Whipweave Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
July 29, 2026
Last Seen
July 29, 2026

Whipweave is a malware family tracked by ThreatCluster, appearing in 1 threat cluster built from 1 intelligence report mention.

Whipweave is a malware family tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed July 29, 2026; most recent activity July 29, 2026.

Related Threat Clusters

  • Guangdong Chanming Sells Botnet to PLA for Cyber Operations

    Guangdong Chanming, a covert Chinese company, has been linked to the sale of a spy botnet to the People's Liberation Army (PLA) and various hacking groups. This botnet serves as an anonymous relay network, facilitating…

    2 articles · Updated July 29, 2026

Recent Intelligence Reports

  • Guangdong Chanming Sold Spy Botnet to PLA and Nearly a Dozen Chinese Hacking Groups — Techtimes · July 29, 2026

Frequently asked questions

What is Whipweave?

Whipweave is a malware family tracked by ThreatCluster, appearing in 1 threat cluster built from 1 intelligence report mention.

Is Whipweave still active?

The most recent intelligence report mentioning Whipweave on ThreatCluster is dated July 29, 2026.

What is Whipweave associated with?

Across ThreatCluster reporting, Whipweave most frequently co-occurs with Apt15, CSF 8th Bureau, Ke3chang, Nickel, Nylon Typhoon, among 12 tracked related entities.

What are the latest developments involving Whipweave?

The most significant recent cluster is “Guangdong Chanming Sells Botnet to PLA for Cyber Operations” (2 articles · Updated July 29, 2026). Whipweave appears across 1 threat cluster in total, listed above with sources.

How much reporting does ThreatCluster have on Whipweave?

Whipweave appears in 1 intelligence report mention across 1 deduplicated threat cluster, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown