@_rectifyqi
iAccount based inMalaysia!
About this account
- Account based in
- Malaysia
- Connected via
- Malaysia Android App
! X says this location may be affected by a proxy or VPN.
Account-level information from X, not a live location or the device used for a specific post.
Threat I̶n̶t̶e̶l̶l̶i̶g̶e̶n̶c̶e̶ ̶ Information focusing on Malaysia 🇲🇾
Joined May 2024
- Tweets1.2K
- Following686
- Followers841
- Likes4.1K
Pinned Tweet
README
4 Categories
[Threat] [Data Breach] [Event] [Report]
Relevancy in 🇲🇾 context.
🔴- Highly relevant. e.g. APT target 🇲🇾.
🟡- Somewhat relevant. e.g. APT target Asian country.
🔵- Potentially relevant. e.g. Infostealers impact globally.
⚫ - Good to know only.
Rectifyq retweeted
We investigated a Windows malware delivery chain beginning with a ZIP archive delivered through WhatsApp targeting Malaysian.
research.pelagos-intel.com/s…
Similar campaign to
threads.com/share/BAXLi6MjXF…
Rectifyq retweeted
GLOBAL PREVENTIVE ALERT 🌐 🇨🇱 🇧🇷 🇲🇾 🇮🇩 🇰🇪 🇮🇳: MASS EXPOSURE OF ADMINISTRATIVE ACCESS
[STATUS: UNCONFIRMED / SOURCE: CYBER INTELLIGENCE CONSOLE / DATE: SEPTEMBER 11, 2026]
CENTRALIZED CYBER INTELLIGENCE MONITORING HAS DETECTED A MASS RELEASE OF ACCESS CREDENTIALS ON CLANDESTINE TELEGRAM CHANNELS BY THREAT ACTOR D1STR1CT9619. THE LEAK CONTAINS HUNDREDS OF DOMAINS COMPROMISED VIA THE CREATION OF AN UNAUTHORIZED ADMINISTRATIVE ACCOUNT (BACKDOOR).
The attack appears to stem from an automated exploitation campaign (possibly targeting vulnerabilities in content management systems like WordPress, as indicated by the filename `368x-wp_login.txt`). Across all affected domains, the actor has consistently injected or configured the username `Baby_Mushr00w`. The full scope and active exploitation of these credentials remain unconfirmed.
VECERT has not independently confirmed whether these credentials are functional; therefore, the status remains unconfirmed, and this serves as a preventive alert.
🌐 IMPACT ANALYSIS
Following an analysis of the more than 300 exposed domains, targets of high strategic criticality have been identified, spanning government entities, financial credit systems, and higher education institutions globally.
🏛️ GOVERNMENT AND DEFENSE SECTOR
🇨🇱 Chile: Directorate General of Civil Aeronautics (Aeronautical and aviation authority of the State of Chile).
🇧🇷 Brazil:— Official portal of the municipal government of Joinville, Santa Catarina.
🇮🇩 Indonesia: — Regional Development Planning Agency of the Barito Timur government.
🇻🇳 Vietnam: .vn — Binh Thuan Provincial Public Library (Public/Cultural Sector).
🏦 CRITICAL FINANCIAL AND CORPORATE SECTOR
🇲🇾 Malaysia — CTOS Digital, Malaysia's largest consumer and corporate credit reporting agency (High risk of PII and financial data compromise).
🎓 HIGHER EDUCATION SECTOR
🇰🇪 Kenya:— Kenyatta University (One of the country's largest public universities).
🇮🇩 Indonesia (Multiple): (Diponegoro University), (Ahmad Dahlan University).
🇮🇳 India: — Sri Ramakrishna Polytechnic College.
🛡️ TECHNICAL PREVENTIVE AND CONTAINMENT RECOMMENDATIONS (SOC / HARDENING)
Rogue User Search and Eradication (Threat Hunting):
Immediately inspect CMS databases (e.g., the `wp_users` table in WordPress) for the user `Baby_Mushr00w`. Delete the account immediately and purge any active sessions or linked authentication tokens.
Access Log Audit (Access/Error Logs):
Review web server logs (Nginx/Apache) for HTTP POST requests to administrative endpoints (`/wp-login.php`, `/wp-admin/`, `/administrator/`) that coincide with the date of compromise or show evidence of login attempts using the reported username.
Initial Breach Remediation:
Simply deleting the user does not close the security gap. Source code must be audited using vulnerability scanning tools to identify the exploited plugin or theme. Temporarily restrict access to the admin panel using geo-blocking or IP filtering rules on the WAF/perimeter firewall.
🖥️ CENTRALIZED THREAT MONITORING SYSTEM
Intelligence System: analyzer.vecert.io
Monitoring Console: monitor.vecert.io
#Cybersecurity #DataLeak #AdminPanel #WordPress #D1STR1CT9619 #BabyMushr00w #ThreatIntel #InfoSec #CyberAlert #VECERT #SOC #CSIRT #Unconfirmed #TelegramLeaks #SecurityAlert #OSINT #CyberCrime #GovSecurity #FinSec
Rectifyq retweeted
anthropic.com/threat-intelli…
Malaysia mentioned...
Rectifyq retweeted
🇲🇾 20GB OF MALAYSIA LITTORAL COMBAT SHIP DOCUMENTS ADVERTISED FOR SALE
A threat actor is advertising what they claim is a 20GB collection of documents related to Malaysia’s Littoral Combat Ship (LCS) program.
The seller claims the material was extracted last year and contains approximately 30,000 PDF files dating from 2014 through 2025.
