{"id":6484,"date":"2025-08-28T10:04:12","date_gmt":"2025-08-28T10:04:12","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/08\/28\/new-malware-attack-exploiting-taspens-legacy-to-target-indonesian-senior-citizens\/"},"modified":"2025-08-28T10:04:12","modified_gmt":"2025-08-28T10:04:12","slug":"new-malware-attack-exploiting-taspens-legacy-to-target-indonesian-senior-citizens","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/08\/28\/new-malware-attack-exploiting-taspens-legacy-to-target-indonesian-senior-citizens\/","title":{"rendered":"New Malware Attack Exploiting TASPEN\u2019s Legacy to Target Indonesian Senior Citizens"},"content":{"rendered":"<p>    New Malware Attack Exploiting TASPEN\u2019s Legacy to Target Indonesian Senior Citizens<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated malware campaign has emerged, targeting Indonesia\u2019s most vulnerable digital citizens through a calculated exploitation of trust in the nation\u2019s pension fund system.<\/p>\n<p>The malicious operation impersonates PT Dana Tabungan dan Asuransi Pegawai Negeri (TASPEN), the state-owned pension fund managing over $15.9 billion in assets for millions of Indonesian civil servants and retirees.<\/p>\n<p>This campaign represents a disturbing evolution in cybercrime tactics, weaponizing institutional trust to conduct large-scale financial fraud against senior citizens who are increasingly encouraged to adopt digital services for pension management.<\/p>\n<p>The attack leverages a meticulously crafted <a href=\"https:\/\/cybersecuritynews.com\/anti-phishing-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">phishing website<\/a> hosted at taspen[.]ahngo[.]cc, which mimics an official mobile application download page complete with TASPEN\u2019s branding and the Indonesian slogan \u201cAplikasi Andal, semudah bersama TASPEN\u201d (A reliable app, easy with TASPEN).<\/p>\n<p>The fraudulent site features weaponized Google Play and Apple App Store buttons, with the Android version initiating direct downloads of malicious APK files while the iOS button displays a deceptive maintenance message in Bahasa Indonesia to maintain credibility.<\/p>\n<p>CloudSEK analysts <a href=\"https:\/\/www.cloudsek.com\/blog\/taspen-malware-campaign-targeting-indonesian-senior-citizens\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> this campaign through their threat intelligence monitoring, revealing that the malware employs advanced evasion techniques to bypass traditional security measures.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhwOh3QFzLjx_sy1dOTKQnZXAPCjB5pQ1fNBQD5ZF9eE0DuQaaSu6pBJCsq5MXmsOK6aykwNYEX1vx46Z_R9v-gPXIlpI1cD9vtQcI3MMawWQ9RJmC2QqMUuJCyKjfEcf1XPiA0iwghCkVMlJFhdEpDirJOFBaO-K6Z44_MdeVT4nHdNh37x0miVshHB70\/s16000\/Attack%2520Lifecycle%2520%28Source%2520-%2520Cloudsek%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Attack Lifecycle (Source \u2013 Cloudsek)<\/figcaption><\/figure>\n<\/div>\n<p>The malicious application is protected by DPT-Shell, an open-source Android packer that encrypts the executable code and deploys it only during runtime, effectively defeating static analysis tools used by security researchers.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-runtime-payload-deployment-and-surveillance-capabilities\"><strong>Runtime Payload Deployment and Surveillance Capabilities<\/strong><\/h2>\n<p>The malware\u2019s most concerning aspect lies in its sophisticated deployment mechanism and comprehensive surveillance capabilities once installed on victim devices.<\/p>\n<p>Upon execution, the DPT-Shell protection system first decrypts the hidden malicious payload in memory before writing it to the application\u2019s private code_cache directory as a ZIP archive named i111111.zip.<\/p>\n<p>This runtime unpacking ensures that the true malicious functionality remains completely hidden from <a href=\"https:\/\/cybersecuritynews.com\/web-security-scanners\/\" target=\"_blank\" rel=\"noreferrer noopener\">security scanners<\/a> until the application is actively running on a live device.<\/p>\n<p>Once operational, the malware deploys multiple background services designed for comprehensive data theft.<\/p>\n<p>The SmsService component provides persistent SMS interception capabilities, automatically reading and forwarding all incoming messages including critical two-factor authentication codes.<\/p>\n<p>Simultaneously, the ScreenRecordService enables real-time visual monitoring of all user activities, while the CameraService facilitates facial video capture for biometric data harvesting.<\/p>\n<p>These components work in concert with a ContactData class that systematically exfiltrates the victim\u2019s complete address book, including names, phone numbers, email addresses, and call history.<\/p>\n<p>The malware establishes encrypted communication with its command and control server at rpc.syids.top through both HTTP POST requests for credential theft and persistent WebSocket connections for real-time command execution.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhrUgLFdN2rkqw3Xwv1cgFF68BiYXi60WFgCLOZyeiX8a_sCMLb4e1L8WbcHP0s-C4NYDg2sviPl05zl7EGBoLImT_tv6wZR6TDjqWYwAaiOinCiZ86peEV_HlJR-sgik6cRmLZvYcZqXqMqJ6aGv0yzFa1hrgudMdYRkL1NomsFLeM5wBoJ8KCvEFJxFY\/s16000\/Encrypted%2520Credential%2520Exfiltration%2520%28Source%2520-%2520Cloudsek%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Encrypted Credential Exfiltration (Source \u2013 Cloudsek)<\/figcaption><\/figure>\n<\/div>\n<p>When victims enter their banking credentials, the <a href=\"https:\/\/cybersecuritynews.com\/chatgpt-powered-malware-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener\">malware<\/a> encrypts and transmits this data while deliberately displaying Indonesian error messages to mask the successful exfiltration, creating the illusion of a simple failed login attempt.<\/p>\n<p>Attribution analysis reveals strong linguistic indicators pointing to Chinese-speaking threat actors, with error messages in Simplified Chinese found embedded within both the phishing infrastructure and C2 server responses.<\/p>\n<p>The campaign\u2019s success threatens to establish a dangerous precedent for similar attacks against other critical Indonesian public institutions, potentially affecting millions of citizens who rely on digital government services for essential financial and healthcare needs.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)\"><strong><code>Boost\u00a0your\u00a0SOC and help your team protect your business with free top-notch threat intelligence:\u00a0<a href=\"https:\/\/intelligence.any.run\/plans\/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=alert_fatigue&amp;utm_content=lookup_plan&amp;utm_term=120825\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Request TI Lookup Premium Trial<\/a>.<\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/new-malware-attack-exploiting-taspens-legacy\/\">New Malware Attack Exploiting TASPEN\u2019s Legacy to Target Indonesian Senior Citizens<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/new-malware-attack-exploiting-taspens-legacy\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New Malware Attack Exploiting TASPEN\u2019s Legacy to Target Indonesian Senior Citizens A sophisticated malware campaign has emerged, targeting Indonesia\u2019s most vulnerable digital citizens through a calculated exploitation of trust in the nation\u2019s pension fund system. The malicious operation impersonates PT Dana Tabungan dan Asuransi Pegawai Negeri (TASPEN), the state-owned pension fund managing over $15.9 billion [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-6484","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6484"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=6484"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6484\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=6484"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=6484"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=6484"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}