This extensive cyber operation, active for over 14 years, primarily targets Indonesian citizens through illegal gambling platforms, malware distribution, and website hijacking. Researchers suggest it also serves as a command and control hub, employing sophisticated techniques to evade detection. #Malanta #IndonesianCyberThreats…
Tag: INDONESIA
Cloudflare reports the mitigation of the largest DDoS attack ever recorded at 29.7 Tbps, originating from the AISURU botnet. This attack highlights the increasing size, sophistication, and targeting of DDoS threats, especially affecting industries such as telecommunications, gaming, and AI. #AISURU #DDoSattacks…
Predator is a modular, stealthy mercenary spyware developed by Cytrox and distributed via an Intellexa-linked corporate web, enabling full access to microphones, cameras, and all device data on Android and iPhone devices. The report maps Intellexa’s fragmented corporate infrastructure, documents delivery methods including “1-click” and ad-based (“Aladdin”) vectors, and details observed deployments across multiple countries alongside mitigations and ongoing investigations. #Predator #Intellexa
There are 2 defacement incidents targeted at Indonesian schools. The attackers involved are Zyfnar. #Indonesia…
There have been a total of 11 defacement incidents targeting Indonesia and the Philippines. The attackers involved are d4nu ghost, Zyfnar, and Terror. #Indonesia #Philippines…
The agency “Badan Pengelola Keuangan Haji” (BPKH) in Indonesia has fallen victim to a ransomware attack purportedly carried out by the threat actor blackshrantac, affecting its financial management operations. This incident compromises the security of funds allocated for the Hajj pilgrimage, impacting Indonesia. #Indonesia
This week highlighted the resurgence of Mirai-based IoT malware and the increasing sophistication of cybercriminal techniques such as AI-powered scams and stealthy malware targeting email servers. Governments and security companies are actively fighting back through regulation, upgrades, and takedowns. #ShadowV2 #Mirai #OpenFind…
Data regulators in Thailand have banned Tools for Humanity from collecting iris scans for cryptocurrency payments, citing violations of the Personal Data Protection Act. The company has been ordered to delete 1.2 million iris scans, amid global bans on similar iris recognition projects. #ToolsForHumanity #IrisScanBan…
Acronis TRU researchers uncovered a novel “JackFix” ClickFix campaign that hijacks the browser to display a convincing full‑screen fake Windows Update prompting victims to run malicious commands. The multistage attack (mshta → PowerShell downloader → final payloads) uses heavy obfuscation, UAC bombardment and a “spray and prey” downloader that executes up to eight payloads including Rhadamanthys and Vidar 2.0, and is detected and blocked by Acronis XDR at the PowerShell stage. #ClickFix #Rhadamanthys
CyberArmor’s report reveals a sophisticated espionage campaign named “Autumn Dragon” targeting Southeast Asian governments and media, possibly linked to Chinese threat actors. The campaign employs a complex malware chain involving DLL sideloading, Telegram C2, and encrypted payloads to gather intelligence covertly. #AutumnDragon #ChinaNexus…
Researchers discovered a massive data leak involving 3.5 billion WhatsApp accounts through abuse of an API lacking rate limiting, exposing personal information worldwide. WhatsApp responded by adding protections, but the incident highlights a common vulnerability in unprotected APIs exploited by threat actors. #WhatsApp #APITraffic #DataLeak
Cybersecurity researchers have uncovered a multi-year ATM fraud campaign by the UNC2891 threat group targeting Indonesian banks, utilizing advanced malware and social engineering tactics. The campaign involved cloned cards, money mule networks, and persistent system infiltration, highlighting the evolving nature of ATM-based cyber threats. #UNC2891 #STEELCORGI #CAKETAP #ATMrotection #BankA #BankB…
A China-linked threat actor known as APT24 has been using sophisticated malware called BADAUDIO to maintain persistent access to compromised networks through a campaign spanning nearly three years. The campaign includes supply chain attacks, web compromises, and spear-phishing, primarily targeting organizations in Taiwan and Southeast Asia. #APT24 #BADAUDIO…
Security researchers identified Android.Backdoor.Baohuo.1.origin embedded in tainted Telegram X builds, capable of stealing logins, passwords, and chat histories. The backdoor conceals connections from third-party devices in Telegram sessions, hijacks channels……
An alleged data breach involving the Ministry of Cooperatives of the Republic of Indonesia has raised concerns about the security of sensitive government information. The incident highlights potential vulnerabilities in government data management and confidentiality. #MinistryofCooperatives #IndonesiaDataBreach…