Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors INDOHAXSEC TEAM

Also known as: cpyy, APT3, Gothic Panda, UPS Team, TG-0110, DeputyDog, Parastoo, Newscaster, APT28, Pawn Storm, Fancy Bear, Sednit, MiniDionis, Hammertoss, Chinastrats, Patchwork

Description

INDOHAXSEC TEAM emerges as an Indonesian hacktivist unit with strong pro‑Palestinian, anti‑Israel rhetoric. The group portrays itself as capable of deploying a web‑based variant of WannaCry, encrypting site files and filenames to demand Bitcoin, though concrete evidence for widespread ransomware attacks remains limited. In operational practice, the collective has released PHP backdoors such as Avaa Bypassed that drop multipurpose scripts onto compromised web servers. It also distributes a Python/Node.js DDoS toolkit called NUKLIR and an XSS vulnerability scanner known as Xss_Fucker to probe for exploitable sites. Site‑encryption malware dubbed Dancokware has been observed encrypting both file contents and name metadata, a technique that hampers recovery and forces extortion. The actors frequently engage in political propaganda by doxxing public officials on social media platforms like X/Twitter. They post under a TikTok handle (@akunthisiadi) to promote tools, while using GitHub commits with unusually timestamped activities to coordinate activity. Despite claims of large‑scale ransomware campaigns against Indian and Malaysian organizations, the actual breadth of impact is not yet confirmed. Overall, INDOHAXSEC operates at the intersection of political hacktivism and opportunistic cybercrime, employing web‑shell vectors and web‐surface attacks rather than sophisticated zero‑day exploits. Their public statements suggest ambitions to inflict widespread disruption, but their true technical reach remains subject to confirmation.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Non profit
Telecommunications
Aerospace
Energy
Media
Healthcare
Pharmaceutical
Education
Information technology
Maritime
Manufacturing
Think tank
Entertainment
Gaming
Chemical
Retail
Hospitality
Transportation
Nuclear
Construction
Food agriculture
Legal services
Mining

Targeted Countries / Regions

US
CN
GB
IN
KR
JP
DE
RU
IL
FR
CA
IR
SA
TW
TR
AU
PK
KZ
ES
BR
SG
NL
IT
UA
PL
BY
VN
IQ
RO
MX
AE
AZ
SY
LB
EG

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 1 day ago

Executive Summary

INDOHAXSEC TEAM is an Indonesian collective that blends political hacktivism with opportunistic cybercrime. They claim to deploy web‑based ransomware and DDoS toolkits while conducting XSS scanning and doxxing campaigns, targeting a broad range of sectors worldwide. Their technical capabilities are uncertain but they actively target governments, defense sites, and politically sensitive entities.

Goals & Targeting

The group’s strategic objectives appear dual‑pronged: a political mission to undermine Israel and allies through public doxxing and propaganda, coupled with opportunistic financial gain via ransomware‑style extortion. Their long‑term goal seems to be sustained pressure on high‑profile government and private sector entities across the globe, leveraging their web‐based tooling to create leverage points for extortion or to amplify political messaging.

Enhanced Description

Key Capabilities

  • PHP backdoor dropper that downloads multipurpose backdoors (e.g., Avaa Bypassed)
  • Python/Node.js based DDoS toolkit (NUKLIR)
  • XSS vulnerability scanner (Xss_Fucker)
  • Website encryption malware that encrypts files and filenames (Dancokware)
  • Claims of deploying a WannaCry‑2.0 variant for extortion
  • Doxxing campaigns via X/Twitter targeting officials

MITRE ATT&CK Tactics

Execution
Impact

ATT&CK Techniques

T1059
T1105
T1499

Software / Tooling

Avaa Bypassed
NUKLIR
Xss_Fucker
Dancokware
warning.php
white.php
Ark‑Cheat‑Detector
FidzXploit

Campaigns & Victims

INDOHAXSEC’s campaigns are opportunistic and politically charged, often timed with regional incidents or protests. They leverage publicly available web application vulnerabilities (primarily PHP) to drop backdoors, then use site encryption or DDoS attacks to coerce victims into payment or compliance. The group frequently announces activities on social media for propaganda purposes and engages in targeted doxxing of officials to further political narratives. Victims have spanned government sites, defense contractors, telecommunication providers, and high‑profile non‑profit entities across many countries, suggesting a wide operational footprint.

IOC Patterns

  • Unauthorized PHP script uploads
  • Website file encryption signatures (encrypted names + contents)
  • XSS scanning scripts inserted into web applications
  • Doxxing activity on X/Twitter
  • Unusual GitHub commit timestamps for malware delivery
  • TikTok handle @akunthisiadi used for tool dissemination

Recommended Actions

  • Secure web servers by restricting unauthorized PHP script uploads and enforcing directory permissions
  • Implement comprehensive file integrity monitoring to detect anomalous encryption or new backdoor files
  • Enforce least privilege for admin accounts, disable unused services, and apply strict access controls on web content management systems
  • Apply timely patches for known CVEs, including notable ones such as CVE‑2026‑0257 that affect PHP applications
  • Deploy Web Application Firewalls (WAFs) with XSS detection rules to prevent exploitation by scanners like Xss_Fucker
  • Monitor social media channels (X/Twitter, TikTok) for doxxing or campaign announcements and feed alerts into SOC workflows

Suggested Tags

DDoS toolkit
WebShell
Ransomware
Political hacktivism
Iran/Israel conflict
Indonesian threat actor
Anti-Israel sentiment
Pro‑Palestinian

Confidence Assessment

The assessment is held at a moderate confidence level. Multiple reports and publicly disclosed IOCs provide evidence of PHP-based backdoors, encryption malware, and DDoS tooling; however, claims regarding large‑scale ransomware deployment (e.g., WannaCry‑2.0) lack corroborating samples or documented victims. Attribution to the Indonesian collective remains based on self‑identified aliases but lacks independent verification from malware analysis. Information gaps persist around the actual extent of victimization, precise timelines of campaigns, and definitive links between public statements and technical activity.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 10 SHA-256 Hash 10

References

  1. chintangurjar.com — Cited by web research for: cpyy
  2. arcticwolf.com — Cited by web research for: Telegram
  3. https://www.enisa.europa.eu/sites/default/files/2026-01/ENISA%20Threat%20Landscape%202025_v1.2.pdf — Cited by AI analysis.

Intel Summary

3

Techniques

48

Tools

0

Campaigns

38

IOCs

0

Observed Data

3

Tactics

Tags

Ransomware
APT
Financial Crime
Indonesia-focused
Web Applications
DDoS toolkit
WebShell
Political hacktivism
Iran/Israel conflict
Indonesian threat actor
Anti-Israel sentiment
Pro‑Palestinian

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
I
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.