Also known as: tracked as
Indonesia's Banking, Financial Services, and Insurance sector faced significant cyber threats throughout 2026, including multiple alleged data breaches targeting major banking institutions and fintech platforms. Underground forums advertised compromised datasets containing customer information, account details, and sensitive documents, with varying levels of validation. Ransomware groups ICARUS and The Gentleman conducted extortion campaigns against financial organizations. China-linked APT groups including SilverFox, Mustang Panda, Amaranth-Dragon, Lotus Blossom, and Shadow Campaigns demonstrated sophisticated capabilities through phishing operations, supply chain compromises, and zero-day exploitation. These state-aligned actors deployed advanced malware such as ValleyRAT, ABCDoor, LOTUSLITE, and custom backdoors for long-term espionage. The expanding digital banking ecosystem and regional financial connectivity have increased attack surfaces, requiring enhanced cyber resilience, continuous monitoring, a...
Targeted Sectors
Targeted Countries / Regions
Executive Summary
The threat actors SilverFox, Mustang Panda, Amaranth-Dragon, Lotus Blossom, Shadow Campaigns, Triplex, Icarus, and The Gentleman represent a mix of state-sponsored Advanced Persistent Threat (APT) groups and ransomware operators. They target financial services, government, communications, transportation, and aerospace sectors across multiple countries, including Indonesia, India, Japan, Russia, South Africa, and Thailand. Their activities include sophisticated cyberattacks such as phishing campaigns, supply chain compromises, and zero-day exploitation, coupled with ransomware deployment, posing significant risks to critical infrastructure and data integrity.
Goals & Targeting
These actors target sectors critical to national security and economic stability, including financial services, government, communications, transportation, and aerospace. Their strategic focus on countries like Indonesia, India, Japan, Russia, South Africa, and Thailand suggests a geopolitical agenda aligning with potential state interests. The targeted industries are chosen for their access to sensitive information and high-value assets, making them prime targets for both espionage and financial gain.
Enhanced Description
The actors SilverFox, Mustang Panda, Amaranth-Dragon, Lotus Blossom, and Shadow Campaigns are associated with China-linked APT groups known for their advanced capabilities in cyber espionage. In 2026, these groups were linked to several significant cyber threats against Indonesia's banking, financial services, and insurance sectors. Their operations include deploying malware such as ValleyRAT and LOTUSLITE for long-term espionage and conducting supply chain compromises. The ransomware groups ICARUS and The Gentleman targeted financial institutions with extortion campaigns. These actors exploit the expanding digital banking ecosystem to increase their attack surface.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
The actors have been active throughout 2026, with notable campaigns targeting financial institutions in Indonesia. Their operational tempo is steady, leveraging sophisticated techniques and tools to maintain persistence within targeted networks. Ransomware groups like ICARUS and The Gentleman have emerged as significant threats due to their extortion demands on financial organizations.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in the APT and ransomware activities due to multiple intelligence reports linking these groups to known campaigns. Limited information on exact timelines or specific campaign details may introduce gaps in comprehensive understanding.
No techniques linked yet.
No campaigns linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
1
Tools
0
Campaigns
1
IOCs
0
Observed Data
0
Tactics