H1 2026 Malaysia Digital Threat Landscape

The half-year in brief · January to June 2026

Five angles on Malaysia's threat picture this half-year: the underground marketplace that trades access, the ransomware crews that monetise it, the credential and identity data leaking into it, the operations we tracked at first hand, and the actors circling the region. The thread through all five is that access is a traded commodity, and the public sector is where it is cheapest to acquire.

TRENDS · The half-year in three questions

Why the attacks happen, how they get in, and who takes the fire, read across all five sections.

Sorted by what drives them, the actors and campaigns of the half-year are overwhelmingly financial. The state-linked minority is small but is where capability concentrates, and a single hacktivist wave accounts for the rest.

The actors of H1 2026 by primary motivation (T.1), de-duplicated across sections.

 

SECTION 1 · Forums

The underground marketplace, where access and data are traded.

1.1 Malaysia-related posting

  • What We tracked posts where Malaysia is the primary target across the underground forums, held to a consistent rule. The monitored thread averaged about five Malaysia-focused posts a month, 27 over the half-year.

  • Why it matters Activity built from one post in January to a peak of eight a month across April and May, then eased to three in June. Malaysian organisations are a standing subject of the marketplace, not an occasional one.

  • Hallmark The trade is databases, webshells and credentials, the material that cannot be sold on legitimate platforms. The count is drawn from the threads we watch, so it understates the whole.

1.2 The BreachForums diaspora

  • What The October 2025 seizure of BreachForums splintered the biggest underground forum into a field of clones.

  • Why it matters At least thirteen domains traded under the name between January and March. The market did not slow; it changed address.

  • Hallmark Most clones closed. Two, HasanBrokers and PwnForums, made a name and stayed live, one of them losing its owner to a staff coup in May.

1.3 BIGBROTHER and government access

  • What On 10 September 2025 this actor claimed live access to 40 Malaysian government websites and publicly listed 33 of them, evidenced only by screenshots of internal portals.

  • Why it matters The access is unverified, but the market it sits in is real: government access offered as a product, admin-panel screenshots as the currency of proof.

  • Hallmark Renamed to DeadMan2000 and wiped its history in March 2026, then resurfaced in May with the same screenshot-only pattern.

 

SECTION 2 · Ransomware

The extortion economy, the loudest monetisation of access.

2.1 The shape of the half-year

  • What 33 Malaysian organisations were publicly listed on ransomware leak sites across the window, claimed by eleven different groups..

  • Why it matters January was the peak with eight victims, then activity settled into three to seven a month. A leak-site listing is a claim, not a confirmed compromise, so the count is a floor.

  • Hallmark Steady, opportunistic campaigns rather than any coordinated push against Malaysia.

2.2 Who is doing it

  • What TheGentlemen led with eight victim claims, followed by Qilin with six and Lamashtu with five.

  • Why it matters All run the ransomware-as-a-service model, which lowers the barrier to entry and raises the overall volume.

  • Hallmark TheGentlemen is believed to have emerged from former Qilin affiliates: the same playbook under a new name.

2.3 Who is being hit

  • What Victims spanned 19 sectors. Manufacturing and engineering led with five claims each, then construction with four and government with three.

  • Why it matters The targeting follows the pressure points that make extortion pay: costly downtime, exposed supply chains, sensitive citizen data.

 

SECTION 3 · Credential & Identity Exposure

The raw material, what is actually leaking into the market.

3.1 Instagram PII exposure

  • What Over 17 million Instagram records aggregated through public interfaces, not a platform breach.

  • Why it matters It is a reconnaissance baseline: 6.2 million emails and 3.5 million phone numbers ready to prime convincing lures.

  • Hallmark The actor sold it as a commodity, the "who" and the "where" for others to work out the "how".

3.2 FortiBleed credential leak

  • What Working FortiGate firewall credentials exposed across 194 countries from an attacker's own server, surfaced in June 2026.

  • Why it matters These are the keys to the gate, not just a target list. Among exposed Malaysian domains, telecommunications led with 197, then manufacturing with 117.

  • Hallmark A Russian-speaking group running administrative access as a programmatic business, verifying credentials at scale before selling them on.

3.3 BreachForums database leak

  • What A dump of the BreachForums user database exposed 323,984 registered accounts.

  • Why it matters The cybercrime community's own hub became a liability, useful for de-anonymising the actors behind it.

  • Hallmark Most likely an internal misconfiguration, not an external break-in: these forums fail the same way any platform does.

 

SECTION 4 · House-tracked Operations

Our first-hand casework, the operations we watched directly.

4.1 GhostCargo

  • What A fake-bank fraud that took a Malaysian SME for more than RM50,000. The portal was not custom-built; it runs a 20-dollar commercial kit.

  • Why it matters The kit, not the scam, is the story. It has been detected 762 times across 41 or more domains worldwide.

  • Hallmark An operator who buys and outsources rather than builds, most likely a customer of the kit rather than its author.

  • Update Eleven weeks on, nothing had been taken down at either end, and we found the kit family now published on GitHub.

4.2 Phantom Casino

  • What An SEO-poisoning campaign, tracked as Tundra and tied to an operator we call Golden Wheel, that plants gambling pages on real government and university sites.

  • Why it matters The pages borrow a .gov.my or .edu.my host's trust and search ranking, and cleaning them does not close the access.

  • Hallmark Follow the money: the funnel resolves to two gambling wallets that are one operation.

  • Update The first report confirmed 83 poisoned hosts across 43 organisations. A re-check a month later found 78, but only 11 were the same hosts: 67 were new. The doorways are cleaned and replaced, so the count holds steady while the estate turns over.

4.3 One host pair, four actors

  • What An incident response on a single Malaysian federal ministry whose two servers held four separate, unrelated actors over roughly 20 months.

  • Why it matters One badly exposed host pair drew four intruders. The routes we could name all point at outsourced software.

  • Hallmark A trojanised antivirus update, a supply-chain compromise, stole every admin credential. Alongside it sat a China-linked APT, the Phantom Casino operator, and an unattributed insider.

4.4 Defacement trends: a June the government felt

  • What Our own count of Malaysian defacements through 2026, pulled from the public mirrors where defacers post their work.

  • Why it matters The public sector broke in June. Government defacements jumped to 92 in that single month, against 27 in all of 2024 and 27 in all of 2025. Education spiked to 58 and all three military branches were hit, while commercial sites did not move.

  • Hallmark A single notifier, Antonkill, drove 61 of the year's government defacements, the most prolific in the eleven-year record.

 

SECTION 5 · OSINT

The horizon: state-linked actors circling the region, and one that has already arrived.

5.1 Lazarus

  • What North Korea's Lazarus Group, which hit Malaysia's central bank in 2018 and is now stealing cryptocurrency at record scale.

  • Why it matters An estimated 577 million dollars stolen in four months, and Malaysia's regulated digital-asset sector is only now building out at the scale its playbook targets.

  • Hallmark Sanctions evasion run as state revenue: fake-recruiter lures, then fileless malware.

5.2 SideWinder

  • What A long-running espionage group, active since 2012, that has just expanded into Thailand and Indonesia.

  • Why it matters Malaysia fits the same maritime, energy and government profile the group has moved into next door. Treat it as early warning.

  • Hallmark Old, reliable Office flaws and infrastructure it can rotate by renaming a file. A five-to-ten-year game.

5.3 mushr00w

  • What The actor behind the June defacement of a federal ministry portal, entered through an unpatched Joomla plugin.

  • Why it matters The fix had shipped 20 days earlier. The lesson is the boring one: the plugins nobody thinks about are often the point of failure.

  • Hallmark Behind the anonymous banner is a one-person webshell business that sells access, not a cause.

 

RECOMMENDATIONS · What you can do

Nothing this half-year needed a novel defence. Four moves, across the lifecycle, each drawn from a finding above.

 

CLOSING · The through-line

Read across all five sections, the picture holds at every layer. Malaysian access is priced as a standing product and simply changes address when a forum is seized. The crews and the state-linked actors reach for the same commodity supply: rented kits, borrowed trust, leaked credentials, and old flaws that never needed a zero-day. The intrusions we worked at first hand make it concrete, one ministry carrying four unrelated actors, a defacement wave running through a plugin patched three weeks earlier. In each case the door was not novel; it was known, and it was left open. That is also the good news: the defence is unglamorous and shared, and closing the common door blunts several threats at once.

That is the half-year in brief. The full report carries the detail behind every feature, the figures, the tradecraft and the evidence. It is freely available, contact us and we will send it over.
Next
Next

Phantom Casino