Electronic Army Special Forces is a pro-Pakistan hacktivist entity active in the cyber operations surrounding the 2025 India-Pakistan crisis. It was identified among multiple non-state groups that publicly claimed attacks against Indian targets following the April 2025 Pahalgam attack and subsequent military escalation. The group has also appeared under the Vietnamese rendering "Lực Lượng Đặc Biệt Quân Đội Điện Tử." Reported activity attributed to the group centered on high-visibility disruptive operations rather than sophisticated intrusion tradecraft. Claimed operations associated with Electronic Army Special Forces focused primarily on Indian government digital services and judicial or public-sector platforms. The group and its affiliates were reported to have claimed 18 attacks, with emphasis on Indian courts and government digital public services. It also appeared in coalition-style hacktivist claims alongside other pro-Pakistan groups, including assertions of distributed denial-of-service activity against prominent Indian government institutions such as central ministries, CERT-In, and the National Testing Agency. Available assessments indicate that many such claims across the broader campaign were exaggerated or had negligible operational impact, consistent with a hacktivist pattern of brief service disruption, propaganda amplification, and psychological pressure. Within the wider 2025 crisis ecosystem, the dominant tactics used by aligned hacktivist groups included DDoS attacks, website defacements, phishing, and unverified breach or exfiltration claims. For Electronic Army Special Forces specifically, the directly supported activity is concentrated on claimed disruptive operations against Indian public-sector targets. The actor is best characterized as a politically aligned hacktivist participant in the India-Pakistan cyber confrontation, motivated by nationalist objectives rather than financial gain.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named hacktivist collective cited as part of the pro-Pakistan cyber mobilization against Indian targets.
Hacktivist collective claiming attacks (notably DDoS) against Indian courts and government digital public services; verification in the content suggests negligible/no sustained disruption.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.