JAKARTA - The National Cyber and Crypto Agency (BSSN) warned of a campaign from a new hacker group called Mysterious Elephant or the so-called Citomaticjah.

The dangerous group was first discovered by Kaspersky's Global Research and Analysis Team (GReAT) in early 2025, where attackers targeted government entities and foreign affairs organizations across the Asia Pacific region.

On its official Instagram account, BSSN mentioned that the main target of this hacker group is documents, archive photos sent via WhatsApp.

"Imagine if the documents are confidential documents, important company documents," wrote BSSN on the @bssn_ri account quoted Wednesday, November 5.

Through this campaign, hackers use sophisticated tactics, ranging from the use of spear-phishing emails, and sharing malicious documents disguised as important attachments (World, PDF) that you need to open.

More dangerous, they use PowerShell (a legal tool on Windows) to carry out malicious commands secretly by adding additional Mallware.

It doesn't stop there, hackers also put up BabShell, a 'backdoor' that gives them full access to your engine remotely.

To avoid this Mysterious Elephant cyberattack, BSSN recommends the following safety measures:


The English, Chinese, Japanese, Arabic, and French versions are automatically generated by the AI. So there may still be inaccuracies in translating, please always see Indonesian as our main language. (system supported by DigitalSiber.id)

Add VOI as a Preferred Source
Follow VOI news updates across Google.
+