The Gentlemen is an operationally disciplined ransomware group first observed in mid-to-late 2025 that conducts double‑extortion attacks across Windows, Linux, NAS, BSD, and ESXi environments using password‑protected, operator-driven builds. Their campaigns leverage exposed internet-facing services and compromised administrative credentials, and victims have been publicly listed on a Dark Web leak site. #TheGentlemen #ESXi
Tag: INDONESIA
There were 2 defacement incidents targeting websites in Indonesia and Brazil. The attackers involved were Maria and p2wnz. #Indonesia #Brazil…
A state-sponsored threat actor tracked as TGR-STA-1030/UNC6619 conducted global espionage operations called “Shadow Campaigns,” compromising at least 70 government and critical infrastructure organizations across 37 countries and conducting reconnaissance against entities in 155 countries. The group used tailored phishing with Mega.nz-hosted archives, the Diaoyu loader (delivering Cobalt Strike and VShell), multiple exploit chains, and a custom eBPF Linux rootkit named ShadowGuard to evade detection and maintain persistent access. #TGR-STA-1030 #ShadowGuard
There were 8 defacement incidents targeting websites in Nigeria, Indonesia, and Pakistan. The attackers involved were Hmei7, y4nch, NizamXploit, and Maria. #Nigeria #Indonesia #Pakistan…
The AISURU/Kimwolf botnet launched a record-setting hyper-volumetric HTTP DDoS attack in November 2025 that peaked at 31.4 Tbps for 35 seconds and later ran the “The Night Before Christmas” campaign with wins up to 24 Tbps and 9 Bpps. Cloudflare and Google disrupted the supporting IPIDEA residential proxy infrastructure that had…
There were 10 defacement incidents targeting websites in Samoa, Kenya, Thailand, Bolivia, and Indonesia. The incidents were carried out by attackers identified as White System’./404, Rici144, Hunter Bajwa, and Maria. #Samoa #Kenya #Thailand #Bolivia #Indonesia…
A Chinese-aligned threat group known as Amaranth-Dragon rapidly weaponized a WinRAR path traversal flaw (CVE-2025-8088) to deliver malicious RAR archives that execute code when opened, targeting government and law enforcement agencies across Southeast Asia. The attackers deploy an Amaranth loader to fetch Havoc C2 payloads and a TGAmaranth RAT that uses…
Unit 42 attributes a large-scale, state-aligned cyberespionage campaign — tracked as TGR-STA-1030 and called the Shadow Campaigns — to an Asia-based actor that has compromised government and critical infrastructure across 37 countries using phishing, exploitation, C2 frameworks and a novel eBPF rootkit. The group used tools including Diaoyu Loader, Cobalt Strike,…
There were 5 defacement incidents targeting websites in the Dominican Republic and Indonesia. The attackers involved were Typical Idiot Security, L4663R666H05T, and Maria. #DominicanRepublic #Indonesia…
Amaranth-Dragon (a nexus linked to APT-41) ran highly targeted 2025 espionage campaigns across Southeast Asia using weaponized archives that exploited WinRAR CVE-2025-8088, custom Amaranth Loader, Havoc C2, and a new Telegram-based TGAmaranth RAT. The campaigns used geo-restricted Cloudflare-protected C2s, legitimate hosting (Dropbox, Pastebin), DLL sideloading, and payload encryption to maximize stealth and persistence. #Amaranth-Dragon #TGAmaranth
Amaranth Dragon, a threat actor linked to APT41, has been conducting espionage attacks against government and law enforcement organizations across Southeast Asia by exploiting the WinRAR path traversal flaw CVE-2025-8088. The group used legitimate tools alongside a custom Amaranth Loader and Cloudflare-backed C2 infrastructure to deliver encrypted payloads (including the Havoc framework and the TGAmaranth RAT), employ strict geofencing, and maintain stealth and persistence. #AmaranthDragon #CVE2025-8088 #WinRAR #TGAmaranthRAT
There were 6 defacement incidents targeting websites in Brazil, Indonesia, and Mongolia. The attackers involved were diparis, Maria, and Crypth0nX. #Brazil #Indonesia #Mongolia…
There were 10 defacement incidents targeting websites in Peru and Indonesia. Attackers involved include CyberTeam, y4nch, vyers, Maria, and Mr.XycanKing #Peru #Indonesia….
There were 4 defacement incidents targeting websites in Brazil and Indonesia, including a São Paulo legislative page and several Indonesian school sites. The attacks were carried out by 0x1998 and Maria. #Brazil #Indonesia…
Thegentlemen claim a ransomware attack against Handsome Manufacturing, a Hong Kong-based OEM producer founded in 1968, with encrypted systems and a ransom demand. Handsome’s global partnerships and production facilities in China and Indonesia imply potential disruption to major brands and supply chains. #HongKong#China#Indonesia