Cisco Talos discovered a new threat actor we’re calling “CoralRaider” that we believe is of Vietnamese origin and financially motivated. CoralRaider has been operating since at least 2023, targeting victims in several Asian and Southeast Asian countries….
Tag: INDONESIA
Generative AI tools are being used worldwide to produce realistic deepfake audio, video, and images that political actors and foreign influencers deploy to sway public opinion and disrupt elections. These techniques are readily available on open platforms and …
A threat actor has emerged, claiming to offer unauthorized access to databases (MySQL) of mobile loan applications operating in Indonesia. It is claimed that there are a total of 11 databases associated with various applications. These databases contain vast amounts of diverse information, including…
RansomHub is a newly emerged ransomware group operating as a ransomware-as-a-service (RaaS) with an affiliate model and a policy aimed at rewarding partners, including a 90/10 revenue split and a decryptor promise under certain conditions. Their victimology sp…
Established in 1995, Indonesia Power, formerly known as PT Pembangkitan Jawa Bali I, operates through its 127 power plants, with a total capacity of 8.888 MW. Indonesia Power is headquartered in South Jakarta and is the largest electricity Power Generating Company
The victims were lured into slavery with false job offers and were forced to adopt fake identities to extract money from their victims through promises of cryptocurrency wins, investments, and romance.
ShinyHunters (aka ShinyCorp) is a global cybercrime group known for major data breaches and owning BreachForums. The article details their methods, notable victims like Tokopedia, Wattpad, and AT&T, and their evolution on dark web platforms, including a member…
Indoarsip is a leading provider of archival solutions, dedicated to preserving and managing critical documents and records for organizations across Indonesia. With a strong presence in the archiving industry, Indoarsip offers comprehensive services and innovative technologies to meet the diverse needs of its clients.
GhostSec, a prominent actor within The Five Families, has evolved from hacktivism toward ransomware activity, including a twin attack with Stormous. The group promotes its own tools and a GhostLocker RaaS ecosystem, with operations spanning dark-web tutorials,…
In my free time, i updated “Indonesia got Hacked! on telegram. Web defacement is a cyber attack where hackers alter the visual appearance or content of a website. It’s essentially digital vandalism. Motives: Bragging rights: Hackers might deface a website to showcase their skills or promote the…
GitHub users accidentally exposed 12.8 million authentication and sensitive secrets in over 3 million public repositories during 2023, with the vast majority remaining valid after five days. […]…
A new version of the infamous GhostLocker ransomware has been developed by cyber criminals, and they are now targeting users across the Middle East, Africa, and Asia with this ransomware. With the help of the new GhostLocker 2.0 ransomware, two ransomware groups have joined forces in attacking organ…
The cybercrime group called GhostSec has been linked to a Golang variant of a ransomware family called GhostLocker.
“TheGhostSec and Stormous ransomware groups are jointly conducting double extortion ransomware attacks on various business verticals in multiple countries,” Cisco Talos researcher Chetan Raghuprasad said in a report shared with The Hacker News.
“GhostLocker and
The Treasury Department announced Tuesday it has sanctioned two people and a Greece-based commercial spyware company headed by a former Israeli military officer that developed, operated and distributed technology used to target U.S. government officials, journalists and policy experts. The sanctions…
Ransomware cybercrime gangs GhostSec and Stormous have teamed up in widespread double-extortion attacks.