According to the listing, the collection includes:
* Factory Acceptance Test (FAT) records
* Calculation reports
* Technical drawings
* Additional engineering/project documentation
* Approximately 30,000 files / 20GB total
The entire collection is being offered for just $500 in cryptocurrency.
⚠️ Analyst Note:
This claim deserves attention because the advertised material is not simply personal or corporate data, it allegedly includes technical documentation associated with a national naval procurement program.
If authentic, engineering drawings, test records and calculation reports could expose sensitive information about system design, specifications, testing and the defense supply chain.
The provenance, authenticity and sensitivity of the advertised documents have not been independently verified.
#DDW #DarkWeb #Malaysia #CyberSecurity
Rectifyq retweeted
🇲🇾 MISI RAKYAT DATABASE ALLEGEDLY FOR SALE — 300K+ CUSTOMERS
A threat actor is offering what they claim is a database belonging to Misi Rakyat, a Malaysian platform associated with the Misi Delivery ecosystem.
The seller claims the data is current as of September 7, 2026 and includes:
* 300,518 customer records — names, usernames, emails, phone numbers, addresses and location coordinates
* 22,508 rider records — identity details, IC numbers, vehicle/license information, addresses and alleged current GPS locations
* 28,562 vendor records — business and contact information, bank details and addresses
* E-wallet transaction data — actor claims approximately 1.88 million transactions
⚠️ Analyst Note:
The most concerning element is the alleged combination of identity, financial and precise location data. If authentic, rider GPS information and customer/vendor coordinates could introduce risks beyond conventional identity theft, including targeted phishing, fraud and physical-security concerns.
The dataset size, freshness and provenance remain threat-actor claims and have not been independently verified.
#DDW #DarkWeb #Malaysia #DataBreach
Rectifyq retweeted
MyCERT issued an advisory about a fake website that silently infects #iPhone simply by opening the page in Safari.
mycert.org.my/portal/details…
Here is a CTI report on the fake site and the multi-stage #Coruna & #DarkSword iOS exploitation chain.
github.com/douglasmun/Dougla…
Rectifyq retweeted
Threat actor SilverFox is hiding malware inside ISO/IMG files and compressed into zip file. When opened, Windows auto-mounts the image as a virtual CD-ROM, bypassing MotW/perimeter controls to deliver the malicious payloads
3108 CTF · Warisan Takhta 🇲🇾
Date: 29 Aug 2026 23:00
Fees: Free
Category: Open to All (Seats Limited)
Organizer: Bahtera Siber
Link: ctf.bahterasiber.my/
Location: Online
MAWAR (Malam Wayang) ; rawSEC x Fortinet 🇲🇾
Date: 28 Aug 2026 20:00
Fees: Refundable Deposit
Category: Open to All (Seats Limited)
Organizer: rawSEC
Link: mcco.org.my/events/mawar-raw…
Location: GSC Mid Valley, Kuala Lumpur
SherpaSec X BlackBerry CCoE August Cybersecurity Industrial Visit 🇲🇾
Date: 28 Aug 2026 14:00
Fees: Free
Category: Open to All (Seats Limited)
Organizer: SherpaSec X BlackBerry
Link: luma.com/1ywucdsc
Location: Blackberry CCoE
OffSec Malaysia Chapter 4th Meetup: MCP: The New Frontier of AI Security 🇲🇾
Date: 28 Aug 2026 18:00
Fees: Free
Category: Open to All (Seats Limited)
Organizer: OffSec Malaysia Chapter
Link: oxidized-root-d90.notion.sit…
Location:Auditorium Library, UNITEN Putrajaya
Rectifyq retweeted
🇲🇾 Malaysia: Student & Teacher Data from SMK Bandar Saujana Utama (2) Allegedly Leaked
A threat actor claims to have leaked data belonging to more than 1,000 students and teachers associated with SMK Bandar Saujana Utama (2), a Malaysian secondary school.
According to the underground forum post:
* More than 1,000 student and teacher records are allegedly affected
* Full names are reportedly included
* Malaysian identification/IC numbers are allegedly exposed
* School email addresses are included
* Class information is reportedly present
* Password fields appear in the published sample
* Data is reportedly structured in JSON format
* The actor claims additional, more detailed information may be released later
⚠️ The alleged exposure is particularly concerning because the dataset appears to involve students and may contain government-issued identification numbers alongside account credentials.
🔎 Analyst Note: This is currently an unverified threat-actor claim observed on an underground forum. A purported sample has been published, but DDW has not independently verified the records, the number of affected individuals, how the information was obtained, or whether the data originated directly from the school's systems.
#DDW #DarkWeb #Malaysia #Education #DataLeak #DataBreach #CyberSecurity #ThreatIntelligence #OSINT
Replying to @_rectifyq
Throwing some fun fact here re wargames.my. wgmy used to be an online CTF for pre HITB event. The last was in 2012. After 2 years of hiatus, me and some CTF-fans received the baton to continue the legacy 😁
Rectifyq retweeted
CFP is now open.
linkedin.com/feed/update/urn…
Rectifyq retweeted
Thanks for the shoutout!
Check out our upcoming new experiiment RE:BOOT 🔥
Uni juniors asked me about the history of the CTF we used to organize back then. Realized I didn't even know the full timeline myself haha.
So I did a bit of diggin, asked AI to help spin up a dashboard, and mapped out the local scene: ctf.rectifyq.com
Uni juniors asked me about the history of the CTF we used to organize back then. Realized I didn't even know the full timeline myself haha.
So I did a bit of diggin, asked AI to help spin up a dashboard, and mapped out the local scene: ctf.rectifyq.com
Wrote a quick Medium post covering my thought process of doing this:
medium.com/@rectifyq/how-big…