The Indian government is a state authority associated with the repeated use of deliberate internet shutdowns as a tool of domestic information control and public-order management. India is widely documented as the global leader in the number of recorded internet shutdown incidents, with hundreds of cases over multiple years. These disruptions have included restrictions imposed during politically sensitive periods and during student examination periods. The activity is characterized by targeted or broader communications disruption rather than conventional cyber intrusion tradecraft such as malware deployment, credential theft, or network exploitation. In this context, the actor is best understood as a government entity employing telecommunications control measures for censorship, suppression of communications, and management of unrest or sensitive events within its jurisdiction.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.