Uptime Hamster: 10d 21h 5mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza WIP26

WIP26

0 incidentes 0 paises 0 sectores apt UNKNOWN Ultimo: -
Aliases: https, www
Ver en IntelTracker → APTTrail →
WIP26 is a cyber espionage threat actor first publicly documented in 2023, though activity was noted as early as 2022. This group focuses on gathering sensitive information and engaging in long-term intrusion campaigns. While its origin remains unknown, WIP26's primary motivation is intelligence collection. What distinguishes WIP26 is its heavy reliance on public cloud infrastructure, such as Microsoft 365 Mail, Microsoft Azure, Google Firebase, and Dropbox, for malware delivery, command and control, and data exfiltration. This tactic is specifically employed to evade detection by making malicious network traffic appear legitimate, allowing the group to blend into normal enterprise cloud usage.

Aliases del actor

httpswww
Motivacion