Beyond Tax Returns: How Shared Malware Infrastructure Scales Brand Abuse In Indonesia
ID: b189d2f7-077f-5e67-a176-dc488e52ceba
STIX ID: report--b189d2f7-077f-5e67-a176-dc488e52ceba
Feed Name: Group-IB Blog
Group-IB reports a coordinated fraud campaign (Jul 2025–Jan 2026) impersonating Indonesia’s Coretax service to distribute sideloaded malicious Android apps that enable screen recording, accessibility abuse, and remote access (Gigabud.RAT, MMRat, Taotie). The GoldFactory-linked operation leverages phishing URLs, WhatsApp/social engineering, and vishing to coerce victims into payments, includes hundreds of phishing domains and 228+ samples, caused estimated national impact up to USD 1.5–2M (Jan 2026 extrapolated) and provides IOCs and mitigation guidance for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
