WIP19
0 incidentes
0 paises
0 sectores
apt CN Ultimo: -
Aliases: SQLMaggie, ScreenCap, WinEggDrop, otros
WIP19 is a Chinese-speaking cyber espionage threat group that emerged publicly in October 2022, primarily targeting telecommunications and IT service providers in the Middle East and Asia. The group is distinguished by its operational security practices, including the consistent use of a stolen digital certificate from DEEPSoft Co., Ltd. to sign its custom malware, a technique employed to evade detection. Their operations frequently involve 'hands-on keyboard' interactive sessions with compromised machines, prioritizing stealth over maintaining stable command and control channels. While exhibiting some tactical overlaps with Operation Shadow Force, WIP19 utilizes a distinct set of novel malware and techniques, suggesting it may be a more mature or separate entity operating with shared toolsets.