AnonSec is a hacktivist group associated with the broader Anonymous ecosystem. It has been publicly linked to anti-India and pro-Pakistan hacktivist activity, including participation in campaigns targeting Indian organizations during periods of India-Pakistan tension. Reported activity includes claimed attacks against Indian government, defense, and critical-infrastructure-related entities, and the group has been named alongside other hacktivist collectives involved in distributed denial-of-service operations and propaganda-driven intrusion claims. AnonSec has also been cited as part of alliance networks with other hacktivist actors such as Keymous+, Mr Hamza, and Moroccan Dragons. The group is also known for claiming responsibility for a high-profile breach of NASA, alleging theft of large volumes of data and partial control of a Global Hawk unmanned aircraft. Those claims were publicly disputed by NASA, which stated it had no evidence that aircraft control was compromised and assessed the purportedly stolen material as publicly available information. As a result, the NASA incident demonstrates AnonSec’s use of publicity-seeking breach claims, but the underlying compromise details remain unverified. Across the available reporting, AnonSec is best characterized as a hacktivist actor focused on disruptive and attention-generating operations rather than a consistently demonstrated advanced intrusion set. Its observed or claimed behavior includes distributed denial-of-service activity, website intrusion claims, and public amplification of alleged breaches in support of political narratives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named allied hacktivist group participating in strategic alliances and joint operations with Keymous+.
Pro-Pakistan hacktivist collective involved in cyber operations against Indian targets during the 2025 India-Pakistan crisis, primarily through publicized disruptive attacks.
Named as a pro-Pakistan hacktivist group involved in cyber activity targeting India during Operation Sindoor.
Hacktivist-led DDoS activity targeting India amid India-Pakistan conflict-related tensions.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.