WIP19 is a Chinese-speaking espionage threat cluster associated with targeted intrusions against telecommunications and IT service providers in the Middle East and Asia. The activity is consistent with intelligence collection and shows tradecraft associated with mature Chinese intrusion operations, including selective targeting, customized malware, use of a stolen code-signing certificate, and stealth-focused hands-on-keyboard operations. The cluster has been linked to tooling and tradecraft overlaps with Operation Shadow Force and to malware attributed to the Chinese-speaking malware author WinEggDrop. Malware associated with WIP19 includes SQLMaggie, an MSSQL extended stored procedure backdoor used to register a malicious DLL on Microsoft SQL Server systems, enabling full control of compromised servers, internal reconnaissance, account discovery, SQL scanning, port checks, remote shell access, file operations, and in some variants tunneling and exploit-assisted remote actions. WIP19 also used credential-dumping tooling that loaded a Security Support Provider into LSASS and leveraged NanoDump-related functionality to obtain credential material. The actor favored interactive intrusion activity over persistent, stable command-and-control infrastructure, apparently prioritizing stealth. Additional observed tradecraft includes DLL search order hijacking to load ScreenCap, a tailored surveillance component used for keylogging and screen recording on selected victim machines. ScreenCap was configured for specific deployments and focused on collecting user activity from targeted systems. Overall, WIP19 represents a focused cyber-espionage intrusion set targeting critical communications-sector organizations with signed malware, credential access tooling, reconnaissance capabilities, and customized post-compromise collection mechanisms.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
52 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.