Skip to content
  • Case Studies
  • Cybersecurity Readiness Assessment
simply data logo
  • About
    • About Us
    • Innovation
      • SD Platform Overview
    • Certifications & Awards
  • Our Services
    • CyberSecurity Services
      • DFIR (Digital Forensics and Incident Response)
      • Compromise Assessment
      • Security Operations Center (SOC) Managed Service
        • SD-Cyber Deception
        • Threat Intelligence
        • Managed Detection and Response (MDR)
        • Cloud Security Posture Management (CSPM)
        • Web Defacement Monitoring
        • In-house Automation Script Development
        • Advanced Malware Analysis & Threat Intelligence
        • Office 365 Monitoring
        • SaaS Monitoring
      • Extended Threat Intelligence
        • Dark Web Monitoring
        • Attack Surface Management
        • Cyber Risk Management
        • Supply Chain Intelligence
      • Security Posture Assessment (SPA)
      • VAPT & Penetration Testing
      • Network & Security Configuration Audit & Hardening
      • Phishing Email Simulation
    • Managed Network & Security Services
    • Application Performance Monitoring (APM)
      • APM as a Service (APMaaS)
      • Cloud Monitoring
      • Database Performance Monitoring
      • Web Application Monitoring
      • Synthetic Testing Monitoring
      • Real User Monitoring (RUM)
      • Application Stress Test / Load Test Services
    • Consultancy Services
      • NCSB Risk Assessment
      • Security BluePrint™ Consultancy Services
    • Agentic AI & Automation
      • SD Unified Platform (SDP)
      • Agentic AI SOC
      • AI Automation
      • SD Monitoring — 100% Data Ingestion Visibility | SD Unified Platform
      • SDP-Portal — Customer-Facing SOC Visibility | SD Unified Platform
      • AI Threat Hunting — Chat-Driven Investigation by SD Unified Platform
    CyberSecurity Services
    • VAPT & Penetration Testing
    • Cyber - 911 - DFIR Services
    • Compromise Assessment
    • Security Operations Center (SOC)
    • Extended Threat Intelligence
    • Security Posture Assessment (SPA) Services
    • Network & Security Configuration Audit & Hardening
    • Phishing Email Simulation
    • AI Automation
    Managed Network & Security Services
    • Managed Network & Security Services
    Consultancy Services
    • NCSB Risk Assessment
    • Security BluePrint™ Consultancy Services
    Agentic AI & Automation
    • SD Unified Platform
    • Agentic AI SOC
    • AI Automation
    • SD Monitoring
    • SDP-Portal
    • AI Threat Hunting
    Application Performance Monitoring
    • APM as a Service (APMaaS)
    • Cloud Monitoring
    • Database Performance Monitoring
    • Web Application Monitoring
    • Synthetic Testing Monitoring
    • Real User Monitoring (RUM)
    • Stress Test / Load Test – Performance Assessment

    Not Sure What Security Threats Your Organization is Facing?

    We can help. Contact us now for a free consultation and protect your business from potential risks.

    Contact Us
  • Technology Vendor Partners
  • Blog & News
  • Contact
    • Contact Us
    • Become a Simply Data Partner

Under Attack?

Submit your message through our contact form or call us at +603 5886 2714.

    Industry Insights & Trends

    Malaysia Threat Report: 2024 Cybersecurity Insights

    March 26, 2025
    Malaysia Threat Report 2024 Cybersecurity Insights

    Home – Malaysia Threat Report: 2024 Cybersecurity Insights

    The Malaysia cybersecurity threat report 2024 highlights a year of escalating attacks against businesses across all sectors. Understanding the threat landscape is essential for Malaysian organisations seeking to strengthen their defences and make informed security investment decisions.

    In today’s rapidly evolving digital landscape, cyber threats continue to pose significant risks to businesses of all sizes. With the increasing complexity of cyberattacks, traditional security measures are no longer sufficient. Organizations must adopt proactive threat intelligence solutions that not only detect threats but also take immediate action. Simply Data is at the forefront of cybersecurity innovation, offering an advanced Threat Intelligence – Integrated SOAR Automation Blocking solution that ensures robust protection for enterprises.

    Key Insights from the 2024 Malaysia Threat Report

    Our latest Malaysia Threat Report provides an in-depth analysis of cybersecurity incidents, revealing alarming trends in the cyber threat landscape. In 2024 alone, Simply Data collected and analyzed 71,830,607,531 logs, identifying key attack patterns and vulnerabilities exploited by malicious actors.

    Executive Summary

    The report highlights a significant rise in ransomware attacks, phishing campaigns, and targeted intrusions affecting organizations across multiple sectors. Notably, Malaysia has seen a surge in APT (Advanced Persistent Threat) groupsleveraging zero-day vulnerabilities to infiltrate critical infrastructure.

