Indian Cyber Force (ICF) is a hacktivist group described as based in India and active since 2022. It conducts politically motivated cyber operations aligned with pro-India causes and has also been characterized as pro-Israel. Reported activity indicates a focus on disruptive and intrusive operations against countries and entities perceived as adversarial to Indian interests, with Pakistan appearing as its most frequently targeted country. ICF has been associated with distributed denial-of-service attacks, website defacements, unauthorized access to exposed systems, compromises of network-connected cameras and other internet-facing devices, and data-breach activity resulting in public leaks. Reported campaigns include operations against government, military, telecommunications, financial, health-care, education, and public-sector targets in Pakistan, Bangladesh, Canada, Palestine, Qatar, the Maldives, China, and Indonesia. Its operations have included retaliatory campaigns tied to geopolitical flashpoints, diplomatic disputes, and regional tensions. Publicly attributed incidents include attacks on Canadian government and military-related websites during the #OpCanada campaign; disruptive and intrusive activity against Palestinian organizations after the October 2023 Hamas attacks; operations against Qatari targets during the dispute over former Indian naval officers; defacements and account compromises in the Maldives during bilateral tensions; and repeated compromises and leaks affecting Pakistani institutions, including police, banking, university, and tax-related entities. The group has also been linked to attacks and data exposure affecting Bangladeshi public-sector systems. ICF is primarily characterized as a hacktivist actor rather than a conventional cybercriminal or espionage unit. Allegations of links to Indian government-associated entities have been reported, but such claims remain speculative and are not established as confirmed state direction. The group publicly presents itself as non-governmental.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.