Team Insane PK is a Pakistan-based hacktivist group associated with pro-Pakistan and, in some reporting, pro-Iran online operations. The group has been linked to politically motivated website compromises and defacements conducted in the context of regional geopolitical tensions. Reported activity includes the compromise of the Indian Army College of Nursing website, where the group posted a provocative ideological message, and the defacement of a commercial website in India. Team Insane PK has also been identified among groups targeting Israeli entities. The group is commonly referenced alongside other South Asian threat clusters active in anti-India campaigns, including APT36 and SideCopy, but available information supports classifying Team Insane PK primarily as a hacktivist actor rather than a confirmed state-sponsored intrusion set. Its observed behavior is consistent with disruptive and propagandistic operations intended to signal political alignment, shape narratives, and embarrass targets through unauthorized website access and public-facing tampering. Reporting also places the group within a broader ecosystem of globally distributed ideologically aligned actors that support Iranian narratives, although direct command-and-control or formal state direction is not established in the available information.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pakistan-based hacktivist group involved in website compromise and defacement targeting an Indian military-affiliated educational institution.
Pro-Iran hacktivist group operating from Pakistan as part of Iran’s globalized recruitment ecosystem.
Pro-Pakistan hacktivist group named as taking part in cyber attacks against India during Operation Sindoor.
Referenced as a South Asian hacktivist group targeting Israeli entities (per CERT-EU brief excerpt); no further detail provided.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.