WIP19

Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:10:51

Targeted industries: technology-and-telecommunications

Targeted regions: country_code:ae country_code:sa country_code:qa country_code:cn

Context

WIP19 is a Chinese-speaking threat group involved in espionage targeting the Middle East and Asia. They utilize a stolen certificate to sign their malware, including SQLMaggie, ScreenCap, and a credential dumper. The group has been observed targeting telecommunications and IT service providers, using toolsets authored by WinEggDrop. WIP19's activities suggest they are after specific information and are part of the broader Chinese espionage landscape.

Reports & references

  • sentinelone.com — Wip19 Espionage New Chinese Apt Targets It Service Providers And Telcos With Signed Malware (report)

External references