Vulture is an Iranian-affiliated hacktivist group that was active in the cyber operations surrounding the 2025 India-Pakistan crisis. It publicly expressed support for Pakistan and was identified among pro-Pakistan or anti-India groups participating in retaliatory cyber activity after the Pahalgam attack and subsequent military escalation. Reported activity attributed to Vulture focused on Indian targets, especially government websites and educational institutions. Vulture’s claimed operations were primarily characteristic of hacktivist disruption and propaganda rather than sophisticated intrusion tradecraft. It was associated with claimed distributed denial-of-service attacks and website-focused operations against Indian public-sector entities, including high-profile national government portals. Vulture also appeared in a coalition with other hacktivist groups claiming attacks against senior Indian government websites and ministries. Additional claims linked Vulture to attacks against Indian cyber and testing-related public institutions. Available reporting indicates that many of the group’s public claims during this period were exaggerated, unverified, or had minimal observable operational impact. In multiple cited cases, targeted Indian government services remained operational or experienced at most negligible disruption. No high-confidence evidence in the supplied material establishes Vulture as a sophisticated espionage or financially motivated actor; the observed pattern is more consistent with politically aligned hacktivism intended to generate visibility, psychological pressure, and symbolic impact during a regional crisis.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Iranian-affiliated group that publicly supported Pakistan during the cyber escalation.
Iranian group named as participating in cyber activity aligned against India during Operation Sindoor.
Hacktivist group frequently involved in joint-operation claims; alleged DDoS against high-profile Indian government sites (PMO/President/ministries) and CERT-In/NTA, with content indicating minimal or no observable impact.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.