Unknown · assessed origin China
WIP19
misp-galaxyrefreshed 2026-09-15
sigil
Analyst brief
WIP19 is a Chinese-speaking threat group involved in espionage targeting the Middle East and Asia. They utilize a stolen certificate to sign their malware, including SQLMaggie, ScreenCap, and a credential dumper. The group has been observed targeting telecommunications and IT service providers, using toolsets authored by WinEggDrop. WIP19's activities suggest they are after specific information and are part of the broader Chinese espionage landscape.
Early access
Track WIP19 on the wire.
Early access opens the actor API and MCP server first — and an alert every time this adversary lands on the wire. One email when it's ready.
bot-protected