TripleX
❔ UnknownMotivation: financialLast active: 2026-08-08First seen: 2026-07-09
1
linked CVEs
Also known as
Triple X
Targeted industries
FinanceGovernmentTechnologyTelecommunicationsInsuranceTransportationAerospace
Targeted regions
British Indian Ocean TerritoryIndiaIndonesiaJapanRussian FederationSouth AfricaThailand
Indonesia's Banking, Financial Services, and Insurance sector faced significant cyber threats throughout 2026, including multiple alleged data breaches targeting major banking institutions and fintech platforms. Underground forums advertised compromised datasets containing customer information, account details, and sensitive documents, with varying levels of validation. Ransomware groups ICARUS and The Gentleman conducted extortion campaigns against financial organizations. China-linked APT groups including SilverFox, Mustang Panda, Amaranth-Dragon, Lotus Blossom, and Shadow Campaigns demonstrated sophisticated capabilities through phishing operations, supply chain compromises, and zero-day exploitation. These state-aligned actors deployed advanced malware such as ValleyRAT, ABCDoor, LOTUSLITE, and custom backdoors for long-term espionage. The expanding digital banking ecosystem and regional financial connectivity have increased attack surfaces, requiring enhanced cyber resilience, continuous monitoring, a...
Source: otx · Collected: 2026-08-10
⚡ Vulnerabilities & Exploits1 CVE
threat_actor_cve → cves / exploits.cve_ids
| CVE-2025-8088 suspected | A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET. | CVSS 8.8 KEVransomware |
🔍 Detection Coverage0 Sigma
Derived from linked CVEs — not a direct actor match
No Sigma rules mapped via this actor's CVEs yet.
🧬 YaraComing soon
🛰️ Infrastructure & IOCs31
| sha256 | 4741c2884d1ca3a40dadd3f3f61cb95a59b11f99a0f980dbadc663b85eb77a2a | — | 2026-08-08 |
| domain | emezonhe.me | — | 2026-08-08 |
| domain | skycloudcenter.com | — | 2026-08-08 |
| domain | dog3rj.tech | — | 2026-08-08 |
| domain | q74vn.live | — | 2026-08-08 |
| domain | abwxjp5.me | — | 2026-08-08 |
| domain | servgate.me | — | 2026-08-08 |
| domain | pr0fu5a.me | — | 2026-08-08 |
| domain | zamstats.me | — | 2026-08-08 |
| domain | pickupweb.me | — | 2026-08-08 |
| domain | zrheblirsy.me | — | 2026-08-08 |
| domain | msonline.help | — | 2026-08-08 |
| domain | gouvn.me | — | 2026-08-08 |
| domain | abc.doublemobile.com | — | 2026-08-08 |
| domain | editor.gleeze.com | — | 2026-08-08 |
| domain | www.cosmosmusic.com | — | 2026-08-08 |
| domain | mcagov.cc | — | 2026-08-08 |
| domain | roldco.com | — | 2026-08-08 |
| domain | abc.3mkorealtd.com | — | 2026-08-08 |
| domain | abc.fetish-friends.com | — | 2026-08-08 |
| domain | abc.haijing88.com | — | 2026-08-08 |
| domain | abc.ilptour.com | — | 2026-08-08 |
| domain | abc.petitechanson.com | — | 2026-08-08 |
| domain | abc.sudsmama.com | — | 2026-08-08 |
| domain | abc.woopami.com | — | 2026-08-08 |
| domain | vnc.kcii2.com | — | 2026-08-08 |
| sha1 | 09b0bc41f8838949d5a1c442ee2e2ec9ff892fdc | — | 2026-08-08 |
| sha1 | a12db7b72879ac0f46079efd8c67e8ca0621f73b | — | 2026-08-08 |
| sha1 | cc6fd90785a528883b0203138348df8bad69bb1a | — | 2026-08-08 |
| sha1 | f0b182423107a04cf5f09b8559e656242a4fcc89 | — | 2026-08-08 |
| domain | gpsfinance.co.id | — | 2026-08-08 |
📰 Threat Intel Coverage0
Digest reports mentioning this actor (incl. aliases)
No threat intel digest coverage found.