@_rectifyq

Threat I̶n̶t̶e̶l̶l̶i̶g̶e̶n̶c̶e̶ ̶ Information focusing on Malaysia 🇲🇾

Joined May 2024
README 4 Categories [Threat] [Data Breach] [Event] [Report] Relevancy in 🇲🇾 context. 🔴- Highly relevant. e.g. APT target 🇲🇾. 🟡- Somewhat relevant. e.g. APT target Asian country. 🔵- Potentially relevant. e.g. Infostealers impact globally. ⚫ - Good to know only.
1
7
11
6,606
We investigated a Windows malware delivery chain beginning with a ZIP archive delivered through WhatsApp targeting Malaysian. research.pelagos-intel.com/s… Similar campaign to threads.com/share/BAXLi6MjXF…
5
79
3
161
9,950
GLOBAL PREVENTIVE ALERT 🌐 🇨🇱 🇧🇷 🇲🇾 🇮🇩 🇰🇪 🇮🇳: MASS EXPOSURE OF ADMINISTRATIVE ACCESS [STATUS: UNCONFIRMED / SOURCE: CYBER INTELLIGENCE CONSOLE / DATE: SEPTEMBER 11, 2026] CENTRALIZED CYBER INTELLIGENCE MONITORING HAS DETECTED A MASS RELEASE OF ACCESS CREDENTIALS ON CLANDESTINE TELEGRAM CHANNELS BY THREAT ACTOR D1STR1CT9619. THE LEAK CONTAINS HUNDREDS OF DOMAINS COMPROMISED VIA THE CREATION OF AN UNAUTHORIZED ADMINISTRATIVE ACCOUNT (BACKDOOR). The attack appears to stem from an automated exploitation campaign (possibly targeting vulnerabilities in content management systems like WordPress, as indicated by the filename `368x-wp_login.txt`). Across all affected domains, the actor has consistently injected or configured the username `Baby_Mushr00w`. The full scope and active exploitation of these credentials remain unconfirmed. VECERT has not independently confirmed whether these credentials are functional; therefore, the status remains unconfirmed, and this serves as a preventive alert. 🌐 IMPACT ANALYSIS Following an analysis of the more than 300 exposed domains, targets of high strategic criticality have been identified, spanning government entities, financial credit systems, and higher education institutions globally. 🏛️ GOVERNMENT AND DEFENSE SECTOR 🇨🇱 Chile: Directorate General of Civil Aeronautics (Aeronautical and aviation authority of the State of Chile). 🇧🇷 Brazil:— Official portal of the municipal government of Joinville, Santa Catarina. 🇮🇩 Indonesia: — Regional Development Planning Agency of the Barito Timur government. 🇻🇳 Vietnam: .vn — Binh Thuan Provincial Public Library (Public/Cultural Sector). 🏦 CRITICAL FINANCIAL AND CORPORATE SECTOR 🇲🇾 Malaysia — CTOS Digital, Malaysia's largest consumer and corporate credit reporting agency (High risk of PII and financial data compromise). 🎓 HIGHER EDUCATION SECTOR 🇰🇪 Kenya:— Kenyatta University (One of the country's largest public universities). 🇮🇩 Indonesia (Multiple): (Diponegoro University), (Ahmad Dahlan University). 🇮🇳 India: — Sri Ramakrishna Polytechnic College. 🛡️ TECHNICAL PREVENTIVE AND CONTAINMENT RECOMMENDATIONS (SOC / HARDENING) Rogue User Search and Eradication (Threat Hunting): Immediately inspect CMS databases (e.g., the `wp_users` table in WordPress) for the user `Baby_Mushr00w`. Delete the account immediately and purge any active sessions or linked authentication tokens. Access Log Audit (Access/Error Logs): Review web server logs (Nginx/Apache) for HTTP POST requests to administrative endpoints (`/wp-login.php`, `/wp-admin/`, `/administrator/`) that coincide with the date of compromise or show evidence of login attempts using the reported username. Initial Breach Remediation: Simply deleting the user does not close the security gap. Source code must be audited using vulnerability scanning tools to identify the exploited plugin or theme. Temporarily restrict access to the admin panel using geo-blocking or IP filtering rules on the WAF/perimeter firewall. 🖥️ CENTRALIZED THREAT MONITORING SYSTEM Intelligence System: analyzer.vecert.io Monitoring Console: monitor.vecert.io #Cybersecurity #DataLeak #AdminPanel #WordPress #D1STR1CT9619 #BabyMushr00w #ThreatIntel #InfoSec #CyberAlert #VECERT #SOC #CSIRT #Unconfirmed #TelegramLeaks #SecurityAlert #OSINT #CyberCrime #GovSecurity #FinSec
2
9
29
6,131
🇲🇾 20GB OF MALAYSIA LITTORAL COMBAT SHIP DOCUMENTS ADVERTISED FOR SALE A threat actor is advertising what they claim is a 20GB collection of documents related to Malaysia’s Littoral Combat Ship (LCS) program. The seller claims the material was extracted last year and contains approximately 30,000 PDF files dating from 2014 through 2025. According to the listing, the collection includes: * Factory Acceptance Test (FAT) records * Calculation reports * Technical drawings * Additional engineering/project documentation * Approximately 30,000 files / 20GB total The entire collection is being offered for just $500 in cryptocurrency. ⚠️ Analyst Note: This claim deserves attention because the advertised material is not simply personal or corporate data, it allegedly includes technical documentation associated with a national naval procurement program. If authentic, engineering drawings, test records and calculation reports could expose sensitive information about system design, specifications, testing and the defense supply chain. The provenance, authenticity and sensitivity of the advertised documents have not been independently verified. #DDW #DarkWeb #Malaysia #CyberSecurity
7
87
28
227
38,342
