Hoax and Digital Security: The Fake Wedding Invitation (.apk) Malware Incident

  1. Introduction 

In early 2025, Indonesian social media and messaging platforms were flooded with a hoax message disguised as a wedding invitation link (.apk). The link, once downloaded, installed malware capable of stealing e-wallet and online banking credentials. This case reflects a dangerous intersection of phishing, hoax circulation, and low digital literacy. Understanding how such scams operate technically and psychologically is crucial for developing strong digital safety habits and legal awareness.

  1. How Hoaxes and Phishing Work

Phishing scams use social engineering to trick users into unsafe actions like clicking links or downloading malware. The harmful .apk file acted as spyware, accessing SMS, contacts, and autofill data, capturing OTPs from e-wallets and banking apps for unauthorized transactions (BSSN, 2024). It exploited Android permissions (READ_SMS, READ_CONTACTS, ACCESS_NETWORK_STATE), similar to Anubis and Joker trojans (Trend Micro, 2023).

Psychologically, phishing manipulates emotions through tactics like fake wedding invitations that trigger curiosity and social norms. It exploits social proof (trusting info from friends) and urgency, reducing critical thinking (UNESCO, 2021). This shows that digital safety requires both technical measures and user awareness (Livingstone, 2017).

  1. Digital Safety Steps (Level 1–4)

Following the Digital Competence Framework (DigComp 2.2) and Kominfo’s National Digital Literacy Framework (2023):

Level 1 – Device & Account Protection  

– Use strong passwords and enable Two-Factor Authentication (2FA).  

– Keep OS and antivirus updated.  

– Disable “Install from Unknown Sources.”  

Level 2 – Data & Privacy  

– Avoid sharing personal info or OTPs via messages.  

– Review app permissions and limit background data.  

Level 3 – Information Safety  

– Verify links and domains.  

– Use fact-checking sites like TurnBackHoax.id and CekFakta.com.  

– Warn others against sharing unverified info.  

Level 4 – Transaction & Network Safety  

– Avoid banking on public Wi-Fi; use VPN or cellular data.  

– Report phishing to AduanKonten.id or Bareskrim Polri.  

Following these steps helps users become responsible digital citizens.

  1. Social, Economy, and Legal Impacts 

• Social Impacts  

The hoax caused panic and mistrust in digital communities, undermining trust in digital services and showing low digital empathy among victims (Kominfo, 2024).  

• Economic Impacts  

Malware led to financial losses by stealing from e-wallets and bank accounts. Phishing incidents rose 30%, causing millions in losses and weakening trust in digital finance (BSSN, 2024).  

•Legal Impacts  

Under Law No. 11 of 2008 (ITE Law), phishing and hoaxes are crimes:  

– Article 28(1) bans false info causing harm.  

– Articles 30–32 punish unauthorized data access and theft.  

Penalties include up to 12 years in prison or fines up to Rp 12 billion.

  1. Suggestions 

• Public Awareness Initiatives 

Kominfo, fintech companies, and banks should enhance “Think Before You Click” campaigns aimed at family WhatsApp groups, as these are where phishing tends to spread most rapidly.

•Responsibility of Platforms  

WhatsApp ought to automatically restrict .apk file transfers in Indonesian groups and implement more robust URL filtering measures.

•Integration of Education  

Incorporate phishing simulation and privacy education into the digital curriculum of schools.

•Community-Based Reporting System  

Promote simple reporting via AduanKonten.id and incentivize early reporters to encourage community vigilance.

•Tools for AI Detection  

Assist BSSN in creating AI models for the detection of phishing in real-time and the classification of links.

  1. Summary

The 2025 “wedding invitation” malware highlights that digital security encompasses both technical and ethical dimensions. Reliable passwords and antivirus software are ineffective without critical thinking, empathy, and awareness. Enhancing national cyber resilience necessitates collaboration among users, organizations, and law enforcement, grounded in the four pillars of digital literacy: skills, safety, ethics, and culture (Kominfo, 2023).

