Milw0rm was a late-1990s hacker group associated with politically motivated website defacement activity and disruptive intrusions. The group is linked to the British hacker known as JF and was publicly associated with a mass compromise affecting more than 300 websites, where anti-nuclear messages were substituted onto victim homepages. Reporting tied the operation to exploitation of weaknesses in a shared hosting environment and characterized the campaign as anti-nuclear protest activity rather than security research. Milw0rm was also reported to have claimed responsibility for stealing email and deleting web servers at India’s Bhabha Atomic Research Centre during a period of heightened India-Pakistan nuclear tensions. Available information supports characterization of the group as hacktivist in motivation, using unauthorized access and disruptive post-compromise actions to advance political messaging.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a named hacking group in the historical timeline/navigation content.
Named hacking group listed in the content's 1990s timeline/navigation material.
Named as a hacking group in a 1990s hacking timeline/sidebar; no specific operations, malware use, or targeting details are provided in the content.
Hacktivist group tied to JF that conducted anti-nuclear politically motivated intrusions, including mass website defacements and attacks on India's atomic research center.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.