Cyber Alerts

MA-1479.072026: MyCERT Advisory - Recent Ransomware Activities Observed: Best Practices for Prevention and Mitigation

Verified Officially confirmed

Recently, the Cyber999 Incident Response Centre has been observing a notable increase in ransomware-related incidents targeting organisations across Malaysia. These attacks have affected a wide range of sectors, including businesses, hence highlighting the growing threat posed by ransomware threat actors. Ransomware activity continued at a significant pace into 2026. Building on the 51 incidents recorded throughout 2025, the first two quarters of 2026 alone accounted for 29 incidents (17 in Q1, 12 in Q2), signalling that ransomware remains a sustained operational risk rather than a diminishing one. Active Threat Groups identified across Q1 and Q2 2026 include LockBit, The DragonHorse, Qilin, Akira, Lynx Group, Black Shatrac, Thegentlemen, CrySiS, Obscura, Skynet, Ransom24 Group, DeadLock, and INC Ransom, alongside several unidentified variants. Threat actors continue to leverage compromised credentials (often harvested via Infostealers), unpatched vulnerabilities, and social engineering to gain initial entry. Organisations must reinforce infrastructure defences and ensure rapid incident reporting to mitigate nationwide impact. 2.0 Impacts Below is the list of ransomware impacts that could be devastating to organisations: Service Interruption: Customer-facing services may go offline, damaging trust and reputation.System and network infrastructure compromised.Files on the infected computer are encrypted, and the owner cannot access the files until a ransom (usually in a cryptocurrency such as Bitcoin) is paid.System Downtime: Ransomware often encrypts critical data and systems, halting business operations.Business operations are disrupted due to permanent or temporary loss of sensitive or proprietary data belonging to an organisation.Aside from financial gain, it exploits sensitive data and uses it as a levy. If the ransom is not paid within time, organisations’ confidential data are exposed, and trade secrets are compromised.Financial loss: Some organisations may feel pressured to pay the ransom, which can be substantial. Restoring systems, conducting forensics, and improving security can be very expensive. A data breach can result in reputational harm to the government and diminish trust in government digital transformation programmes.

First observed
29 Jul 2026
Last checked
01 Aug 2026
Evidence records
1
Publication state
Published

What happened?

Current assessment

Recently, the Cyber999 Incident Response Centre has been observing a notable increase in ransomware-related incidents targeting organisations across Malaysia. These attacks have affected a wide range of sectors, including businesses, hence highlighting the growing threat posed by ransomware threat actors. Ransomware activity continued at a significant pace into 2026. Building on the 51 incidents recorded throughout 2025, the first two quarters of 2026 alone accounted for 29 incidents (17 in Q1, 12 in Q2), signalling that ransomware remains a sustained operational risk rather than a diminishing one. Active Threat Groups identified across Q1 and Q2 2026 include LockBit, The DragonHorse, Qilin, Akira, Lynx Group, Black Shatrac, Thegentlemen, CrySiS, Obscura, Skynet, Ransom24 Group, DeadLock, and INC Ransom, alongside several unidentified variants. Threat actors continue to leverage compromised credentials (often harvested via Infostealers), unpatched vulnerabilities, and social engineering to gain initial entry. Organisations must reinforce infrastructure defences and ensure rapid incident reporting to mitigate nationwide impact. 2.0 Impacts Below is the list of ransomware impacts that could be devastating to organisations: Service Interruption: Customer-facing services may go offline, damaging trust and reputation.System and network infrastructure compromised.Files on the infected computer are encrypted, and the owner cannot access the files until a ransom (usually in a cryptocurrency such as Bitcoin) is paid.System Downtime: Ransomware often encrypts critical data and systems, halting business operations.Business operations are disrupted due to permanent or temporary loss of sensitive or proprietary data belonging to an organisation.Aside from financial gain, it exploits sensitive data and uses it as a levy. If the ransom is not paid within time, organisations’ confidential data are exposed, and trade secrets are compromised.Financial loss: Some organisations may feel pressured to pay the ransom, which can be substantial. Restoring systems, conducting forensics, and improving security can be very expensive. A data breach can result in reputational harm to the government and diminish trust in government digital transformation programmes.

Why it matters

The available source does not yet provide enough structured information for a separate impact assessment.

Who is affected?

Affected products and groups

No affected entity has been safely confirmed in the structured record yet.

What should you do now?

