CSIDB logo
Threat actor

Godzilla

Attribution profile

Type
Activist
Location
India
Known incidents
3 incidents
First seen
2014-04-08
Last seen
2015-11-26
Updated
2026-07-31 03:05
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Godzilla is the alias used by an Indian hacker who has been publicly linked to a series of website defacements targeting extremist organizations based in Pakistan. The actor’s known location is India, and the moniker appears in multiple reports describing actions against groups such as Lashkar-e-Taiba, its political wing Jamat ul Dawa, and Tehreek e Taliban Pakistan. The actor’s activity is consistently described as retaliatory or commemorative in nature, with messages that condemn militant leadership, accuse Pakistani military institutions of supporting terrorism, and assert national pride following major terrorist incidents. These statements indicate that the actor’s strategic objectives are primarily disruption of online propaganda channels and ideological messaging rather than financial gain or espionage.

The tactics, techniques, and procedures attributed to Godzilla involve exploiting security weaknesses in shared hosting environments to gain unauthorized access and then defacing the compromised sites. In the 2014 takedown of the Tehreek e Taliban Pakistan website, the actor reportedly identified several security flaws on the shared server and used them to render the site inaccessible. Similar methods were referenced in the 2015 campaigns where approximately two hundred Pakistani websites were defaced, suggesting a reliance on web application vulnerabilities rather than custom malware or advanced persistent threat tooling. No specific malware families, exploit kits, or specialized tooling suites are mentioned in the available sources, and the actor’s approach appears focused on straightforward web defacement techniques.

Publicly reported operations that illustrate the actor’s pattern include the April 2014 disruption of the Umar media site associated with Tehreek e Taliban Pakistan, the November 2015 defacement of roughly two hundred Pakistani websites—including the primary online platforms of Lashkar-e-Taiba—as a response to a prior terrorist attack, and the earlier defacement of two Jamat ul Dawa websites on the fifth anniversary of the 2008 Mumbai attacks. These incidents collectively demonstrate a repeated focus on silencing extremist propaganda outlets and conveying political messages through website disruption, with each action framed as a retaliatory measure by the actor. The available information does not establish any formal state sponsorship, criminal consortium affiliation, or broader organizational structure behind the alias.

Incidents

Attributed incidents are available to members.

3 incidents
CSIDB