gif?width=1200&format=pjpg&optimize=medium https://www.recordedfuture.com/research/cyberβ¦Β»
πTitle: Affidavit in Support of Application for Criminal Complaint
π Date: 2026-06-09
πReferences:
https://cyberscoop.com/wp-content/uploads/sites/3/2026/06/11-1.pdf
πRectifyq Taxonomies:
Relevancy: π΅ Potentially Relevant
Category: β Threat
β’ mitre-att&ck="none-from-src"
β’ mitre-att&ck="from-OTX"
β’ sub-category="TA-profile"
β’ sub-category="report"
β’ target="broad-based"
β’ topic="geopolitical"
β’ TA-category="APT"
β’ no-samples-in="MalwareBazaar"
β’ no-samples-in="Tria.ge"
β’ action-taken="VT-comment"
πMISP Galaxies:
β’ target-information="United States"
β’ threat-actor="Void Blizzard"
mitre-attack-pattern=['T1133', 'T1114', 'T1071', 'T1562', 'T1567', 'T1589', 'T1185', 'T1090', 'T1020', 'T1588.001', 'T1070', 'T1586', 'T1590', 'T1048', 'T1588.002', 'T1566', 'T1078', 'T1573', 'T1598', 'T1213']
MISP event uuid: 48a8d13e-0e7e-4d6f-8807-d4d9761dc8b5
π Date: 2026-06-09
πReferences:
https://cyberscoop.com/wp-content/uploads/sites/3/2026/06/11-1.pdf
πRectifyq Taxonomies:
Relevancy: π΅ Potentially Relevant
Category: β Threat
β’ mitre-att&ck="none-from-src"
β’ mitre-att&ck="from-OTX"
β’ sub-category="TA-profile"
β’ sub-category="report"
β’ target="broad-based"
β’ topic="geopolitical"
β’ TA-category="APT"
β’ no-samples-in="MalwareBazaar"
β’ no-samples-in="Tria.ge"
β’ action-taken="VT-comment"
πMISP Galaxies:
β’ target-information="United States"
β’ threat-actor="Void Blizzard"
mitre-attack-pattern=['T1133', 'T1114', 'T1071', 'T1562', 'T1567', 'T1589', 'T1185', 'T1090', 'T1020', 'T1588.001', 'T1070', 'T1586', 'T1590', 'T1048', 'T1588.002', 'T1566', 'T1078', 'T1573', 'T1598', 'T1213']
MISP event uuid: 48a8d13e-0e7e-4d6f-8807-d4d9761dc8b5
πTitle: Defending the Digital Pitch: World Cup 2026 Cyber Threats
π Date: 2026-06-11
πReferences:
https://www.cyberproof.com/blog/defending-the-digital-pitch-world-cup-2026-cyber-threats/
πRectifyq Taxonomies:
Relevancy: π΅ Potentially Relevant
Category: β Threat
β’ mitre-att&ck="none-from-src"
β’ mitre-att&ck="from-OTX"
β’ sub-category="campaign-analysis"
β’ target="broad-based"
β’ no-samples-in="MalwareBazaar"
β’ no-samples-in="Tria.ge"
β’ action-taken="VT-comment"
πMISP Galaxies:
mitre-attack-pattern=['T1557', 'T1583', 'T1539', 'T1566.002', 'T1190', 'T1583.001', 'T1589', 'T1185', 'T1588.001', 'T1586', 'T1528', 'T1204', 'T1199', 'T1566', 'T1110', 'T1078', 'T1499', 'T1598', 'T1189', 'T1498']
MISP event uuid: 1708688e-6ab1-4949-83be-1fe8e61d59e3
π Date: 2026-06-11
πReferences:
https://www.cyberproof.com/blog/defending-the-digital-pitch-world-cup-2026-cyber-threats/
πRectifyq Taxonomies:
Relevancy: π΅ Potentially Relevant
Category: β Threat
β’ mitre-att&ck="none-from-src"
β’ mitre-att&ck="from-OTX"
β’ sub-category="campaign-analysis"
β’ target="broad-based"
β’ no-samples-in="MalwareBazaar"
β’ no-samples-in="Tria.ge"
β’ action-taken="VT-comment"
πMISP Galaxies:
mitre-attack-pattern=['T1557', 'T1583', 'T1539', 'T1566.002', 'T1190', 'T1583.001', 'T1589', 'T1185', 'T1588.001', 'T1586', 'T1528', 'T1204', 'T1199', 'T1566', 'T1110', 'T1078', 'T1499', 'T1598', 'T1189', 'T1498']
MISP event uuid: 1708688e-6ab1-4949-83be-1fe8e61d59e3
CyberProof
Defending the Digital Pitch: World Cup 2026 Cyber Threats
Contributors: Amit Gini, Tom Saar, Liora Ziv Introduction Kicking off today, the 2026 FIFA World Cup is expected to be one of the largest and most
πTitle: World Cup 2026 Mobile Targeted Phishing: The Global Social Engineering Threat
π Date: 2026-06-11
πReferences:
