24/06/2026
Interview with Patrick Dannacher, President Director & CEO, PT ITSEC Asia Tbk
Cyber-espionage activity in Southeast Asia appears to be expanding, with recent threat intelligence indicating that the India-linked espionage group RagaSerpent (SideWinder) has extended its operations into Indonesia and other parts of the region. The activity suggests a geographic evolution of advanced persistent threat campaigns previously observed in India and Thailand, raising concerns for governments and operators of critical infrastructure across Southeast Asia.
In this interview, Patrick Dannacher discusses findings from ITSEC Asiaโs latest Threat Intelligence Report, which identifies RagaSerpent as a sustained espionage threat operating through a repeatable and scalable intrusion model. He explains that the group continues to rely on tax and audit-themed spearphishing campaigns, staged malware deployment, credential harvesting and long-term persistence techniques, enabling attackers to maintain durable access to government, telecommunications and strategically important organizations.
Dannacher also highlights how the actor combines credential theft with installer-based persistence mechanisms to establish long-lasting access while avoiding detection. By localizing lures and impersonating trusted institutions such as tax authorities, the group has demonstrated a growing level of operational maturity and an ability to rapidly adapt campaigns across different countries. He notes that the consistency of the underlying attack methodology makes the threat particularly challenging, even as domains, infrastructure and payloads are frequently rotated.
The discussion further explores why traditional indicator-based defenses are becoming insufficient against persistent espionage campaigns. Rather than focusing solely on malicious domains, IP addresses or file hashes, organizations are encouraged to adopt behavior-led detection models capable of identifying suspicious activities such as unusual Windows service creation, unexpected installer ex*****on, and direct outbound communications to IP addresses. Greater correlation between email security, endpoint telemetry and network monitoring is also becoming essential for detecting attacks early in their lifecycle.
Looking ahead, Dannacher expects espionage operations to become increasingly scalable, localized and difficult to detect as threat actors refine language impersonation techniques and adopt more modular tooling. He advises organizations to strengthen phishing defenses, monitor user-driven installer ex*****on, improve network egress visibility, and invest in behavior-based threat hunting and incident response capabilities while assuming compromise is inevitable.
Read the full interview - https://cybersecasia.net/features/s-e-asia-governments-targeted-by-cyber-espionage-group/