Arabian Hosts is a pro-Pakistan hacktivist group publicly identified as active during the 2025 India-Pakistan crisis and Operation Sindoor-related cyber activity. It was named among anti-India or pro-Pakistan collectives that participated in retaliatory cyber operations following the Pahalgam attack and subsequent military escalation. Reported activity associated with this broader hacktivist wave centered on disruptive and propaganda-oriented operations rather than advanced, covert intrusion tradecraft. Commonly observed behaviors in that campaign included distributed denial-of-service attacks, website defacements, phishing, and public claims of data breaches, many of which were intended to generate psychological impact and visibility. Indian government, defense, and other public-sector entities were among the principal targets of the pro-Pakistan hacktivist ecosystem in which Arabian Hosts was identified. Available information supports classifying Arabian Hosts as a hacktivist actor aligned with anti-India messaging and disruptive cyber operations; high-confidence attribution of more specific independent tradecraft, sub-groups, or state direction is currently not available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pro-Pakistan hacktivist collective identified as part of the broader retaliatory cyber campaign against Indian organizations.
Named as a hacktivist group participating in pro-Pakistan cyber activity against India during Operation Sindoor.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.