HolaKo
Attribution profile
- Type
- Activist
- Location
- India
- Known incidents
- 1 incident
- Sources
- 1 source
- First seen
- 2015-04-30
- Last seen
- 2015-04-30
- Updated
- 2026-08-01 02:36
- Aliases
- 1 alias
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor tracked under the alias HolaKo has been identified as operating from India. HolaKo presents themselves as a Palestinian‑friendly hacker whose actions are motivated by opposition to the Israeli occupation of Palestinian territories. The alias first appeared in public reporting when HackRead published an interview with the individual following a defacement of an Indian web portal. In that interview HolaKo explained that the goal of the intrusion was to deliver a political message concerning Palestine. The actor has been described in the media as having previously targeted other organizations for similar political causes. No additional names, affiliations or group memberships have been publicly linked to HolaKo. The actor’s public communications include an offer to be contacted directly, indicating a willingness to engage with journalists or supporters. All available information about HolaKo stems from the two defacement incidents described in the sources.
HolaKo’s observed activity centers on compromising web‑accessible services, particularly subdomains that host email, hosting or informational content. The sectors affected include media and entertainment portals as well as international professional associations. Geographically, the actor has targeted Indian‑hosted domains while also hitting sites that are globally reachable. The stated objective of the operations is to convey a political message rather than to pursue financial gain, espionage or prolonged service disruption. In the Rediff incident HolaKo claimed to have obtained unauthorized access to the target’s databases, email systems and login credentials before administrators revoked the entry. The actor left a defacement page containing the text “Hacked by HolaKo, Rediff mail owned!? w00t !! Free Palestine ! #SaveGaza”. No specific malware families, exploit kits or toolsets are mentioned in the reporting; the activity is limited to web defacement and the claim of data access. Proof of the compromise was provided via a link to the defaced subdomain and a zone‑h mirror identifier.
The most thoroughly documented operation occurred on 30 April 2015 when HolaKo defaced the businessemail.rediff.com subdomain of the Rediff portal. The compromised subdomain provided email, Windows and Linux web hosting services to Rediff customers. After gaining access, HolaKo displayed the political message and asserted that databases, email systems and login data had been accessed. A zone‑h mirror with ID 24135554 was posted as evidence, and the Rediff domain was restored to normal operation shortly after the defacement was discovered. Prior to the Rediff event, HolaKo was reported to have defaced the Institute of Electrical and Electronics Engineers (IEEE) website in support of the same Palestinian cause. The IEEE defacement similarly featured a political statement and was noted in news coverage as a notable intrusion. Both incidents were temporary; administrators removed the unauthorized content and restored the affected services without indicating any lasting damage. Aside from these two publicly reported actions, no further campaigns, tools or operational details concerning HolaKo have been made available.
Incidents
Attributed incidents are available to members.
1 incidentSources
Sources available to members: 1 source.