Indian Cyber Mafia is a pro-India hacktivist entity referenced in the context of the 2025 India-Pakistan cyber escalation. It has been identified as participating in coordinated retaliatory operations against Pakistani targets, including website defacement activity against Pakistani government infrastructure. The group appears to operate as part of a broader ecosystem of non-state, politically motivated hacktivist actors active during periods of India-Pakistan tension. Its observed tradecraft is consistent with high-visibility hacktivism rather than advanced clandestine intrusion activity. Reported operations align with disruptive and propagandistic tactics such as website defacement and coordinated attack waves conducted in response to geopolitical events. In the 2025 crisis period, Indian Cyber Mafia was listed among pro-India groups involved in retaliatory cyber activity alongside other Indian hacktivist collectives. Available information directly supports characterization of Indian Cyber Mafia as a politically motivated hacktivist actor associated with Indian interests and focused on Pakistani targets. High-confidence evidence in the supplied material does not establish ransomware operations, sustained espionage activity, or a broader verified victimology beyond Pakistan-linked government targets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Indian hacktivist group that retaliated by defacing a Pakistani government website and issuing aggressive nationalist messaging.
Listed (via Radware reference excerpt) as a hacktivist group involved in coordinated waves of attacks; no specific operations described in this content.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.