Kerala Cyber Xtractors is a pro-India hacktivist group active in the cyber operations that accompanied the 2025 India-Pakistan crisis and Operation Sindoor. It has been identified among the most active and vocal Indian-aligned hacktivist groups during that period, alongside groups such as Indian Cyber Force, Indian Cyber Defender, Unknown Cyber Cult, and Kerala Cyber Warriors. The group publicly claimed offensive operations against Pakistani targets, including website defacements, service disruption, and alleged unauthorized access to government-related data. Reported activity attributed to Kerala Cyber Xtractors centers on Pakistani government and public-sector entities. Claimed operations include defacement of a Pakistani defense-industrial website, disruption of airport-related websites in Islamabad and Karachi, and an alleged compromise and leak involving Pakistan's national identity database authority. These operations fit the broader pattern of high-visibility retaliatory hacktivism seen during the crisis, where public claims, propaganda value, and psychological impact were prominent. The group's observed tradecraft is consistent with hacktivist operations focused on disruption and publicity rather than stealthy long-term intrusion. High-confidence behaviors directly associated with the group include website defacement, distributed denial-of-service activity or comparable service disruption claims, and alleged data theft or leakage. Kerala Cyber Xtractors is best characterized as a politically motivated, pro-India hacktivist actor engaged in anti-Pakistan cyber operations during a period of interstate tension.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pro-India hacktivist group involved in retaliatory cyberattacks against Pakistani organizations.
Pro-India hacktivist group that claimed website defacement, service disruption, and data theft against Pakistani defense, aviation, and identity systems during Operation Sindoor.
Listed (via Radware reference excerpt) as a hacktivist group involved in coordinated waves of attacks; no specific operations described in this content.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.