https://zimperium.com/blog/world-cup-2026-mobile-targeted-phishing-the-global-social-engineering-threat?hs_amp=true
πRectifyq Taxonomies:
Relevancy: π΅ Potentially Relevant
Category: β Threat
β’ mitre-att&ck="none-from-src"
β’ mitre-att&ck="from-OTX"
β’ sub-category="campaign-analysis"
β’ topic="mobile-attack"
β’ target="broad-based"
β’ no-samples-in="MalwareBazaar"
β’ no-samples-in="Tria.ge"
β’ action-taken="VT-comment"
πMISP Galaxies:
β’ producer="Zimperium"
mitre-attack-pattern=['T1539', 'T1114', 'T1566.002', 'T1598.003', 'T1566.001', 'T1586.002', 'T1608.001', 'T1583.001', 'T1589', 'T1185', 'T1056.003', 'T1589.002', 'T1608.005', 'T1528', 'T1566', 'T1056', 'T1589.001', 'T1598', 'T1204.001']
MISP event uuid: 2d22208a-0035-4f4c-8dfd-a7b056feab82
π Date: 2026-06-11
πReferences:
https://zimperium.com/blog/world-cup-2026-mobile-targeted-phishing-the-global-social-engineering-threat?hs_amp=true
πRectifyq Taxonomies:
Relevancy: π΅ Potentially Relevant
Category: β Threat
β’ mitre-att&ck="none-from-src"
β’ mitre-att&ck="from-OTX"
β’ sub-category="campaign-analysis"
β’ topic="mobile-attack"
β’ target="broad-based"
β’ no-samples-in="MalwareBazaar"
β’ no-samples-in="Tria.ge"
β’ action-taken="VT-comment"
πMISP Galaxies:
β’ producer="Zimperium"
mitre-attack-pattern=['T1539', 'T1114', 'T1566.002', 'T1598.003', 'T1566.001', 'T1586.002', 'T1608.001', 'T1583.001', 'T1589', 'T1185', 'T1056.003', 'T1589.002', 'T1608.005', 'T1528', 'T1566', 'T1056', 'T1589.001', 'T1598', 'T1204.001']
MISP event uuid: 2d22208a-0035-4f4c-8dfd-a7b056feab82
Zimperium
World Cup 2026 Mobile Targeted Phishing: The Global Social Engineering Threat
true
πTitle: Targets Education Sector with Oracle PeopleSoft Exploit
π Date: 2026-06-11
πReferences:
https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit
πRectifyq Taxonomies:
Relevancy: π΅ Potentially Relevant
Category: β Threat
β’ mitre-att&ck="from-OTX"
β’ sub-category="campaign-analysis"
β’ TA-category="Cybercrime"
β’ target="broad-based"
β’ mitre-att&ck="none-from-src"
β’ no-samples-in="MalwareBazaar"
β’ samples-found-in="Tria.ge"
β’ action-taken="VT-comment"
πMISP Galaxies:
β’ producer="Mandiant"
β’ target-information="United States"
β’ sector="Education"
β’ threat-actor="ShinyHunters"
mitre-attack-pattern=['T1560.001', 'T1110.001', 'T1133', 'T1069', 'T1114', 'T1036.005', 'T1021.004', 'T1190', 'T1491', 'T1505.003', 'T1083', 'T1552.001', 'T1041', 'T1059.004', 'T1078', 'T1027', 'T1486', 'T1573.002', 'T1071.001', 'T1018']
MISP event uuid: 612a10dd-f897-4556-ab31-f50a1b128318
π Date: 2026-06-11
πReferences:
https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit
πRectifyq Taxonomies:
Relevancy: π΅ Potentially Relevant
Category: β Threat
β’ mitre-att&ck="from-OTX"
β’ sub-category="campaign-analysis"
β’ TA-category="Cybercrime"
β’ target="broad-based"
β’ mitre-att&ck="none-from-src"
β’ no-samples-in="MalwareBazaar"
β’ samples-found-in="Tria.ge"
β’ action-taken="VT-comment"
πMISP Galaxies:
β’ producer="Mandiant"
β’ target-information="United States"
β’ sector="Education"
β’ threat-actor="ShinyHunters"
mitre-attack-pattern=['T1560.001', 'T1110.001', 'T1133', 'T1069', 'T1114', 'T1036.005', 'T1021.004', 'T1190', 'T1491', 'T1505.003', 'T1083', 'T1552.001', 'T1041', 'T1059.004', 'T1078', 'T1027', 'T1486', 'T1573.002', 'T1071.001', 'T1018']
MISP event uuid: 612a10dd-f897-4556-ab31-f50a1b128318
Google Cloud Blog
ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit | Google Cloud Blog
An active compromise and extortion campaign attributed to ShinyHunters targeting Oracle PeopleSoft with a zero-day exploit.
