Here’s the organized report based on the provided hacking activity: Attacker: F4k3-ScR!pT (Bangladeshi Hacker) 1. Target: https://shiro.muniriosantiago.gob.pe/fake.txt Source: link Victim Country: Peru Sector: Government – Involves a government domain related to public services or administration. De…
Tag: INDONESIA
This report highlights recent cyber threats targeting the financial sector, specifically focusing on malware and phishing incidents, credit card information leaks, database breaches, and ransomware attacks. Notable cases include the sale of Indian credit card …
Keypoints: Indonesia is among the countries experiencing ransomware incidents, accounting for 0.7% of global cases, indicating its susceptibility to sophisticated groups like Cactus. Cactus ransomware employs a multi-stage attack, including social engineering via email and Microsoft Teams, DLL sidel…
Keypoints: An Indonesian software programmer, Yohanes Nugroho, developed a method to brute-force the encryption of the Linux-based Akira ransomware variant. This offers a potential solution for Indonesian organizations and individuals who may fall victim to this global threat. The Akira ransomware,…
The finance industry is facing an increasing number of cyberattacks, with significant recent incidents exposing vast amounts of sensitive data. Notable breaches have involved major financial institutions and data theft, highlighting vulnerabilities and the nee…
The Cactus Ransomware Group employs a sophisticated multi-stage attack method, featuring social engineering and exploits to compromise targeted systems. Their toolkit includes ransomware delivery, stealthy lateral movement, and custom command-and-control tacti…
Group: root@x-krypt0n-x Target: https://library.bangda.kemendagri.go.id/me.php Source: zone-h Victim Country: Indonesia Sector: Government – This target appears to be a governmental library, indicating a focus on public sector information systems. Description: A website associated with a government…
Summary: A threat actor has claimed responsibility for a data breach of an Indonesian online student admission platform, allegedly compromising personal information of 13,291 users. The leaked data includes user credentials, full names, addresses, and registration dates, although these claims are ye…
Keypoints: The SideWinder APT group expanded its targets in 2024 to include maritime and logistics companies in Southeast Asia, with Indonesia being specifically identified as a targeted country. SideWinder primarily uses spear-phishing emails with malicious DOCX attachments exploiting the CVE-2017-…
Here’s a categorized report based on the provided list of hacked websites, grouped by attacker, along with the affected victim countries and sectors: Attacker: Simsimi – Target: https://binamarga.pu.go.id/jurnal/public/site/images/r34d/shelby.gif Source: zone-h.org Victim Country: Indonesia Sector:…
Summary: The U.S. Cybersecurity and Infrastructure Security Agency has added five critical vulnerabilities to its Known Exploited Vulnerabilities catalog, affecting Advantive VeraCore and Ivanti Endpoint Manager. These vulnerabilities, actively exploited by threat actors, include file upload and SQL…
SideWinder, an advanced persistent threat (APT) group, has intensified attacks targeting military, government, and logistics entities in various regions, particularly in Asia, Africa, and beyond. With sophisticated malware and exploitation techniques, includin…
Keypoints: Analysis of FlowerStorm, a phishing-as-a-service platform, reveals that 19 of its identified command and control domains were registered in Indonesia, indicating a direct connection to the country’s infrastructure. FlowerStorm emerged following the disruption of Rockstar2FA, suggesting a…
Here’s a summary of the hacked website reports based on the attackers, including the victim countries and sectors affected: Attacker: root./exe – Target: dewanganjbhata.gov.bd – Source: zone-h – Victim Country: Bangladesh – Sector: Government – This website appears to be part of the local government…
The article discusses the emergence of phishing-as-a-service (PhaaS) platform FlowerStorm, which gained traction following the shutdown of another operation, Rockstar2FA. Researchers identified a significant number of indicators of compromise (IoCs) linked to …