Industrial-Scale Fake Coretax Apps Drive $2m Fraud in Indonesia
ID: 904ec74f-2104-5b9d-bef4-4992c50805fe
STIX ID: report--904ec74f-2104-5b9d-bef4-4992c50805fe
Feed Name: Infosecurity Magazine (News)
Group-IB uncovered a sophisticated fraud campaign attributed to the GoldFactory cluster that impersonated Indonesia’s Coretax service to trick taxpayers into installing malicious Android APKs; the multi-stage attack combined phishing links, WhatsApp impersonation, vishing calls, and RATs (Gigabud.RAT, MMRat) to harvest credentials, record screens, perform account takeovers, and facilitate mule transfers, resulting in an estimated $1.5–2M nationwide impact and the discovery of 228 malware samples and 996 phishing URLs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