Case 5: Ethics of AI Use in Academia: Undisclosed Use of ChatGPT and MidJourney

  1. Introduction 

In 2025, a university instructor discovered a student used ChatGPT and MidJourney for their thesis without disclosure. Although technically sound, it violated academic ethics, transparency, and originality. This highlights the growing challenge in higher education to balance AI-driven innovation with ethical responsibility and legal standards.

  1. Academic Ethics, Copyright, and Transparency

Academic ethics demand honesty, fairness, and originality. According to APA (2023) and UNESCO, using AI-generated ideas without proper attribution is plagiarism and academic misconduct. Failing to acknowledge AI misleads evaluators and breaches authorship authenticity, harming trust between students and teachers.

Copyright laws, like Indonesia’s Law No. 28 of 2014, protect only human-created works. AI outputs usually lack copyright protection but may infringe rights if they replicate copyrighted material (OECD, 2023). Thus, the student’s use of AI may violate both academic and intellectual property ethics.

Transparency is essential; users must disclose AI involvement, detailing how it assisted (Council of Europe, 2024; UNESCO, 2021). Without disclosure, the evaluation of genuine learning and understanding is compromised.

  1. UNESCO Ai Ethics Principles 

The UNESCO Recommendation on the Ethics of Artificial Intelligence (2021) points out two key principles important here: transparency and accountability.

Transparency means that both organizations and individuals must make AI use clear and understandable. In academic settings, students should record when, how, and why they use AI tools. Meanwhile, supervisors need to set clear rules to distinguish proper AI assistance from cheating.

Accountability means that people remain fully responsible for the results AI helps create. Even if AI contributes, students must ensure accuracy, give proper credit, and use AI ethically. This reflects the idea that AI can support learning but cannot replace independent thinking and judgment.

Without transparency and accountability, AI can be misused to deceive, which harms trust and credibility in educational institutions.

  1. Designing Ethical AI Usage Guidelines in Academia

According to digital ethics frameworks (Kominfo, 2023; UNESCO, 2021), higher education institutions should implement the following ethical guidelines for AI usage:  

•Transparency Requirement  

All AI-assisted efforts must include a disclaimer such as:  

“Some aspects of this document were developed with the aid of AI tools (ChatGPT, MidJourney) for generating ideas and visual content. The final interpretation and written content are solely my responsibility.”  

•Human Oversight  

Supervisors are required to assess whether AI-generated outputs show critical thinking rather than simple duplication. AI tools should enhance, rather than substitute, human cognitive processes.  

•Purpose Restriction  

AI can be utilized for:  

Enhancing language, formatting, or brainstorming ideas.  

AI should not be used to produce complete essays, research findings, or images without significant contextual alterations.  

•Verification and Attribution  

When AI supplies factual information, students are responsible for manually verifying the sources. Citations for AI-generated content must indicate the model and its version (e.g., “Generated using ChatGPT, OpenAI, 2025”).  

•Data Privacy Adherence  

Students should refrain from uploading sensitive academic or personal information to AI platforms to comply with the Personal Data Protection Law (UU PDP No. 27/2022).  

•Education and Policy Awareness  

Universities should conduct workshops on AI literacy that cover the ethical, legal, and creative aspects of AI use, fostering responsible innovation.  

•Consequences Framework  

Failure to disclose or misleading use of AI should be classified as plagiarism and will be subject to academic disciplinary measures.

  1. Conclusion 

This situation reveals an important ethical challenge in education: Can AI enhance learning without compromising integrity? Using AI tools like ChatGPT or MidJourney is not wrong by itself; unethical behavior arises from a lack of transparency, responsibility, and understanding. By applying UNESCO’s AI Ethics principles, institutions can turn AI from a risk into a helpful learning tool, fostering students who are skilled digitally and ethically aware.

As AI becomes part of higher education, the key remains that technology generates content, but only humans give it true meaning.

