There was one defacement incident targeting the website diskominsa.acehjayakab.go.id, with the attacker identified as jendralgbk. The incident highlights a cyberattack involving these specific entities.
#Indonesia…
There was one defacement incident targeting the website diskominsa.acehjayakab.go.id, with the attacker identified as jendralgbk. The incident highlights a cyberattack involving these specific entities.
#Indonesia…
Cybersecurity researchers have uncovered a large-scale spam campaign called IndonesianFoods, flooding the npm registry with over 67,000 fake packages designed to overwhelm the ecosystem. The campaign employs a worm-like propagation mechanism, exploiting manual script execution to sustain continuous spam uploads, potentially monetizing via the TEA protocol. #IndonesianFoods #npmspam #TEAprotocol…
There were 3 defacement incidents targeting Indonesia and other unspecified locations. The attackers involved are JENDRAL DOMBA, Komik, and NizamXploit. #Indonesia…
PT Wiraswasta Gemilang Indonesia (WGI), Indonesia’s leading private lubricant plant, has reportedly been targeted by the threat actor incransom, who claims to have compromised their systems. Evidence includes a small selection of screenshots indicating a ransomware attack impacting Indonesia. #Indonesia
The ransomware claim involves the infiltration of Sarulla Operation’s systems by the threat actor incransom, compromising sensitive data including financial operations, budgets, user information, and confidential documents such as passports, payment instructions, contracts, and more. The impacted country is Indonesia #Indonesia.
There have been 4 defacement incidents targeting websites in Cameroon, Indonesia, Madagascar, and Malaysia. The attackers involved are Mr. BDKR28, whanx708, Infinite Cyber Team, and jendralvera. #Cameroon #Indonesia #Madagascar #Malaysia…
Online casino SEO spam has surged since 2021, with attackers increasingly compromising WordPress sites to inject cloaked casino pages and backlinks, often targeting regions with strict gambling laws like Indonesia. The observed infection used layered redundancies—database-stored payloads, .dat files, theme/plugin modifications, and reinfection code—to persist and evade detection. #SlotGacor #browsec.xyz
The threat actor Stormous gained VPN access to the internal network of www.danareksa.com, a financial services company in Indonesia, and issued a ransomware claim. This incident underscores the vulnerability of Indonesian organizations to sophisticated cyber threats. #Indonesia
The threat actor Stormous claims to have gained VPN access to the internal network of www.wilmar.co.id, a company based in Indonesia, and has deployed ransomware to compromise the organization’s data. The attack has impacted Indonesia.
Chinese-linked APT actors used known exploitation scans and a multi-stage intrusion in April 2025 to establish persistent, stealthy access to a U.S. organization, employing DLL sideloading (vetysafe.exe -> sbamres.dll), legitimate binaries (msbuild.exe, Imjpuexc), scheduled tasks, a custom loader, and DCSync-like activity. #APT41 #Kelp #SpacePirates #Dcsync #DeedRAT
There have been 23 defacement incidents targeting multiple countries, primarily Indonesia, Argentina, and Thailand, with attackers including God Of Server, ZaXploit, Dods, and jendralvera. The incidents involved hacking and defacement of government, educational, and local websites. #Indonesia #Argentina #Thailand…
There have been 2 defacement incidents targeting websites in the country mentioned, with targets including disdikbud.papua.go.id and perpus.mtsn2balangan.sch.id. The attackers involved are HanzOFC and Komik. #Papua #Indonesia…
There have been multiple defacement incidents involving at least three countries, with a total of ten attacks documented. The attackers involved include jendralvera, syadlas_vgas, and Justinegate, targeting countries such as Indonesia, Zimbabwe, and Iran. #Indonesia #Zimbabwe #Iran…
XLab discovered RPX_Client, a previously undocumented PolarEdge relay component that onboards compromised IoT/edge devices into a proxy pool and enables remote command execution, linked to download infrastructure at 111.119.223.196 and corroborated by homology with known PolarEdge samples. The investigation identified 140 RPX_Server VPS nodes (port 55555) and over 25,000 infected devices across 40 countries, revealing an ORB network used for long-term stealth and traffic obfuscation. #PolarEdge #RPX_Client
There was 1 defacement incident targeting the website www.smkmerdekabdg.sch.id, carried out by attacker whanx708. The incident highlights the ongoing cyber threat posed by individual hackers to educational institutions in Indonesia. #Indonesia…