Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors silverfox, mustang panda, amaranth-dragon, lotus blossom, shadow campaigns, triplex, icarus, the gen

silverfox, mustang panda, amaranth-dragon, lotus blossom, shadow campaigns, triplex, icarus, the gen

TLP:CLEAR
Active

Also known as: tracked as

Description

Indonesia's Banking, Financial Services, and Insurance sector faced significant cyber threats throughout 2026, including multiple alleged data breaches targeting major banking institutions and fintech platforms. Underground forums advertised compromised datasets containing customer information, account details, and sensitive documents, with varying levels of validation. Ransomware groups ICARUS and The Gentleman conducted extortion campaigns against financial organizations. China-linked APT groups including SilverFox, Mustang Panda, Amaranth-Dragon, Lotus Blossom, and Shadow Campaigns demonstrated sophisticated capabilities through phishing operations, supply chain compromises, and zero-day exploitation. These state-aligned actors deployed advanced malware such as ValleyRAT, ABCDoor, LOTUSLITE, and custom backdoors for long-term espionage. The expanding digital banking ecosystem and regional financial connectivity have increased attack surfaces, requiring enhanced cyber resilience, continuous monitoring, a...

Goals & Targeting

Targeted Sectors

Financial services
Government
Communications
Transportation
Aerospace

Targeted Countries / Regions

British Indian Ocean Territory
India
Indonesia
Japan
Russian Federation
South Africa
Thailand

AI Analysis

· 1 week ago

Executive Summary

The threat actors SilverFox, Mustang Panda, Amaranth-Dragon, Lotus Blossom, Shadow Campaigns, Triplex, Icarus, and The Gentleman represent a mix of state-sponsored Advanced Persistent Threat (APT) groups and ransomware operators. They target financial services, government, communications, transportation, and aerospace sectors across multiple countries, including Indonesia, India, Japan, Russia, South Africa, and Thailand. Their activities include sophisticated cyberattacks such as phishing campaigns, supply chain compromises, and zero-day exploitation, coupled with ransomware deployment, posing significant risks to critical infrastructure and data integrity.

Goals & Targeting

These actors target sectors critical to national security and economic stability, including financial services, government, communications, transportation, and aerospace. Their strategic focus on countries like Indonesia, India, Japan, Russia, South Africa, and Thailand suggests a geopolitical agenda aligning with potential state interests. The targeted industries are chosen for their access to sensitive information and high-value assets, making them prime targets for both espionage and financial gain.

Enhanced Description

The actors SilverFox, Mustang Panda, Amaranth-Dragon, Lotus Blossom, and Shadow Campaigns are associated with China-linked APT groups known for their advanced capabilities in cyber espionage. In 2026, these groups were linked to several significant cyber threats against Indonesia's banking, financial services, and insurance sectors. Their operations include deploying malware such as ValleyRAT and LOTUSLITE for long-term espionage and conducting supply chain compromises. The ransomware groups ICARUS and The Gentleman targeted financial institutions with extortion campaigns. These actors exploit the expanding digital banking ecosystem to increase their attack surface.

Key Capabilities

  • Phishing operations
  • Supply chain compromises
  • Zero-day exploits
  • Advanced malware deployment
  • Ransomware activities

MITRE ATT&CK Tactics

Reconnaissance
Credential Access
Execution
Persistence
Defense Evasion

ATT&CK Techniques

T1059.003
T1055
T1566.001
T1003

Software / Tooling

ValleyRAT
ABCDoor
LOTUSLITE
Cobalt Strike
Mimikatz

Campaigns & Victims

The actors have been active throughout 2026, with notable campaigns targeting financial institutions in Indonesia. Their operational tempo is steady, leveraging sophisticated techniques and tools to maintain persistence within targeted networks. Ransomware groups like ICARUS and The Gentleman have emerged as significant threats due to their extortion demands on financial organizations.

IOC Patterns

  • Spear-phishing emails with malicious attachments
  • C2 communication via DNS queries
  • Compromised supply chain software updates
  • Malware signatures matching known APT tools

Recommended Actions

  • Implement robust user training and phishing simulations
  • Enhance network monitoring for anomaly detection
  • Secure supply chains with regular updates and validations
  • Deploy endpoint protection solutions against known malware strains
  • Establish incident response teams for rapid threat containment

Suggested Tags

APT
ransomware
espionage
finance-sector

Confidence Assessment

High confidence in the APT and ransomware activities due to multiple intelligence reports linking these groups to known campaigns. Limited information on exact timelines or specific campaign details may introduce gaps in comprehensive understanding.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

1

Tools

0

Campaigns

1

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
APT
Financial Targeting
Supply Chain Attack
Phishing
Zero-Day Exploitation
Backdoor / C2
Data Exfiltration
ransomware
espionage
finance-sector

Details

Type
Unknown
Confidence
55%
Added
Jul 12, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.