Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Beyond Tax Returns: How Shared Malware Infrastructure Scales Brand Abuse In Indonesia

djp.otuind.cc

TLP:CLEAR
Active

Domain

Description

A sophisticated fraud campaign exploiting Indonesia's tax season targeted 67 million residents through fake Coretax applications distributed via phishing websites and WhatsApp social engineering. The GoldFactory threat cluster orchestrated operations using Gigabud.RAT and MMRat malware families with shared infrastructure abusing over 16 trusted brands across government and financial sectors. The attack chain combines vishing, screen recording, and remote access capabilities to achieve device compromise and unauthorized financial transfers. Estimated financial impact reaches USD 1.5-2 million nationwide, with global implications extending to USD 6 million annually across multiple countries. The industrialized malware-as-a-service infrastructure enables horizontal scaling across Thailand, Vietnam, Philippines, and South Africa, demonstrating a shift toward unified cross-border operations that systematically undermine trust in digital government services.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Beyond Tax Returns: How Shared Malware Infrastructure Scales Brand Abuse In Indonesia
Pattern Type
STIX
Confidence
75%
Valid From
May 26, 2026 02:42
Total Sightings
0
Added
May 26, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of djp.otuind.cc

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.