WIP26
0 incidentes
0 paises
0 sectores
apt UNKNOWN Ultimo: -
Aliases: https, www
WIP26 is a cyber espionage threat actor first publicly documented in 2023, though activity was noted as early as 2022. This group focuses on gathering sensitive information and engaging in long-term intrusion campaigns. While its origin remains unknown, WIP26's primary motivation is intelligence collection. What distinguishes WIP26 is its heavy reliance on public cloud infrastructure, such as Microsoft 365 Mail, Microsoft Azure, Google Firebase, and Dropbox, for malware delivery, command and control, and data exfiltration. This tactic is specifically employed to evade detection by making malicious network traffic appear legitimate, allowing the group to blend into normal enterprise cloud usage.