There were 3 defacement incidents targeting websites in Indonesia. The attacker involved was Maria. #Indonesia…
Tag: INDONESIA
Arsink is a cloud-native Android RAT that exfiltrates extensive personal data and grants remote operators intrusive control over infected devices while abusing legitimate cloud services for C2 and media/file exfiltration. The campaign deployed 1,216 distinct APKs across global social-engineered distribution channels and used 317 Firebase Realtime Database endpoints, Google Apps Script/Drive, and Telegram for C2 and exfiltration. #Arsink #Firebase
The Aisuru/Kimwolf botnet launched a record-breaking DDoS campaign that peaked at 31.4 Tbps and generated over 200 million HTTP requests per second, targeting telecommunications providers, IT organizations, and Cloudflare’s dashboard and infrastructure. Cloudflare reported it detected and automatically mitigated the attacks on December 19 and noted a 121% year-over-year increase in…
The claim attributes the ransomware to the tengu group and the Tahkout Group, citing targets such as skyegtours.com, KSP TLM, COMPAGNIE FONCIÈRE PARISIENNE, lenotech.com.ph, Jakarta, Nanyang School, and namico.go.ke, with all data reportedly compromised. The claim implies encryption or exfiltration of all data across these entities, with impacted country coverage including Indonesia, the Philippines, and Kenya. #Indonesia #Philippines #Kenya
Two defacement incidents were reported targeting Indonesian school websites (sekolahbppi.sch.id and adm.smansal.sch.id). Both incidents were carried out by an attacker named Maria. #Indonesia…
There were 3 defacement incidents targeting websites in Indonesia: absensi.mtsislamiyahmalo.sch.id, www.ppdbm2b.man2banjarnegara.sch.id, and ppdb.smppaq.sch.id. All three attacks were carried out by an attacker named Maria. #Indonesia…
Russian and Chinese state-backed groups and financially motivated actors have been exploiting CVE-2025-8088 in WinRAR to drop malware into Windows Startup folders using a path traversal vulnerability combined with Alternate Data Streams. The flaw remained widely abused months after RARLAB released WinRAR 7.13, with actors like UNC4895 (RomCom), APT44 (FROZENBARENTS), Turla,…
Malicious open source packages surged into industrialized, large-scale campaigns in 2025, with researchers identifying more than 454,600 new malicious packages across npm, PyPI, Maven Central, NuGet, and Hugging Face and attacks increasing in sophistication. The report spotlights npm as the primary vector—featuring self-replicating packages like Shai-Hulud, activity from threat actors such…
There were 5 defacement incidents targeting Indonesian school websites: surat.m1g.sch.id; surat.yppalbadriyah.my.id.aliy…; surat.aliyahalbadriyah.sch.id; skl-smk.namboardingschool.sch….; and skl.sman5magelang.sch.id. All five incidents were carried out by the attacker Maria and targeted domains in Indonesia. #Indonesia…
Google’s Threat Intelligence Group warns that a path-traversal flaw in WinRAR (CVE-2025-8088) disclosed and patched six months ago is still being actively exploited by a diverse set of attackers. Nation-state actors linked to Russia and China and financially motivated cybercriminals have been deploying silent, no-interaction payloads into critical locations like the…
The GTIG reported widespread exploitation of CVE-2025-8088 in WinRAR using Alternate Data Streams and path traversal to drop payloads into the Windows Startup folder for persistence across state-sponsored and financially motivated campaigns. Defenders are urged to patch immediately and hunt for indicators such as malicious RAR archives, LNK/HTA/BAT/CMD payloads, and the provided SHA-256 hashes. #CVE-2025-8088 #WinRAR
Threat actor tengu claims to have compromised KSP TLM Indonesia, a large cooperative savings and loan association in Indonesia that focuses on empowering the community economy—especially small and medium-sized female entrepreneurs. The claim frames this as ransomware activity against the victim in Indonesia #Indonesia
There were 9 defacement incidents targeting websites in Argentina, Mongolia, and Indonesia. The attacks were carried out by BontenSec, Typical Idiot Security, Maria, and T-XpLoiT. #Argentina #Mongolia #Indonesia…
There were 11 defacement incidents targeting websites in Indonesia, Bangladesh, and Mongolia. The attacks were carried out by two attackers, T-XpLoiT and Maria. #Indonesia #Bangladesh #Mongolia…
There were 23 defacement incidents targeting websites in Pakistan, Thailand, Mexico, Bangladesh, and Indonesia. The incidents were carried out by the following attackers: L4663R666H05T; White System’./404; M@rAz Ali; ryoZenith; Maria; NizamXploit; and TOMODACHI. #Pakistan #Thailand #Mexico #Bangladesh #Indonesia…