Indonesia Under Cyberattacks: Analyzing Threat Actors
ID: 24eb8a13-c53a-5348-8b7f-46d0710ccba6
STIX ID: report--24eb8a13-c53a-5348-8b7f-46d0710ccba6
Feed Name: Cyble Blog
Cyble Research analyzed a series of coordinated cybercrime activities targeting Indonesian entities in mid‑2021, including an alleged 200M+ PII data leak (claiming 279M records) sold on RaidForums and mass exploitation of vulnerable websites posted to GitHub and forums. Threat actors (aliases such as Kotz and AkuCintaMamaMuda and groups like RaidForum Indo Cyber/DragonForce Malaysia) used automated tools (e.g., SQLMap) to exfiltrate databases, shared tools/tutorials on Telegram, and conducted DDoS and breach campaigns impacting government, education, health, and commercial portals; the report includes impacted asset types, sample leaked data, TTP diagrams, and remediation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