    The report identifies threat actors such as FLAX TYPHOON, SIDEWINDER, RIPPERSEC, GAMAREDON, HUNTERS, RANSOMHUB, RHYSIDA, and BLACKCAT, who have been actively targeting financial institutions, logistics, and education sectors in Malaysia. These groups employ sophisticated techniques like credential theft, supply chain attacks, and advanced evasion tactics. Additionally, the LockBit ransomware group has been responsible for several high-profile ransomware incidents, crippling organizations through double extortion tactics—encrypting data and threatening to release stolen information publicly.

    Another critical finding is the rise in phishing-as-a-service (PhaaS) platforms, enabling cybercriminals to deploy large-scale credential-harvesting campaigns with minimal effort. The emergence of deepfake social engineering tactics further complicates security defenses, requiring businesses to enhance their detection mechanisms.

    Top 5 Cybersecurity Incidents

    Our research recorded a substantial rise in cybersecurity incidents across Malaysia in 2024. The report details multiple high-impact cases, including:

    1. Unauthorized Access via Brute Force Attacks – Attackers exploited weak passwords and credential stuffing techniques, leading to significant breaches.
    2. Ransomware Infections via Phishing Emails – Organizations fell victim to sophisticated phishing campaigns delivering ransomware payloads.
    3. Supply Chain Attacks – Malware was injected into widely used third-party software updates, compromising hundreds of businesses.
    4. Data Destruction & Wiper Malware Attacks – Malicious actors deployed destructive malware to erase critical business data.
    5. Cloud Infrastructure Exploitation – Attackers took advantage of misconfigured public cloud environments, leading to data leaks and account takeovers.

    Top 3 MITRE Tactics & Techniques

    The report highlights the most commonly used MITRE ATT&CK techniques observed in attacks against Malaysian businesses:

    • T1110 (Brute Force Attacks) – Cybercriminals attempted to gain access by guessing user credentials.
    • T1665 (Hide Infrastructure) – Adversaries concealed malicious command-and-control (C2) communications to avoid detection.
    • T1485 (Data Destruction) – Attackers deployed malware to delete critical data, disrupting business operations.

    Threat Intelligence by Countries

    The report reveals the top 5 countries from which cyberattacks targeting Malaysia originated:

    1. United States – Hosting a significant number of compromised servers used in attacks.
    2. China – Linked to state-sponsored APT activities.
    3. Great Britain – Origin of multiple cybercrime operations.
    4. South Korea – Emerging hub for cyber exploitation activities.
    5. Russia – A major source of ransomware and cyber extortion campaigns.

    Key Risks Identified in 2024

    The primary risks affecting organizations in Malaysia include:

    Download Full Report





      Stay Ahead with Simply Data

      Cyber threats are becoming more sophisticated, and organizations must be proactive in their defense strategies. With Simply Data Threat Intelligence – Integrated SOAR Automation Blocking, businesses can safeguard their critical assets, maintain compliance, and ensure uninterrupted operations.

      Want to learn more about how Simply Data can protect your business? Contact us today to schedule a consultation or subscribe to our quarterly Cybersecurity Intelligence Newsletter for the latest threat updates.

      Resources and Further Reading on Malaysia Cybersecurity Threat Report 2024

      For organisations looking to strengthen their cybersecurity posture, the following authoritative resources provide valuable guidance: CISA Cyber Threats and Advisories | MITRE ATT&CK Framework.

      Simply Data offers a full suite of cybersecurity and technology solutions tailored for Malaysian businesses. Explore our services: SOC-as-a-Service | Cybersecurity Case Studies. Ready to get started? Contact our cybersecurity experts for a free consultation today.

      Frequently Asked Questions

      1. What were the most common cybersecurity incidents in Malaysia in 2024?

      The report identifies five high-impact incident types that surged in 2024:
      – Brute Force Attacks: Exploiting weak passwords to gain unauthorized access.
      – Ransomware via Phishing: Using sophisticated emails to deliver malicious payloads.
      – Supply Chain Attacks: Injecting malware into third-party software updates.
      – Data Destruction: Deploying “wiper” malware to intentionally erase business data.
      – Cloud Exploitation: Targeting misconfigured public cloud environments.

      2. Which industries in Malaysia are being targeted by Advanced Persistent Threat (APT) groups?

      The report highlights that APT groups (such as FLAX TYPHOON and SIDEWINDER) are actively targeting financial institutions, logistics, and education sectors. These groups often leverage zero-day vulnerabilities to infiltrate critical infrastructure.

      3. What is “Double Extortion” in the context of ransomware?

      The report mentions that groups like LockBit use double extortion tactics. This means they do not just encrypt an organization’s data to demand a ransom, they also threaten to release stolen sensitive information publicly if the payment is not made, increasing the pressure on victims.

      4. From which countries do most cyberattacks against Malaysia originate?

      According to Simply Data threat intelligence, the top 5 countries serving as sources for cyberattacks targeting Malaysia are the United States, China, Great Britain, South Korea, and Russia. These locations host compromised servers or serve as hubs for state-sponsored and criminal operations.

