Skip to main content

Threats Affecting Philippines

View all threats affecting or targeting Philippines. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Country:PhilippinesPhilippines

Threats Affecting Philippines

Click on any threat for detailed analysis and mitigation recommendations

Gigabud is an Android remote access banking trojan active since 2022, attributed to GoldFactory group, targeting victims across Southeast Asia, South Asia, Middle East, Africa and Latin America. The malware now utilizes Vwork, a weaponized fork of the open-source app cloning application Shelter, to evade detection by creating isolated work profiles. After initial Gigabud infection, Vwork is installed to clone banking applications into the work profile, hiding malicious activity from signature-based detection in application security SDKs. Between February and July 2026, approximately 1,469 compromised devices and 1,281 potentially compromised logins were observed in Indonesia alone, with estimated losses of roughly $960,939. The infection chain involves social engineering through phishing sites delivering fake apps disguised as legitimate services, followed by credential theft through overlays and remote-controlled fraudulent transactions executed within cloned banking apps.

Join the discussion
0

Three implants named SPEAKINGSTONE, DARKLANTERN, and ENDLESSDOORS have been found embedded in ZBT router firmware distributed globally, including in the US, Canada, Australia, Philippines, Germany, and Russia. DARKLANTERN is an unauthenticated UDP backdoor on port 9992 providing root shell access with trivial MAC address bypass. SPEAKINGSTONE is a phone-home implant capable of DNS hijacking, ISP credential theft, and remote command execution. These implants use plaintext protocols without authentication, making them vulnerable to hijacking by network adversaries. The compromised hardware is found in white-labeled consumer products sold through mainstream retailers, representing embedded surveillance capabilities in commercial devices. A sinkholed backup domain revealed 392 devices, mostly in China, and internet scans found 203 DARKLANTERN instances in 22 countries.

Join the discussion

A suspected Chinese-speaking threat actor conducted targeted intrusions against Philippine nuclear research and defense organizations. On August 13, 2026, an open directory on a VPS exposed custom Python scripts exploiting CVE-2023-49105 in ownCloud and CVE-2024-28000 in WordPress LiteSpeed Cache. The operator exfiltrated approximately 9 GB from a nuclear agency, including reactor core databases, radiation safety documentation, employee PII, BitLocker keys, and strategic planning materials. A second victim, a marine engineering firm serving the Philippine Navy, had its complete WordPress installation compromised. Simplified Chinese language usage throughout scripts, logs, and folder structures indicates operator origin. The methodical targeting of nuclear and naval defense sectors aligns with South China Sea tensions and broader Chinese espionage activities against Philippine government infrastructure.

Join the discussion
0

Beginning in August 2025, a sophisticated intrusion was discovered where attackers used log poisoning techniques to deploy a web shell on vulnerable phpMyAdmin panels. The threat actors exploited misconfigured web applications to plant China Chopper web shells, controlled via AntSword, before deploying Nezha, an open-source monitoring tool, to facilitate remote command execution. This led to the deployment of Ghost RAT on compromised systems. Analysis revealed over 100 compromised machines, predominantly located in Taiwan, Japan, South Korea, and Hong Kong. The attackers demonstrated technical proficiency through multi-stage operations, utilizing AWS and VPS infrastructure, with indicators pointing to China-nexus threat actors. The campaign highlights increasing abuse of legitimate publicly available tools to achieve malicious objectives while maintaining plausible deniability.

Join the discussion

A sophisticated fraud campaign exploiting Indonesia's tax season targeted 67 million residents through fake Coretax applications distributed via phishing websites and WhatsApp social engineering. The GoldFactory threat cluster orchestrated operations using Gigabud.RAT and MMRat malware families with shared infrastructure abusing over 16 trusted brands across government and financial sectors. The attack chain combines vishing, screen recording, and remote access capabilities to achieve device compromise and unauthorized financial transfers. Estimated financial impact reaches USD 1.5-2 million nationwide, with global implications extending to USD 6 million annually across multiple countries. The industrialized malware-as-a-service infrastructure enables horizontal scaling across Thailand, Vietnam, Philippines, and South Africa, demonstrating a shift toward unified cross-border operations that systematically undermine trust in digital government services.

Join the discussion

A sophisticated spear phishing campaign dubbed Operation GriefLure targeted senior executives of Viettel Group, Vietnam's largest military-owned telecommunications provider, and St. Luke's Medical Center in the Philippines. The operation weaponized authentic legal documents from a genuine data breach dispute involving a Vietnamese citizen and Viettel, alongside fabricated whistleblower complaints targeting Philippine healthcare administrators. Attackers delivered malicious Windows LNK files within nested RAR archives, abusing native ftp.exe as a Living-off-the-Land dropper. Upon execution, the payload assembled polymorphic implants directly on disk from chunked .doc files, establishing persistence while displaying legitimate decoy PDFs. The malware enabled remote access through process injection, credential harvesting from browsers and remote access tools, screenshot capture, and file exfiltration via HTTPS C2 communication to infrastructure hosted on bulletproof Hong Kong servers.

Join the discussion
CVE-2026-30573: n/aCVE-2026-30573
0

A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0. The vulnerability is located in the add-sales.php file. The application fails to validate the "txtprice" and "txttotalcost" parameters, allowing attackers to submit negative values for sales transactions. This leads to incorrect financial calculations, corruption of sales reports, and potential financial loss.

Join the discussion
CVE-2026-30523: n/aCVE-2026-30523
0

A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to the lack of proper input validation. The application allows administrators to define "Loan Plans" which determine the duration of a loan (in months). However, the backend fails to validate that the duration must be a positive integer. An attacker can submit a negative value for the months parameter. The system accepts this invalid data and creates a loan plan with a negative duration.

Join the discussion
CVE-2026-30522: n/aCVE-2026-30522
0

A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to improper server-side validation. The application allows administrators to create "Loan Plans" with specific penalty rates for overdue payments. While the frontend interface prevents users from entering negative numbers in the "Monthly Overdue Penalty" field, this constraint is not enforced on the backend. An authenticated attacker can bypass the client-side restriction by manipulating the HTTP POST request to submit a negative value for the penalty_rate.

Join the discussion

Key Points Introduction At the beginning of 2026, Check Point Research observed a series of targeted attacks against government entities in Southeast Asia carried out via a legitimate TrueConf software installed in the targets’ environment. The investigation led to the discovery of a zero-day vulnerability in the TrueConf client, tracked as CVE-2026-3502 with a CVSS score of 7.8. […] The post Operation TrueChaos: 0-Day Exploitation Against Southeast Asian Government Targets appeared first on Check Point Research .

Join the discussion

Showing 1 to 10 of 429 results

Filters:Country: Philippines
Page 1 of 43
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses