Also known as: cpyy, APT3, Gothic Panda, UPS Team, TG-0110, DeputyDog, Parastoo, Newscaster, APT28, Pawn Storm, Fancy Bear, Sednit, MiniDionis, Hammertoss, Chinastrats, Patchwork
INDOHAXSEC TEAM emerges as an Indonesian hacktivist unit with strong pro‑Palestinian, anti‑Israel rhetoric. The group portrays itself as capable of deploying a web‑based variant of WannaCry, encrypting site files and filenames to demand Bitcoin, though concrete evidence for widespread ransomware attacks remains limited. In operational practice, the collective has released PHP backdoors such as Avaa Bypassed that drop multipurpose scripts onto compromised web servers. It also distributes a Python/Node.js DDoS toolkit called NUKLIR and an XSS vulnerability scanner known as Xss_Fucker to probe for exploitable sites. Site‑encryption malware dubbed Dancokware has been observed encrypting both file contents and name metadata, a technique that hampers recovery and forces extortion. The actors frequently engage in political propaganda by doxxing public officials on social media platforms like X/Twitter. They post under a TikTok handle (@akunthisiadi) to promote tools, while using GitHub commits with unusually timestamped activities to coordinate activity. Despite claims of large‑scale ransomware campaigns against Indian and Malaysian organizations, the actual breadth of impact is not yet confirmed. Overall, INDOHAXSEC operates at the intersection of political hacktivism and opportunistic cybercrime, employing web‑shell vectors and web‐surface attacks rather than sophisticated zero‑day exploits. Their public statements suggest ambitions to inflict widespread disruption, but their true technical reach remains subject to confirmation.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
INDOHAXSEC TEAM is an Indonesian collective that blends political hacktivism with opportunistic cybercrime. They claim to deploy web‑based ransomware and DDoS toolkits while conducting XSS scanning and doxxing campaigns, targeting a broad range of sectors worldwide. Their technical capabilities are uncertain but they actively target governments, defense sites, and politically sensitive entities.
Goals & Targeting
The group’s strategic objectives appear dual‑pronged: a political mission to undermine Israel and allies through public doxxing and propaganda, coupled with opportunistic financial gain via ransomware‑style extortion. Their long‑term goal seems to be sustained pressure on high‑profile government and private sector entities across the globe, leveraging their web‐based tooling to create leverage points for extortion or to amplify political messaging.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
INDOHAXSEC’s campaigns are opportunistic and politically charged, often timed with regional incidents or protests. They leverage publicly available web application vulnerabilities (primarily PHP) to drop backdoors, then use site encryption or DDoS attacks to coerce victims into payment or compliance. The group frequently announces activities on social media for propaganda purposes and engages in targeted doxxing of officials to further political narratives. Victims have spanned government sites, defense contractors, telecommunication providers, and high‑profile non‑profit entities across many countries, suggesting a wide operational footprint.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The assessment is held at a moderate confidence level. Multiple reports and publicly disclosed IOCs provide evidence of PHP-based backdoors, encryption malware, and DDoS tooling; however, claims regarding large‑scale ransomware deployment (e.g., WannaCry‑2.0) lack corroborating samples or documented victims. Attribution to the Indonesian collective remains based on self‑identified aliases but lacks independent verification from malware analysis. Information gaps persist around the actual extent of victimization, precise timelines of campaigns, and definitive links between public statements and technical activity.
No campaigns linked yet.
No observed data linked yet.
3
Techniques
48
Tools
0
Campaigns
38
IOCs
0
Observed Data
3
Tactics