Indra is an alias associated with two distinct but similarly named threat-actor contexts that should not be conflated without additional corroboration. One usage refers to the administrator alias of the relaunched BreachForums active in late 2025 and early 2026, linked to retaliatory rhetoric against France, claims of access to French government systems, and public claims of responsibility for data breaches such as the ManoMano incident. In that context, Indra is tied to underground forum administration, data-leak claims, alleged access to sensitive repositories, and extortionate or coercive messaging directed at victims or governments. Reported activity includes claims of unauthorized access to customer-support data through a third-party service provider and publication of breach claims on BreachForums. The same alias was also reported as framing attacks as retaliation for arrests connected to BreachForums figures including ShinyHunters. A separate usage in reporting from 2021 describes a hacktivist group calling itself Indra, portrayed as an anti-government or anti-Iranian-regime partisan resistance group. That cluster was linked by researchers to disruptive operations affecting Iranian transportation and fuel-related systems and was also reported to have previously targeted firms in Syria. In that context, the actor’s operations were associated with politically charged messaging and disruptive effects rather than conventional financially motivated ransomware activity. Across the supplied reporting, the strongest common denominator for the BreachForums-linked Indra alias is data-theft and leak-oriented activity, use of underground forums for publicity and pressure, and targeting connected to France. However, because the available material mixes at least two actor contexts under the same name, attribution should be treated cautiously unless further evidence separates the BreachForums administrator from the earlier anti-Iranian-regime hacktivist entity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Described as the BreachForums administrator who published a statement calling for reprisals against France, helping trigger the spike in data-leak claims against French entities.
BreachForums administrator who promoted retaliatory narratives against France after arrests and forum seizure, potentially acting as an initial trigger for increased France-focused leak claims.
Claimed responsibility for the ManoMano breach, alleging theft of ~43 GB of data from a customer support environment (reportedly a Zendesk instance), including tens of millions of user-account records and support artifacts (tickets/attachments).
Financially motivated cybercriminal activity associated with a third-party/supply-chain compromise of a subcontractor’s Zendesk account to exfiltrate large volumes of ManoMano customer data, followed by advertising/selling/leaking the dataset on BreachForums.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.