logo

Beyond Tax Returns: How Shared Malware Infrastructure Scales Brand Abuse In Indonesia

ID: b189d2f7-077f-5e67-a176-dc488e52ceba

STIX ID: report--b189d2f7-077f-5e67-a176-dc488e52ceba

Feed Name: Group-IB Blog

Threat Score
78/100

Date Published: 2026-02-19

Date Updated: 2026-04-28

...
...

Group-IB reports a coordinated fraud campaign (Jul 2025–Jan 2026) impersonating Indonesia’s Coretax service to distribute sideloaded malicious Android apps that enable screen recording, accessibility abuse, and remote access (Gigabud.RAT, MMRat, Taotie). The GoldFactory-linked operation leverages phishing URLs, WhatsApp/social engineering, and vishing to coerce victims into payments, includes hundreds of phishing domains and 228+ samples, caused estimated national impact up to USD 1.5–2M (Jan 2026 extrapolated) and provides IOCs and mitigation guidance for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.