Read all Blogs from this Author
A Chinese-speaking threat group is exploiting Indonesia’s state pension fund, TASPEN, to launch a sophisticated mobile malware campaign targeting senior citizens. Disguised as an official app, the spyware steals banking credentials, OTPs, and even biometric data, enabling large-scale fraud. Beyond financial loss, the attack erodes public trust, threatens Indonesia’s digital transformation, and sets a dangerous precedent for pension fund attacks across Southeast Asia.
A new ClickFix social engineering attack weaponizes AI summarizers. Threat actors hide malicious instructions in documents using CSS obfuscation and prompt overdose. This makes the code invisible to humans but fully readable to AI models. When a user summarizes the content, the AI-generated output delivers the malicious payload, tricking the user into executing ransomware. Organizations must implement content sanitization and user awareness to mitigate this risk.
Read all Whitepapers and reports from this Author
Read all knowledge base articles from this Author