Indian Cyber Force (ICF) is an India-based hacktivist group active since at least 2022 that conducts politically motivated cyber operations aligned with pro-India causes and, in some campaigns, pro-Israel positions. The group is known primarily for disruptive and propaganda-oriented activity such as distributed denial-of-service attacks, website defacements, claimed data breaches, and publicized compromises of internet-connected cameras and network devices. Its operations are typically framed as retaliation for geopolitical events involving India, including India-Pakistan tensions, the India-Maldives diplomatic dispute, the sentencing of former Indian Navy personnel in Qatar, allegations by Canada related to Hardeep Singh Nijjar, and the Israel-Hamas war. Indian Cyber Force has repeatedly targeted Pakistani entities and is most consistently associated with operations against Pakistan. Reported and claimed targets include government portals, financial institutions, universities, police-related systems, and surveillance infrastructure. The group has also been linked to campaigns against Palestinian entities, including Hamas-linked and Palestinian banking and telecommunications targets, as well as activity affecting Canada, Qatar, Bangladesh, the Maldives, Iran, China, and Indonesia. During the 2025 India-Pakistan crisis and Operation Sindoor period, Indian Cyber Force was identified among the most active pro-India hacktivist groups and publicly claimed intrusions, data theft, and large-scale camera compromises against Pakistani organizations. The actor’s observed tradecraft centers on high-visibility disruption and information operations rather than stealthy long-term intrusion. Commonly reported behaviors include DDoS attacks, website defacement, unauthorized access to exposed services and portals, theft and public leaking of data, and compromises of CCTV or other internet-facing devices. Public reporting also associates pro-India hacktivist activity during the 2025 crisis with spear phishing, social engineering, ransomware claims, and persistence-oriented exploitation, but the strongest corroborated pattern for Indian Cyber Force specifically remains disruptive hacktivism and opportunistic intrusion. The group maintains a strong social-media presence and uses public channels to announce operations, amplify political messaging, and advertise claimed successes. Indian Cyber Force is also referred to as ICF and Indian Cyber Force (ICF). It presents itself as non-governmental. Speculation about possible links between some members and Indian government-linked entities has been reported, but high-confidence attribution to the Indian state is not established. The group is best characterized as a politically motivated Indian hacktivist actor focused on retaliatory cyber campaigns, propaganda impact, and public demonstration of offensive capability against perceived adversaries of India.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pro-Israel hacktivist group targeting pro-Iran channels and defacing Pakistani and Iranian websites in solidarity operations.
Pro-India hacktivist group conducting retaliatory cyberattacks against Pakistani targets, including DDoS and claimed compromises of government and institutional websites.
Pro-India hacktivist group that claimed breaches of Pakistani government, banking, university, and surveillance systems during Operation Sindoor.
Pro-India (and described as pro-Israel) hacktivist collective conducting politically motivated operations including DDoS, website defacements, and data leaks/breaches; also claims compromises of IP camera networks and other networked devices, often in response to geopolitical events involving India (e.g., Canada diplomatic row, Israel-Hamas conflict, India–Maldives row, India–Pakistan tensions).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.