🇲🇾 MISI RAKYAT DATABASE ALLEGEDLY FOR SALE — 300K+ CUSTOMERS A threat actor is offering what they claim is a database belonging to Misi Rakyat, a Malaysian platform associated with the Misi Delivery ecosystem. The seller claims the data is current as of September 7, 2026 and includes: * 300,518 customer records — names, usernames, emails, phone numbers, addresses and location coordinates * 22,508 rider records — identity details, IC numbers, vehicle/license information, addresses and alleged current GPS locations * 28,562 vendor records — business and contact information, bank details and addresses * E-wallet transaction data — actor claims approximately 1.88 million transactions ⚠️ Analyst Note: The most concerning element is the alleged combination of identity, financial and precise location data. If authentic, rider GPS information and customer/vendor coordinates could introduce risks beyond conventional identity theft, including targeted phishing, fraud and physical-security concerns. The dataset size, freshness and provenance remain threat-actor claims and have not been independently verified. #DDW #DarkWeb #Malaysia #DataBreach
4
195
38
381
84,952
Rectifyq retweeted
MyCERT issued an advisory about a fake website that silently infects #iPhone simply by opening the page in Safari. mycert.org.my/portal/details… Here is a CTI report on the fake site and the multi-stage #Coruna & #DarkSword iOS exploitation chain. github.com/douglasmun/Dougla…
2
33
1
72
40,113
Threat actor SilverFox is hiding malware inside ISO/IMG files and compressed into zip file. When opened, Windows auto-mounts the image as a virtual CD-ROM, bypassing MotW/perimeter controls to deliver the malicious payloads
16
43
2,062
3108 CTF · Warisan Takhta 🇲🇾 Date: 29 Aug 2026 23:00 Fees: Free Category: Open to All (Seats Limited) Organizer: Bahtera Siber Link: ctf.bahterasiber.my/ Location: Online
1
9
1,350
Rectifyq retweeted
Anatomy of a macOS ClickFix Crimekit that Weaponises EtherHiding notes.netbytesec.com/2026/08…
1
25
1
51
4,702
MAWAR (Malam Wayang) ; rawSEC x Fortinet 🇲🇾 Date: 28 Aug 2026 20:00 Fees: Refundable Deposit Category: Open to All (Seats Limited) Organizer: rawSEC Link: mcco.org.my/events/mawar-raw… Location: GSC Mid Valley, Kuala Lumpur
7
525
SherpaSec X BlackBerry CCoE August Cybersecurity Industrial Visit 🇲🇾 Date: 28 Aug 2026 14:00 Fees: Free Category: Open to All (Seats Limited) Organizer: SherpaSec X BlackBerry Link: luma.com/1ywucdsc Location: Blackberry CCoE
5
388
OffSec Malaysia Chapter 4th Meetup: MCP: The New Frontier of AI Security 🇲🇾 Date: 28 Aug 2026 18:00 Fees: Free Category: Open to All (Seats Limited) Organizer: OffSec Malaysia Chapter Link: oxidized-root-d90.notion.sit… Location:Auditorium Library, UNITEN Putrajaya
2
4
357
🇲🇾 Malaysia: Student & Teacher Data from SMK Bandar Saujana Utama (2) Allegedly Leaked A threat actor claims to have leaked data belonging to more than 1,000 students and teachers associated with SMK Bandar Saujana Utama (2), a Malaysian secondary school. According to the underground forum post: * More than 1,000 student and teacher records are allegedly affected * Full names are reportedly included * Malaysian identification/IC numbers are allegedly exposed * School email addresses are included * Class information is reportedly present * Password fields appear in the published sample * Data is reportedly structured in JSON format * The actor claims additional, more detailed information may be released later ⚠️ The alleged exposure is particularly concerning because the dataset appears to involve students and may contain government-issued identification numbers alongside account credentials. 🔎 Analyst Note: This is currently an unverified threat-actor claim observed on an underground forum. A purported sample has been published, but DDW has not independently verified the records, the number of affected individuals, how the information was obtained, or whether the data originated directly from the school's systems. #DDW #DarkWeb #Malaysia #Education #DataLeak #DataBreach #CyberSecurity #ThreatIntelligence #OSINT
18
2
44
8,828
Rectifyq retweeted
Replying to @_rectifyq
Throwing some fun fact here re wargames.my. wgmy used to be an online CTF for pre HITB event. The last was in 2012. After 2 years of hiatus, me and some CTF-fans received the baton to continue the legacy 😁
3
3
5
317
Rectifyq retweeted
1
10
1
15
1,758
Rectifyq retweeted
Thanks for the shoutout! Check out our upcoming new experiiment RE:BOOT 🔥
Uni juniors asked me about the history of the CTF we used to organize back then. Realized I didn't even know the full timeline myself haha. So I did a bit of diggin, asked AI to help spin up a dashboard, and mapped out the local scene: ctf.rectifyq.com
1
2
6
402
Uni juniors asked me about the history of the CTF we used to organize back then. Realized I didn't even know the full timeline myself haha. So I did a bit of diggin, asked AI to help spin up a dashboard, and mapped out the local scene: ctf.rectifyq.com
2
5
1
22
1,639
Wrote a quick Medium post covering my thought process of doing this: medium.com/@rectifyq/how-big…
1
1
2
3,434
Anyway, fun side quest over. Need to close these 50 tabs and get back to actual work before my main priorities collapse hahaha. If you run CTFs or have writeups to share, feel free to drop a PR on the repo!
4
274