Nation of Saviors is a hacktivist threat group active in Middle East and South Asia conflict-driven cyber campaigns. The group is primarily associated with disruptive operations and information effects, especially distributed denial-of-service activity, public breach claims, data leak announcements, and doxxing. It has appeared alongside broader pro-Iran and pro-Pakistan hacktivist ecosystems that coordinate and amplify operations through Telegram-based channels. The group has been publicly linked to campaigns targeting Israeli government entities, Indian government portals, and at least one Saudi private-sector organization. Reported activity includes claimed disruption of Israeli government websites, including the education sector; claimed attacks against numerous Indian government portals during the 2025 India-Pakistan crisis; and a claimed breach and data exfiltration incident involving a Saudi engineering company. Nation of Saviors has also been described as a data leak and doxxing specialist and has been associated with claims involving exposure of U.S. military personnel information. Operationally, Nation of Saviors fits the pattern of low-to-moderate sophistication hacktivism in which DDoS attacks, website compromise claims, alleged data theft, and propaganda amplification are central. Across reporting on the wider coalitions in which it participates, many public breach claims by aligned groups were difficult to verify independently, indicating that psychological impact and narrative shaping are important components of its activity. High-confidence reporting supports the group’s role in disruptive operations and leak-oriented intimidation rather than advanced intrusion tradecraft. Known aliases are limited, and the group is most commonly referenced as Nation of Saviors or NOS.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Part of the coalition contributing DDoS activity and propaganda amplification.
Hacktivist group specializing in data leaks, doxxing, and DDoS attacks against Saudi, US military-related, and Israeli targets.
Actor involved in breach, doxxing and DDoS claims against Saudi, Israeli and US-linked targets, including alleged exfiltration and public release threats.
Hacktivist group named as participating in disruptive operations related to the conflict.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.