logo

The Price of Trust: Analyzing the Malware Campaign Exploiting TASPEN's Legacy to Target Indonesian Senior Citizens

ID: 70e5863e-1220-5e26-a767-a588d72d529f

STIX ID: report--70e5863e-1220-5e26-a767-a588d72d529f

Feed Name: CloudSEK Blog

Threat Score
80/100

Date Published: 2025-08-27

Date Updated: 2026-04-27

...
...

**Executive Summary:** A sophisticated, targeted Android malware campaign is impersonating PT Dana Tabungan dan Asuransi Pegawai Negeri (TASPEN) to distribute a banking trojan/spyware that harvests credentials, SMS OTPs, contacts and biometric video, uses DPT-Shell packing and Frida anti-analysis, maintains encrypted WebSocket C2 (wss://rpc.syids.top) for real-time control and exfiltration, and includes IoCs (domains, IP, hashes, hardcoded key); linguistic artifacts point to Chinese-speaking operators and the campaign poses systemic financial and trust risks to Indonesian pensioners and institutions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.