      5. How are “Phishing-as-a-Service” (PhaaS) and deepfakes changing the threat landscape?

      Cybercrime has become more accessible through PhaaS platforms, which allow low-skilled attackers to launch large-scale credential-harvesting campaigns. Additionally, the emergence of deepfake social engineering has made it harder for employees to distinguish between legitimate communications and fraudulent ones, requiring more advanced detection mechanisms.

      • Cyber Threats
      • cybersecurity-malaysia
      • Malaysia
      • Ransomware
      • Threat Report
      • threat-intelligence

      Post navigation

      Previous
      Next

      Search

      Categories

      • Announcements (9)
      • Cybersecurity Tips (41)
      • Industry Insights & Trends (13)
      • Regulatory & Compliance (4)
      • Service Spotlight (8)

      Recent posts

      • Proactive SOC vs Agentic SOC
        Proactive SOC vs Agentic SOC: Why Malaysian Businesses Should Ask a Different Question
      • FortiClient EMS zero-day CVE-2026-35616 patch advisory Malaysia
        FortiClient EMS Zero-Day CVE-2026-35616: Patch Now
      • cloud security malaysia 1 1024x683
        Cloud Security Malaysia: Best Practices for Protecting Your Cloud Environment in 2026

      Tags

      2026 Trends AI Threats Anthropic apm Bank Negara RMiT Certification Company News Compliance Cost-Benefit Analysis CVE cyber-security-act cybersecurity-malaysia Cybersecurity Malaysia Cyber SOC Cyber Threats Dark Web DFIR Digital Forensics Dwell Time Incident Response iso27001 Malaysia Malaysia Cybersecurity Malaysia Cybersecurity 2025 Managed Services MDR nacsa Network Security Patch Management PDPA penetration-testing Proactive Cybersecurity Ransomware ROI SIEM SME Budget SME Security soc SOC Malaysia threat-intelligence Threat Hunting Threat Report vapt Vulnerability Web Application Security

      Related posts

      Simply Data Earns Anthropic Claude CCA F Certification
      Announcements

      Simply Data Earns Anthropic Claude Certified Architect – Foundations (CCA-F) Certification

      June 7, 2026

      Simply Data Co-Founder Eric Leong passes the Anthropic CCA-F exam with 747/1000 — among Malaysia’s first Claude Certified Architects. What it means for AI-powered cybersecurity clients.

      what does a dfir report contain 1 1024x683
      Cybersecurity Tips

      What Does a DFIR Report Contain? Inside a Simply Data Digital Forensics Investigation

      May 28, 2026

      Home – What Does a DFIR Report Contain? Inside a Simply Data Digital Forensics Investigation What Is a DFIR Report? A DFIR report is the final deliverable from a Digital Forensics and Incident Response engagement. Unlike a standard IT incident report, a DFIR report is structured as forensic evidence — meaning every finding is tied […]

      what does a compromise assessment report contain 1 1024x683
      Service Spotlight

      What Does a Compromise Assessment Report Contain? A Complete Guide for Malaysian Organisations

      May 28, 2026

      Home – What Does a Compromise Assessment Report Contain? A Complete Guide for Malaysian Organisations What Is a Compromise Assessment Report? A compromise assessment report is the formal deliverable produced at the end of a Compromise Assessment engagement. It documents every suspicious activity detected across your environment during a defined observation window, the analyst’s investigation […]

      simply data logo

      Started in 2022, Simply Data is a CREST certified and NACSA Licensed (No. 20007-01 & 20007-02) Cyber Security company in Malaysia that provides cyber security services including Network & Security IT Managed Service, Security Operation Centre (SOC), Cyber Threat Intelligence, Vulnerability Assessment & Penetration Testing (VAPT) service, Application Performance Monitoring (APM) services, and more.

      • B-03A-03, 3RD Floor, Block B Setiawalk, Persiaran Wawasan, Pusat Bandar Puchong, 47100 Puchong, Selangor
      • +603 5886 2714
      • contactus@simplydata.com.my
      Quick Links
      • Home
      • About Us
      • Innovation
      • Technology Vendor Partners
      • Blog / News
      • Career Opportunities
        Hiring
      • Become a Simply Data Partner
      • Cybersecurity Readiness Assessment
      • Malaysia CyberSecurity Act 854
      CyberSecurity Services
      • Cyber - 911 - DFIR Services
      • Compromise Assessment
      • Security Operations Center (SOC)
      • Extended Threat Intelligence
      • Security Posture Assessment (SPA) Services
      • Network & Security Configuration Audit & Hardening
      • Phishing Email Simulation
      Managed Network & Security Services
      • Managed Network & Security Services
      Observability Application Performance Monitoring
      • Observability APM as a Service
      • Cloud Monitoring
      • Database Performance Monitoring
      • Web Application Monitoring
      • Synthetic Testing Monitoring
      • Real User Monitoring
      • Stress Test / Load Test – Performance Assessment
      Consultancy Services
      • NCSB Risk Assessment
      • Security BluePrint™ Consultancy Services

      © 2025 Simply Data Sdn Bhd. All rights reserved.

      • Terms & Conditions
      • Data Protection & User Privacy
      • Privacy Policy
      • Cookie Policy