There were 14 defacement incidents targeting websites in Thailand, Mexico, and Indonesia. The attackers involved were EXA-DOS, aDriv4, y4nch, syadlas_vgas, and Maria. #Thailand #Mexico #Indonesia…
Tag: INDONESIA
There were 10 defacement incidents targeting Indonesian school websites (all targets are .sch.id domains) in Indonesia. The attacker involved in all incidents is Maria #Indonesia…
Elastic Security Labs discovered a multi-stage ClickFix campaign that compromises legitimate websites to deliver a five-stage chain culminating in a custom native RAT called MIMICRAT. The attack uses an obfuscated PowerShell downloader with ETW and AMSI bypass, a Lua-based in-memory loader and Meterpreter-like shellcode, and a C++ implant with token impersonation and SOCKS5 tunneling. #MIMICRAT #ClickFix
A sophisticated fraud campaign exploiting Indonesia’s official Coretax tax platform has caused an estimated nationwide financial impact of $1.5m to $2m. Beginning in July 2025 and surging during the January 2026 tax filing period, the operation impersonated Coretax to distribute malicious APKs via phishing sites, WhatsApp and vishing, and was linked…
Lotus Blossom is a long-running, China-attributed APT that evolved from spear-phishing and watering-hole campaigns into sophisticated supply-chain compromises and targeted espionage using custom implants like Elise, Sagerunex, Hannotog, and Chrysalis. The group’s Notepad++ update-channel compromise and prior attacks against diplomatic, military, and maritime infrastructure demonstrate a “low-and-slow” intelligence collection approach emphasizing DLL sideloading, living-off-the-land techniques, and clandestine persistence. #LotusBlossom #Chrysalis
CloudSEK and follow-up research focused on QakBot as a top access trojan/loader that is commonly distributed via phishing, harvests credentials, maintains C2 access, delivers payloads, and moves laterally to enable targeted attacks and ransomware against email-reliant enterprises. The investigation analyzed Trellix IoCs (extracted 929 domains, filtered to 492, studied 125), 19 subdomains, multiple client and infrastructure IPs, and thousands of email-connected domains, identifying specific malicious artifacts (e.g., books[.]ttc[.]edu[.]sg -> 200[.]69[.]23[.]93) and providing a downloadable dataset for further hunting. #QakBot #Trellix
13 defacement incidents targeted websites in Brazil, the Philippines, Pakistan and Indonesia; attackers included spl1nt3r, Typical Idiot Security, Anonymous Davao Philippines, unknown_*3x and Maria. #Brazil #Philippines #Pakistan #Indonesia…
There were 4 defacement incidents targeting Pakistan and Indonesia, involving attackers unknown_*3x, Team Tai core, Team kcd core, and YamiFool. Affected sites included multiple .gos.pk government subdomains and an .id school domain. #Pakistan #Indonesia…
There were 11 defacement incidents targeting websites in Mozambique (.mz), Indonesia (.id) and Paraguay (.py). The attackers involved were /Rayzky_, Maria and omgsmok. #Mozambique #Indonesia #Paraguay…
There were 10 defacement incidents targeting websites in Indonesia (domains ending in .id), affecting multiple school and library sites across the country. The attackers involved are Maria and Ghost Haxor (Maria responsible for seven incidents and Ghost Haxor for three) #Indonesia…
Ransomware claim alleges that PT Ikapharmindo Putramas, a Jakarta-based pharmaceutical company, was targeted by the threat actor coinbasecartel, potentially resulting in file encryption and data exfiltration. The claim describes operational disruptions and possible exposure of sensitive health and business data, but there is no independent verification. #Indonesia
There were 12 defacement incidents targeting websites in Indonesia and Jordan. The attackers involved are Maria and omgsmok; the targets are primarily Indonesian school sites (various .id domains) and one Jordanian government site (www.cvdb.gov.jo). #Indonesia #Jordan…
There were 40 defacement incidents targeting websites in Indonesia and Pakistan. The incidents involved attackers identified as omgsmok, Theremis and Maria. #Indonesia #Pakistan…
DomainTools Investigations | Lotus Blossom (G0030) and the Notepad++ Supply-Chain Espionage Campaign
Investigators determined the Notepad++ update mechanism (WinGUp/GUP.exe) was subverted for roughly six months to selectively deliver trojanized installers to a narrow set of high-value targets without modifying the project’s source code. The operation is attributed with moderate–high confidence to the China-aligned espionage cluster Lotus Blossom, which deployed bespoke implants (notably Chrysalis), DLL sideloading, and API-style HTTPS C2 to enable long-term intelligence collection. #LotusBlossom #Chrysalis
Fancy Bear (APT28) remains an active Russian state‑aligned espionage actor that quickly adopts newly disclosed vulnerabilities and uses spear‑phishing and credential harvesting to maintain long‑term access to government, defense, energy, and communications targets. The group recently weaponized a Microsoft Office vulnerability to compromise organizations in Eastern Europe and the EU, demonstrating a shift toward lightweight, high‑ROI tradecraft. #FancyBear #CVE-2026-21509