SYLHET GANG-SG is a Bangladesh-linked hacktivist group active in the pro-Iranian and pro-Palestinian cyber ecosystem that expanded during the 2025-2026 Middle East and South Asia conflict cycles. The group has been identified as part of a globally distributed network of ideologically aligned operators recruited outside Iran and used to support deniable disruptive operations. It has also publicly declared allegiance to KillNet 2.0, reflecting overlap with broader transnational hacktivist coalitions. The group is primarily associated with disruptive operations, especially distributed denial-of-service activity against government and public-sector targets. It has been cited in campaigns against Kuwaiti government infrastructure, Indian government and financial-sector entities during the India-Pakistan crisis, and Israeli digital services and public-facing resources during the Iran-Israel confrontation. Reported targeting has included e-government portals, government ministries, financial institutions, media outlets, and, in some claims, industrial control environments. SYLHET GANG-SG has collaborated with other aligned groups including DieNet, Team Azrael, and Keymous+. It was promoted alongside DieNet at that group’s launch and later appeared in joint anti-India and anti-Israel operations. In the broader Iranian-aligned campaign environment, the group has been listed among participants in coordinated operations rooms and coalition efforts involving multiple hacktivist brands. Operationally, the group is most consistently linked to DDoS-style disruption and propaganda amplification rather than high-confidence sophisticated intrusion tradecraft. It has made data-theft and industrial-control targeting claims, including alleged exfiltration from Indian government systems and claimed targeting of PLCs in Tel Aviv, but reporting indicates that several associated breach claims in this ecosystem were exaggerated, recycled, or only partially substantiated. A claimed breach involving India’s National Informatics Centre was assessed as relying largely on publicly available material, and a claimed Andhra Pradesh High Court compromise appeared to involve mostly public case metadata with some leaked password hashes. As with many conflict-driven hacktivist actors, SYLHET GANG-SG appears to combine symbolic targeting, coalition branding, and information operations with opportunistic disruptive attacks.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Southeast Asian hacktivist collective using DieNet tooling to target Kuwaiti government infrastructure.
Named hacktivist group participating in the Iranian-aligned cyber campaign during the 2026 conflict.
Hacktivist group aligned with DieNet in operations against Indian government portals and part of DieNet’s broader support and amplification ecosystem.
Hacktivist group claiming attacks on Israeli government-related resources and associated with underground DDoS-for-hire activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.