Anonymous Kashmir is a pro-Palestinian and pro-Iran hacktivist group active in the 2025 wave of cyber operations surrounding the Israel-Iran conflict. It has been publicly identified as part of a broader ecosystem of more than 80 ideologically aligned hacktivist groups that coordinated propaganda, resource sharing, and offensive activity primarily through Telegram. The group formalized an alliance with Mr Hamza Cyber Force, reflecting a higher degree of organization and inter-group coordination than earlier, looser hacktivist campaigns. The actor is associated with ideological and political motivations rather than conventional financially driven cybercrime. Its activity is linked to anti-Israel operations and support for Palestinian and Iranian causes. Reporting places Anonymous Kashmir among groups that publicly announced alliances, shared resources, and coordinated operations with other hacktivist entities such as Keymous+ and Inteid in the same campaign environment. High-confidence reporting supports Anonymous Kashmir’s role in coordinated hacktivist operations, but does not provide sufficiently corroborated technical detail on specific malware, intrusion methods, or confirmed victim compromises attributable to the group alone. As a result, its most defensible characterization is as an ideologically motivated hacktivist actor participating in organized anti-Israel cyber campaigning and coalition-building with like-minded groups.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pro-Palestinian/pro-Iranian hacktivist group involved in cyber campaigns against Israel and its allies.
Hacktivist actor allied with Mr Hamza, publicly framing operations as support for Palestine and Iran.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.