Uptime Hamster: 10d 8h 5mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza WIP19

WIP19

0 incidentes 0 paises 0 sectores apt CN Ultimo: -
Aliases: SQLMaggie, ScreenCap, WinEggDrop, otros
Ver en IntelTracker → APTTrail →
WIP19 is a Chinese-speaking cyber espionage threat group that emerged publicly in October 2022, primarily targeting telecommunications and IT service providers in the Middle East and Asia. The group is distinguished by its operational security practices, including the consistent use of a stolen digital certificate from DEEPSoft Co., Ltd. to sign its custom malware, a technique employed to evade detection. Their operations frequently involve 'hands-on keyboard' interactive sessions with compromised machines, prioritizing stealth over maintaining stable command and control channels. While exhibiting some tactical overlaps with Operation Shadow Force, WIP19 utilizes a distinct set of novel malware and techniques, suggesting it may be a more mature or separate entity operating with shared toolsets.

Aliases del actor

SQLMaggieScreenCapWinEggDropotros
Tecnicas MITRE
T1059.001, T1071.001, T1082, T1566.001
Tipo
apt
Pais origen
CN
Motivacion
-
Impacto
4
Actualizado
Sat, 09 De