NC4-ALR-2026-000008 : Heightened Hacktivist and Opportunistic Activity Targeting Malaysian Financial Institutions
Introduction

NC4 is observing elevated risk of hacktivist and opportunistic cyber activity targeting financial institutions in Malaysia. NC4 urges financial institutions to take these immediate measures:

  • Implement robust protection for privileged identities.
  • Review and ensure Distributed Denial-of-Service (DDoS) defences are properly deployed and have been tested.

 

Impact

  • Privileged ID compromise: If an administrator, service, database or vendor account is misused, attackers can gain unauthorised access to core systems, steal or destroy data, carry out fraudulent transactions, and deploy ransomware.
  • DDoS: Volumetric, protocol and application-layer attacks can take down internet banking, mobile apps, payment gateways, APIs, and public websites. Customers can also be disrupted, while the institution may face regulatory and reputational damage.
  • Combined attacks: Attackers may use a DDoS as cover for an intrusion. This can delay detection and response and provide the attacker more time inside the network.

 

Brief Description

Through closed-source monitoring, NC4 has identified accounts being promoted to recruit participants or publicise attacks. Some of these accounts may have originated from leaked credentials linked to financial institutions.

NC4 has also observed incidents involving compromised privileged IDs and DDoS attacks that disrupted the online services of financial institutions.

At this stage:

  • No specific actor has been attributed to the activities.
  • Such campaigns often pair credential theft with leak claims to get as much publicity and disruption as possible.
  • A DDoS can serve as a diversion while intrusion activity, such as abuse of compromised privileged accounts, happens elsewhere in the victim's network.
  • Financial institutions are attractive targets because they are highly visible, and any outage or alleged breach damages their reputation.

 

Recommendation

To mitigate these threats, financial institutions are advised to implement the following without delay:

 

  1. Privileged ID Protection
    1. Inventory privileged accounts: Inventory must cover human, service, application, database, network device, cloud, third-party, and emergency ("break-glass") accounts. Dormant accounts and privileges that are no longer needed should be removed.
    2. Enforce phishing-resistant MFA: Enforce MFA on all privileged access, including remote and vendor access. Legacy authentication protocols should be disabled.
    3. Vault and rotate credentials: Store privileged credentials in a Privileged Access Management (PAM) solution with session recording. Routinely perform passwords rotation. Eliminate shared, default and hard-coded credentials. Where a compromise is suspected, rotate passwords and keys immediately.
    4. Apply least privilege and just-in-time access: Grant elevated rights only for the task and the time it takes. Documented the approval.
    5. Isolate administration: Use dedicated admin workstations on segmented admin networks with no internet or email access. Make sure privileged users carry out administration only with their privileged accounts on these systems.
    6. Monitor privileged activity: Send logs to the SIEM and set alerts for unusual logins (e.g. time, location, or source), privilege escalation, new account creation, disabled security tools, and bulk data access or export.
    7. Control third-party access: Require MFA, time-bound approval and session monitoring. Revoke access as soon as the task is done.
    8. Protect identity infrastructure: Harden and closely monitor Active Directory, identity providers and cloud identity tenants. Patch internet-facing systems promptly.
    9. Maintain offline, tested backups: Make backups of critical systems and configurations, and keep them out of reach of privileged account compromise.
    10. Check for exposed credentials: Review dark web and paste-site monitoring, threat intelligence feeds, and breach notifications for leaked staff or admin credentials. Reset any affected accounts.

  2. DDoS Mitigation
    1. Engage upstream protection: Confirm that engaged ISPs and/or cloud scrubbing provider have active arrangements covering volumetric, protocol, and application-layer attacks. Beforehand, make agreement on capacity, activation time and escalation contacts.
    2. Protect all internet-facing assets: Other than the main website, include also internet banking, mobile app back ends, APIs, payment and card gateways, DNS, mail, and VPN endpoints.
    3. Deploy a Web Application Firewall (WAF) and bot management: Apply rate limiting, geo and reputation-based filtering, and challenge mechanisms for abusive traffic.
    4. Secure DNS: Use resilient, redundant DNS with DDoS protection. Protect registrar and DNS administration accounts with MFA.
    5. Hide origin infrastructure: Set origin servers to accept traffic only from protection provider, and avoid exposing origin IP addresses.
    6. Build in resilience: Use redundant internet links, load balancing, and enough spare capacity.
    7. Maintain a DDoS response playbook: Define roles, decision authority, customer, and regulator communication templates, and provider contacts. Periodically run a tabletop exercise or controlled simulation.
    8. Monitor in real time: Baseline enterprise normal traffic, set alerting thresholds, and staff 24x7 monitoring team throughout the heightened-risk period.
    9. Prepare for diversion tactics: Make sure SOC team keeps investigating non-DDoS alerts during an attack, particularly those involving privileged accounts and data access.

 

Reporting

If you are a Malaysian NCII entity affected by this activity, you are required under Act 854 to report any indicators or incidents to NC4.

Alert