Indian Cyber Force (ICF) is an India-based hacktivist collective that conducts politically motivated cyberattacks in support of pro-India causes and has publicly expressed a pro-Israel stance. Pakistan is its principal target, with additional operations targeting Palestinian, Canadian, Qatari, Maldivian, Bangladeshi, Iranian, and Indonesian entities. Its targeting follows geopolitical conflicts and diplomatic disputes rather than an established financial objective. ICF uses distributed denial-of-service attacks, website defacement, unauthorized access, and data theft and publication. Targets include government agencies, military websites, banks, telecommunications providers, educational institutions, healthcare organizations, and commercial websites. The group has repeatedly targeted internet-connected surveillance cameras and publicly distributed compromised account information. It publicizes operations and political messaging through X and Telegram; many of its larger breach claims remain independently unverified. Notable campaigns include attacks against Canadian government and military websites under #OpCanada during the 2023 India–Canada diplomatic dispute; attacks against Palestinian entities, including Hamas and banking and telecommunications services, following the October 2023 outbreak of the Israel–Hamas war; and attacks against Qatar following death sentences imposed on eight former Indian Navy personnel. ICF also conducted website defacements during the India–Maldives diplomatic dispute and participated in pro-India hacktivist activity during the 2025 India–Pakistan escalation. Its Pakistani operations have included attacks on public-sector and financial targets, surveillance-camera compromises, and publication of stolen personal information.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pro-Israel hacktivist group targeting pro-Iran channels and defacing Pakistani and Iranian websites in solidarity operations.
Pro-India hacktivist collective included among groups reporting retaliatory attacks against Pakistani websites. The report does not individually validate its claims.
Pro-India hacktivist group that claimed breaches of Pakistani government, banking, university, and surveillance systems during Operation Sindoor.
Pro-India (and described as pro-Israel) hacktivist collective conducting politically motivated operations including DDoS, website defacements, and data leaks/breaches; also claims compromises of IP camera networks and other networked devices, often in response to geopolitical events involving India (e.g., Canada diplomatic row, Israel-Hamas conflict, India–Maldives row, India–Pakistan tensions).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.