πTitle: UNC1151/Ghostwriter phishing campaign targeting Gmail accounts
π Date: 2026-06-12
πReferences:
https://cert.pl/en/posts/2026/06/UNC1151-gmail-campaign/
πRectifyq Taxonomies:
Relevancy: π΅ Potentially Relevant
Category: β Threat
β’ mitre-att&ck="none-from-src"
β’ mitre-att&ck="from-OTX"
β’ sub-category="campaign-analysis"
β’ TA-category="APT"
β’ target="broad-based"
β’ no-samples-in="MalwareBazaar"
β’ no-samples-in="Tria.ge"
β’ action-taken="VT-comment"
πMISP Galaxies:
β’ target-information="Poland"
β’ threat-actor="Ghostwriter"
mitre-attack-pattern=['T1566']
MISP event uuid: 5c1e7285-f735-49d8-9fcf-ef31d47b10ae
π Date: 2026-06-12
πReferences:
https://cert.pl/en/posts/2026/06/UNC1151-gmail-campaign/
πRectifyq Taxonomies:
Relevancy: π΅ Potentially Relevant
Category: β Threat
β’ mitre-att&ck="none-from-src"
β’ mitre-att&ck="from-OTX"
β’ sub-category="campaign-analysis"
β’ TA-category="APT"
β’ target="broad-based"
β’ no-samples-in="MalwareBazaar"
β’ no-samples-in="Tria.ge"
β’ action-taken="VT-comment"
πMISP Galaxies:
β’ target-information="Poland"
β’ threat-actor="Ghostwriter"
mitre-attack-pattern=['T1566']
MISP event uuid: 5c1e7285-f735-49d8-9fcf-ef31d47b10ae
cert.pl
UNC1151/Ghostwriter phishing campaign targeting Gmail accounts
Recently, we have been observing attacks by the UNC1151/Ghostwriter group targeting Gmail accounts. This group has been regularly attacking the mailboxes of Polish citizens for several years, although in the past these attacks focused on other email providers.β¦
πTitle: How to defend ARM64 cloud infrastructure
π Date: 2026-06-11
πReferences:
https://www.reversinglabs.com/blog/defend-cloud-infrastructure-itscape
πRectifyq Taxonomies:
Relevancy: π΅ Potentially Relevant
Category: π Vulnerability
β’ mitre-att&ck="none-from-src"
β’ mitre-att&ck="from-OTX"
β’ sub-category="campaign-analysis"
β’ sub-category="critical-vuln"
β’ target="broad-based"
β’ topic="cloud"
β’ no-samples-in="MalwareBazaar"
β’ no-samples-in="Tria.ge"
β’ action-taken="VT-comment"
πMISP Galaxies:
mitre-attack-pattern=['T1592', 'T1082', 'T1005', 'T1611', 'T1610', 'T1548', 'T1059', 'T1609', 'T1204', 'T1068']
MISP event uuid: b91d23b7-24fc-4cac-87d6-d5dc6b6bfd67
π Date: 2026-06-11
πReferences:
https://www.reversinglabs.com/blog/defend-cloud-infrastructure-itscape
πRectifyq Taxonomies:
Relevancy: π΅ Potentially Relevant
Category: π Vulnerability
β’ mitre-att&ck="none-from-src"
β’ mitre-att&ck="from-OTX"
β’ sub-category="campaign-analysis"
β’ sub-category="critical-vuln"
β’ target="broad-based"
β’ topic="cloud"
β’ no-samples-in="MalwareBazaar"
β’ no-samples-in="Tria.ge"
β’ action-taken="VT-comment"
πMISP Galaxies:
mitre-attack-pattern=['T1592', 'T1082', 'T1005', 'T1611', 'T1610', 'T1548', 'T1059', 'T1609', 'T1204', 'T1068']
MISP event uuid: b91d23b7-24fc-4cac-87d6-d5dc6b6bfd67
ReversingLabs
How to defend ARM64 cloud infrastructure from ITScape | RL Blog
RL has documented CVE-2026-46316, and developed two YARA rules to help detect exploits of the multi-tenant cloud vulnerability.