Actions from official guidance

For technical teams

  1. Organisations should actively monitor for compromised credentials, particularly those that may result from Infostealer infections, which can serve as entry points for more serious attacks such as ransomware.Implement password revocation policies to enforce timely password changes and minimise exposure to compromised accountsPromote the use of secure password managers and encourage employees to create strong, unique passphrases, avoid reusing passwords, and update them regularly.Enable multi-factor authentication (MFA) to provide an additional layer of security for accessing critical systems and sensitive dataEnforce role-based access control and establish a formal authorisation policy that includes automatically locking idle accounts and alerting IT personnel after multiple failed login attempts.Regularly audit and review Active Directory (AD) to detect and remove backdoors, particularly compromised service accounts that may hold elevated privileges.Additional recommendations for AD Security:Protect Against Compromised Passwords: Implement strong password policies, password hashing, and rotation to prevent password theft and compromise. Monitor and Investigate: Implement monitoring and logging to detect and investigate suspicious activity in Active Directory. Review and Update Security Settings: Regularly review and update security settings, including Group Policy Objects (GPOs) and other security configurations. Clean Up Active Directory: Regularly remove unused accounts and computer objects to reduce the attack surface. Encrypt Data: Encryption is used for sensitive data stored in Active Directory. Apply security patches and update antivirus software consistently to mitigate known vulnerabilities and reduce the attack surface.Perform daily data backups in multiple copies, verify their integrity through regular testing, and store backup copies securely at an offsite location.Conduct mandatory cybersecurity awareness training for all employees at least once a year to reinforce secure behaviours and response readiness.Educate staff to avoid downloading files or attachments from unknown or untrusted sources.Review and update the organisation’s Disaster Recovery Plan (DRP) to ensure preparedness in the event of a security incident or system failure.Review and revise the Business Continuity Plan (BCP) as needed to maintain operational stability during and after a disruption.Disable RDP if not needed, as RDP is one of the most commonly exploited vectors. Use tools like Group Policy or the Windows Firewall to block RDP (port 3389). Official source

For everyone

  1. Generally, CyberSecurity Malaysia advises organisations to be updated with the latest security announcements by the vendor and follow best practices for prompt security updates and patches. Official source

Which sources support it?

Evidence and official sources

  1. MyCERTOfficial source
    MA-1479.072026: MyCERT Advisory - Recent Ransomware Activities Observed: Best Practices for Prevention and Mitigation

    Recently, the Cyber999 Incident Response Centre has been observing a notable increase in ransomware-related incidents targeting organisations across Malaysia. These attacks have affected a wide range of sectors, including businesses, hence highlighting the growing threat posed by ransomware threat actors. Ransomware activity continued at a significant pace into 2026. Building on the 51 incidents recorded throughout 2025, the first two quarters of 2026 alone accounted for 29 incidents (17 in Q1, 12 in Q2), signalling that ransomware remains a sustained operational risk rather than a diminishing one. Active Threat Groups identified across Q1 and Q2 2026 include LockBit, The DragonHorse, Qilin, Akira, Lynx Group, Black Shatrac, Thegentlemen, CrySiS, Obscura, Skynet, Ransom24 Group, DeadLock, and INC Ransom, alongside several unidentified variants. Threat actors continue to leverage compromised credentials (often harvested via Infostealers), unpatched vulnerabilities, and social engineering to gain initial entry. Organisations must reinforce infrastructure defences and ensure rapid incident reporting to mitigate nationwide impact. 2.0 Impacts Below is the list of ransomware impacts that could be devastating to organisations: Service Interruption: Customer-facing services may go offline, damaging trust and reputation.System and network infrastructure compromised.Files on the infected computer are encrypted, and the owner cannot access the files until a ransom (usually in a cryptocurrency such as Bitcoin) is paid.System Downtime: Ransomware often encrypts critical data and systems, halting business operations.Business operations are disrupted due to permanent or temporary loss of sensitive or proprietary data belonging to an organisation.Aside from financial gain, it exploits sensitive data and uses it as a levy. If the ransom is not paid within time, organisations’ confidential data are exposed, and trade secrets are compromised.Financial loss: Some organisations may feel pressured to pay the ransom, which can be substantial. Restoring systems, conducting forensics, and improving security can be very expensive. A data breach can result in reputational harm to the government and diminish trust in government digital transformation programmes.

    Published Just published · Retrieved 01 Aug 2026