Indonesian Hacktivist Group INDOHAXSEC Intensifies Cyberattacks Across Southeast Asia
Indonesian hacktivist group INDOHAXSEC has escalated cyberattacks targeting Southeast Asian nations, employing DDoS attacks, ransomware, and data leaks to advance pro-Palestinian causes.
Encrygma is selling the entire Full Cyber Weapon Research of Indonesian Hacktivist Group INDOHAXSEC Intensifies Cyberattacks Across Southeast Asia for ₿ 0.10 BTC. Contact us.
Executive Takeaway — TL;DR
- Category:
- Cyber Espionage
- Severity:
- Medium
- Actor Type:
- Hacktivist
- Geography:
- Southeast Asia
- Confidence:
- Confirmed
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 5 min
Overview
In recent months, the Indonesian hacktivist group INDOHAXSEC has significantly intensified its cyber operations across Southeast Asia. Primarily driven by pro-Palestinian sentiments, the group has expanded its activities to include financially motivated attacks, thereby broadening its impact and reach.
Operational Tactics and Tools
INDOHAXSEC employs a diverse array of cyberattack methods, including Distributed Denial of Service (DDoS) attacks, ransomware deployment, website defacement, and data leaks. The group has developed and utilized several malicious tools to execute these operations:
-
DDoS Kits: Tools such as NUKLIR and RUDAL are employed to overwhelm and disable targeted websites and online services.
-
Backdoors: Malware like white.php is used to maintain unauthorized access to compromised systems, facilitating prolonged surveillance and data exfiltration.
-
Ransomware: ExorLock ransomware is deployed to encrypt data on infected systems, demanding payment for decryption keys.
-
Website-Destroying Malware: Dancokware is utilized to deface and disrupt the functionality of targeted websites, often leaving politically charged messages.
These tools are typically disseminated through phishing campaigns, exploiting social engineering tactics to deceive individuals into executing malicious payloads.
Targeted Entities and Impact
INDOHAXSEC's targets are diverse, encompassing government agencies, educational institutions, and private sector organizations across Southeast Asia. Notable incidents include:
-
Bangladesh: On August 15, 2025, the group defaced over 100 Bangladeshi government and educational websites, displaying messages advocating for Palestinian causes.
-
Pakistan: The group has previously targeted Pakistani government websites, including the Provincial Assembly of the Punjab, compromising sensitive data and disrupting online services.
The impact of these attacks is multifaceted, leading to operational disruptions, reputational damage, and potential data breaches. The politically charged nature of the attacks also exacerbates regional tensions, potentially influencing diplomatic relations.
Operational Infrastructure and Communication
INDOHAXSEC operates with a decentralized and anonymous infrastructure, utilizing platforms like Telegram for coordination and GitHub for sharing malicious tools and resources. This approach enhances the group's operational security and facilitates rapid dissemination of attack tools and updates. Additionally, the group's presence on platforms like TikTok indicates an awareness of leveraging social media for recruitment, propaganda, and potentially for coordinating attacks.
Strategic Alliances and Expansion
In a notable development, INDOHAXSEC announced an alliance with the pro-Russian hacktivist group NoName057(16). This collaboration suggests a strategic expansion of the group's operational capabilities and a potential increase in the scale and sophistication of future cyberattacks.
Conclusion
The escalation of cyberattacks by INDOHAXSEC across Southeast Asia underscores the evolving threat landscape posed by hacktivist groups. Their ability to execute sophisticated, politically motivated cyber operations, coupled with the adoption of advanced tools and strategic alliances, presents significant challenges to regional cybersecurity. Organizations within the affected regions are advised to enhance their cybersecurity posture by implementing robust defense mechanisms, conducting regular security audits, and fostering information-sharing collaborations to effectively mitigate the risks associated with such cyber threats.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.



