Indian Cyber Force (ICF), also referred to as Anonymous India in some reporting, is an India-based hacktivist group founded in 2022 that conducts politically motivated cyber operations aligned with pro-India causes. The group is known for disruptive and intrusive activity including distributed denial-of-service attacks, website defacement, unauthorized access to exposed systems, and data-breach operations. Its campaigns have frequently tracked geopolitical flashpoints involving India and have targeted states, institutions, and organizations perceived as adversarial to Indian interests. Some reporting has characterized parts of its activity as influenced by Hindu nationalist and anti-Muslim sentiment. ICF publicly presents itself as non-governmental, while allegations of possible links to government-associated individuals remain unconfirmed. ICF has repeatedly targeted Pakistan and appears to prioritize it above other countries. Reported operations have included compromises of institutional data, repeated intrusions into internet-connected camera infrastructure, and disruptive actions against public- and private-sector entities. The group has also targeted Bangladesh, including police and municipal entities; Canada during the #OpCanada campaign amid diplomatic tensions; Palestinian organizations and institutions after the October 2023 Hamas attacks; Qatar during a dispute involving former Indian naval officers; the Maldives during a bilateral political dispute; and Indonesian military- and diplomatic-linked websites during G20-related tensions. Observed tradecraft includes DDoS, defacement, credential exposure, exploitation of vulnerable internet-facing services, unauthorized access to networked devices such as IP cameras, and theft and publication of allegedly stolen data. The group has demonstrated capabilities spanning reconnaissance, initial access, exfiltration, and disruptive post-compromise actions. Its operations are characteristic of hacktivist campaigns focused on publicity, retaliation, and coercive signaling rather than stealthy long-term espionage.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.