CSIDB logo
Threat actor

Anti Mortadin!@

Attribution profile

Type
Activist
Location
Pakistan
Known incidents
1 incident
Sources
1 source
First seen
2014-05-15
Last seen
2014-05-15
Updated
2026-07-31 20:33
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Anti Mortadin!@ is a hacker alias associated with a group that operates from Pakistan and has publicly expressed support for the Taliban. The actor first came to attention in mid‑May 2014 when the official website of the Rawalpindi police was defaced with a message crediting the breach to Anti Mortadin!@ and proclaiming a victory for the Taliban, accompanied by images of Al‑Qaeda and Taliban figures. While the group’s exact organizational structure is not disclosed in open sources, the statements left on compromised sites indicate an ideological alignment with extremist narratives and a retaliatory stance toward perceived Indian cyber aggression. No public evidence links the alias to a state‑sponsored program or a formal criminal consortium; the actor is described in reporting as a hacktivist entity rather than a financially motivated enterprise.

The actor’s targeting pattern, as evidenced by the two reported incidents, focuses on government and telecommunications sectors within the South Asian region. The Rawalpindi police website, a public‑facing government portal, was chosen for defacement to spread propaganda, while the intrusion into the BSNL intranet portal for the Indian state of Haryana served as a demonstrative strike against an Indian telecom provider. The strategic objectives observable from the messages are primarily disruption and messaging: the defacement sought to embarrass the Pakistani police and showcase Taliban sympathies, whereas the BSNL breach was framed as payback for alleged Indian hacking and included a warning about escalating cyber vulnerabilities. There is no indication in the source material that the actor pursues financial gain, espionage, or data theft; the activities appear aimed at publicity and ideological signaling.

Regarding tactics, techniques, and procedures, the actor relies on web‑based defacement and unauthorized access to online portals, leaving textual claims and imagery as signatures of the compromise. No malware families, exploit kits, or specialized tooling are mentioned in the available reports; the intrusions appear to involve standard web‑application vulnerabilities sufficient to alter site content and gain access to an intranet portal. The mirror of the Rawalpindi police defacement was hosted on Aljyyosh.org, suggesting the use of external sites to preserve and disseminate evidence of the operation. The group’s public statements reference a broader pattern of Pakistani hacktivists targeting Indian telecom domains, indicating a recurring focus on cross‑border website disruption rather than sustained, multi‑stage campaigns. These observed behaviors constitute the entirety of the publicly documented activity for Anti Mortadin!@.

Incidents

Attributed incidents are available to members.

1 incident

Sources

Sources available to members: 1 source.

CSIDB