Threat Actor Characterization
You’re viewing the read-only version.
Sign in for analyst tools (editors, promote draft, file/relations management, etc.)
PhantomSec1337
ID: 3f97ccf68d4ce27448864b79ab1fd512
Hacktivist Group
Defacement Crew
Hacktivism
Threat types: Defacement
Progress: 65%
Completeness: 71%
Freshness: 50%
Operation zone: Albania, Armenia, Brazil, Chile, Cocos(Keeling)Islands, India, Indonesia, Lesotho, Pakistan, Russia, South Africa, Sri Lanka, Trinidad and Tobago, United Kingdom
Aliases
Limited alias preview
| Phantom Security 1337 | PhantomSecurity1337 | P* | P***** |
Showing 2 of 4 aliases in free preview.
Actor Network Graph
Open Network GraphMITRE ATT&CK®
confidence: medium
PhantomSec1337 — Indonesian defacement crew (Top-10 by volume on Zone-Xsec) active through 2020–2025; frequent page takeovers of .id government/edu sites; often credited by notifiers as team for Indonesian defacers (e.g., Babacang07).
| Technique | Technique name | Tactics | Evidence |
|---|---|---|---|
| T1491.002 | External Defacement | TA0040 | |
| T1190 | Exploit Public-Facing Application | TA0001 |
|
PhantomSec1337 (Indonesia)
CLASSIFICATION: Unclassified / Open Source
Executive Summary
PhantomSec1337 is a prolific Indonesian defacement crew, consistently visible in Zone-Xsec rankings (Top-10 by total defacements) and frequently credited on social OSINT posts for recent .go.id / .sch.id takeovers. Open sources emphasize volume and cadence over deep post-exploitation. Confidence: medium (mirrors and team page corroborate activity; vectors rarely detailed).
- 2020–2025. High-tempo defacements across gov/edu/SME in Indonesia, tracked by Zone-Xsec team page.
- 2025-04-29. Gov ID site defaced; team credited as PhantomSec1337 (OSINT capture on X).
- Team banner used by multiple Indonesian notifiers (e.g., MR-4PEAJE; previously Babacang07 cases). INFERENCE (medium).
- Tradecraft: external defacement of public WordPress/CMS; little evidence of persistence or data-theft. INFERENCE (medium).
Executive brief
now
Saved successfully.
Hunting Playbook
now
Saved successfully.
IOC Appendix
now
Saved successfully.
OSINT Library
now
Saved successfully.
Showing 1–8 of 8 images
Free Preview
Logo variant
Free Preview
Image used in hacked website
Free Preview
Avatar used in social media resources
Free Preview
Logo variant
Free Preview
Logo variant
Free Preview
Logo variant
Free Preview
Logo variant
Free Preview
Banner used in social media resources
Showing 4 of 8 images in preview mode. Additional evidence is restricted for Analyst and Premium plans.