Indian Cyber Force (ICF) is an India-based hacktivist group founded in 2022 that conducts politically motivated cyber operations aligned with pro-India causes. The group is known for disruptive and intrusive activity including distributed denial-of-service attacks, website defacement, unauthorized access to internet-connected devices and web services, and publicized data breaches. Its operations have frequently tracked geopolitical flashpoints involving India and have targeted states and entities perceived as adversarial to Indian interests. Some reporting has characterized parts of its activity as influenced by Hindu nationalist and anti-Muslim sentiment. ICF publicly presents itself as non-governmental, while allegations of links to government-associated individuals remain unverified. ICF has repeatedly targeted Pakistan, which appears to be its most frequent focus, alongside operations affecting Bangladesh, Canada, Palestine, Qatar, the Maldives, China, and Indonesia. Reported victims have included government bodies, military-related organizations, police entities, courts, universities, telecommunications providers, financial institutions, hospitals, and other public-facing services. The group has been associated with campaigns involving coordinated DDoS waves, mass website defacements, exploitation of exposed services, compromise of IP camera networks, and theft and leakage of sensitive records. Publicly reported operations include attacks on Canadian government and military-related websites during the #OpCanada campaign, disruptive activity against Palestinian entities after the October 2023 Hamas attack on Israel, attacks on Qatari targets during a diplomatic dispute involving former Indian naval officers, defacements and compromises in the Maldives during bilateral tensions, and multiple claimed breaches and leaks affecting Pakistani institutions in 2024 and 2025. The group’s tradecraft is consistent with hacktivist operations focused on disruption, propaganda, and reputational damage, but it has also demonstrated recurring data-exposure and exfiltration behavior. Reported activity includes identifying vulnerabilities in government websites, compromising large numbers of websites, accessing network monitoring systems and internet-connected cameras, and leaking personal, administrative, and institutional data. Third-party tracking has listed ICF among the more active hacktivist groups in 2024, and public defacement archives have recorded numerous incidents attributed to it.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.