Indian Cyber Force (ICF) is an India-based hacktivist group founded in 2022 that conducts politically motivated cyber operations aligned with pro-India causes. The group has been associated with disruptive and intrusive activity including distributed denial-of-service attacks, website defacement, unauthorized access to internet-connected devices and web services, and public leaking of stolen data. Its operations have repeatedly targeted states and organizations perceived as adversarial to Indian interests, with Pakistan appearing as its most frequent target. Reported targeting has also included Bangladesh, Canada, Palestine, Qatar, the Maldives, China, and Indonesia. ICF has been linked to coordinated campaigns tied to geopolitical flashpoints and diplomatic disputes. Reported operations include attacks against Canadian government and military-related websites during the “#OpCanada” campaign; disruptive and intrusive activity against Palestinian entities after the October 2023 Hamas attacks on Israel; attacks against Qatari targets during the dispute over imprisoned former Indian naval officers; and operations against Maldivian government entities during the India–Maldives diplomatic row. The group has also been associated with compromises affecting Bangladeshi police systems and repeated campaigns against Pakistani institutions, including universities, police-related systems, financial entities, tax-related systems, and large numbers of internet-connected cameras. The group’s tradecraft is characteristic of hacktivist operations focused on disruption, publicity, and reputational impact. Commonly reported behaviors include DDoS, defacement, exploitation of exposed services, compromise of network-connected cameras and monitoring systems, theft and publication of sensitive data, and broad social-media amplification of claimed successes. Public reporting has also described unauthorized access to networking devices and web infrastructure across civilian and government environments, including schools, hospitals, banks, telecommunications, and public-sector entities. Indian Cyber Force is widely described as a hacktivist actor rather than a conventional cybercrime or espionage group. Allegations of possible links between some members and Indian government-linked entities have been reported publicly, but such claims remain unconfirmed; the group has publicly presented itself as non-governmental. Its dominant motivation is hacktivism, with operations driven by nationalist and geopolitical causes rather than financial gain.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.