Bangladesh Civilian Force (BCF) is a hacktivist collective and online influence brand centered on pro-Palestinian messaging and antagonistic narratives toward India and Israel. The actor maintains a fragmented but coordinated cross-platform presence spanning Telegram, Instagram, Twitter/X, Facebook, and a dedicated website, with shared branding, mutual amplification, and overlapping references indicating an intentionally resilient ecosystem rather than a single narrowly bounded account set. BCF has been publicly associated with website defacement activity, with multiple victims attributed to the group over a monitored period from 2023 into 2024. Its propaganda and defacement messaging repeatedly referenced India and Israel, aligning operational activity with its ideological positioning. Recruitment messaging linked to BCF explicitly sought individuals skilled in defacement and DDoS operations, and described separate social-media and cyber-focused sections, indicating both propaganda and disruptive cyber components. The group’s Telegram presence dates back at least to 2021 and includes multiple channels that forward and reinforce one another without exclusivity claims, suggesting coordination or accepted coexistence under the same banner. BCF also appears to cultivate supporter engagement and visibility through large social-media audiences and sustained community interaction. Available evidence supports characterization of BCF as a hacktivist actor motivated primarily by ideology and influence-oriented activism, with demonstrated disruptive cyber activity including defacement and stated interest in DDoS operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.