Indian Cyber Defender is a pro-India hacktivist group that was active during the 2025 India-Pakistan crisis and Operation Sindoor. It was identified alongside other Indian-aligned groups such as Indian Cyber Force, Kerala Cyber Xtractors, Unknown Cyber Cult, WhiteHorse, Cyber Warriors India, AnonOpsIndia, and Kerala Cyber Warriors as part of retaliatory cyber activity directed at Pakistani targets. The group has been associated with politically motivated offensive cyber operations in the context of India-Pakistan tensions. Reported activity attributed to Indian Cyber Defender includes claimed attacks against Pakistani government and institutional targets, with the broader pro-India campaign characterized by distributed denial-of-service attacks, website defacements, spear phishing, social engineering, ransomware claims, and intrusion activity. Available reporting indicates these operations were largely high-visibility hacktivist actions intended to disrupt services, project nationalist messaging, and impose psychological pressure rather than demonstrate sustained, covert access at the level of a mature state espionage program. Indian Cyber Defender was described as one of the more active and vocal pro-India groups on social media during Operation Sindoor. The wider campaign in which it participated targeted Pakistani public-sector and institutional systems, including government, banking, university, logistics, transport, and other organizational infrastructure. High-confidence reporting supports its alignment with hacktivist retaliation and influence-oriented disruption rather than financially motivated cybercrime.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pro-India hacktivist group involved in counterattacks against Pakistani targets during the crisis.
Pro-India hacktivist group named as actively countering pro-Pakistan cyber operations during Operation Sindoor.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.