Case 6 – Provocative Social Media Content: Misleading Student Protest Video on X (Twitter)

  1. Introduction 

In March 2025, a verified X (Twitter) account, @BANGSAygSUJUD, shared a cropped video of a student protest, alleging that the demonstrators were assaulting the police with Molotov cocktails. The tweet read: “Under the guise of democracy, students are attacking officers with hard objects and even throwing MOLOTOV BOMBS.” This post went viral, amassing over 51,000 views and sparking intense discussions and animosity toward student organizations. Subsequent investigations by independent journalists found that the violence depicted in the video was actually instigated by a small group of outsiders, rather than the student organization itself. This incident underscores how manipulated digital media and inflammatory language can exacerbate polarization and lead to real-world conflict, illustrating breaches of netiquette, digital citizenship, and legal standards within Indonesia’s online landscape.

  1. Breach of Netiquette and Digital Citizenship  

Netiquette refers to the ethical and responsible way of communicating online, which values truth and empathy (Kominfo, 2023). In this instance, the account violated several essential principles:  

•Context Manipulation: The video was edited in a way that obscured the fact that students were behaving peacefully before security intervened, thus spreading misinformation through omission.  

•Incendiary Language: Utilizing phrases like “bahaya TERHASUT BUZZER PROVOKATOR” and accusing “students” fostered division and animosity rather than promoting constructive dialogue.  

•Absence of Verification and Empathy: The post neglected the importance of fact-checking and demonstrated a lack of digital empathy, resulting in erroneous conclusions and social repercussions (Livingstone, 2017).

  1. Legal Perspective and Social Impact

According to Indonesia’s Law No. 11 of 2008 regarding Electronic Information and Transactions (UU ITE), which was revised by Law No. 19 of 2016, such messages are categorized as digital misconduct:

Article 28(1) forbids the distribution of false or misleading information that leads to public unrest or harm.

Article 27(3) makes online defamation and hate speech against individuals or groups a criminal offense.

Article 45A(1) imposes penalties of up to six years in prison or fines reaching Rp 1 billion for offenders.

If the tweet is shown to be false, it can be classified as digital provocation, which has the potential to incite real-world violence — violating both legal and ethical obligations.

On a social level, the rapid spread led to several outcomes:

It deepened public divisions, portraying students as violent extremists.

It fostered skepticism toward both activists and law enforcement agencies.

It promoted digital vigilantism, as individuals began to engage in “doxxing” of protesters.

These outcomes reflect the concerns raised by UNESCO (2019) about “information disorder,” wherein online manipulation undermines democratic discussions and harms civic relationships.

  1. Campaign for Preventive Digital Literacy  

Kominfo and civil organizations can initiate #ShareWithContext, a digital literacy initiative centered around three key areas:  

•Awareness and Critical Thinking  

Educate on how cropping images and using emotional language can be misleading, while also advocating for the use of fact-checking tools like InVID and CekFakta.com.  

•Empathy and Responsibility  

Motivate users to fairly rephrase misleading posts and collaborate with influencers to exemplify ethical sharing practices.  

•Community Monitoring  

Encourage the reporting of provocative content through AduanKonten.id and collaborate with X/Twitter to implement fact-check labels.  

These actions foster responsible digital citizenship and assist in averting conflicts driven by misinformation.

  1. Conclusion 

The misleading protest video shared by @BANGSAygSUJUD demonstrates how a singular act of online irresponsibility can magnify false information and threaten social harmony. By breaching netiquette, ethical communication standards, and the legal frameworks set out by the ITE Law, this incident highlights the pressing necessity for critical digital literacy anchored in empathy and fact-checking. Through ongoing education, clear regulations, and cooperative initiatives, Indonesia can cultivate a generation of digital citizens who pause to consider before sharing — guaranteeing that online freedom is exercised thoughtfully and with integrity.

Leave a Reply

Discover more from inaymaula

Subscribe now to keep reading and get access to the full archive.

Continue reading