CSIDB logo
Threat actor

DangerPro

Attribution profile

Type
Activist
Location
Bangladesh
Known incidents
2 incidents
First seen
2015-07-07
Last seen
2015-09-10
Updated
2026-08-01 07:53
Aliases
2 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor known as DangerPro also operates under the alias Cyber‑71 and has been linked to Bangladesh in open‑source reporting. Public sources identify the group as a Bangladeshi hacking collective that has carried out website defacements to convey political messages. The actor’s location is noted only as Bangladesh, with no further geographic detail provided in the available material. No public attribution to a state sponsor or criminal consortium has been made for DangerPro/Cyber‑71. The alias usage appears consistent across the incidents described, with the group switching between DangerPro and Cyber‑71 in its communications.

The actor’s observed targets include educational institutions and commercial entities, with attacks directed at a Bangladeshi university and an Israeli franchise of a fast‑food chain. In the Dhaka University incident, the defacement protested the imposition of value‑added tax on private university tuition fees, indicating a goal of disrupting services to draw attention to a domestic policy issue. The Pizza Hut Israel defacement carried a message addressed to the Indian government, accusing it of border killings and announcing a cyber war, showing an intention to leverage a foreign target for a geopolitical statement. Both actions resulted in service interruption, as the affected sites were taken offline or redirected to alternative pages. The actor’s strategic objective appears to be disruption coupled with political messaging rather than financial gain or espionage.

Technical details reported for the operations are limited to website defacement techniques, specifically the replacement of landing pages with protest text while leaving the remainder of the site untouched. The group disseminated screenshots of the defacements on Facebook, using the platform to publicize its actions and to prompt user reports to the targeted organizations. In the Pizza Hut Israel case, the compromised contact page was subsequently redirected to the official Pizza Hut Facebook page for Israel, further disrupting normal web traffic. No mention of malware families, exploit kits, or specific initial access vectors appears in the sources, so the actor’s tooling style is characterized by straightforward web‑site alteration and social‑media amplification. The two cited incidents represent the actor’s publicly reported campaigns, illustrating a pattern of using defacement to convey politically motivated messages across different sectors and regions.

Incidents

Attributed incidents are available to members.

2 incidents
CSIDB