CSIDB logo
Threat actor

The Mallu Soldiers

Attribution profile

Type
Activist
Location
India
Known incidents
4 incidents
First seen
2014-10-07
Last seen
2015-09-27
Updated
2026-08-01 05:42
Aliases
4 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor is known by several aliases including Indian Hackers Online Squad, The Mallu Soldiers, Cyber warriors and The Mallu Cyber Soldiers, with an indicated base of operations in India. These groups operate as loosely affiliated hacking collectives rather than a single unified organization and have been observed conducting retaliatory cyber actions in response to perceived provocations against Indian interests, particularly those related to the Kashmir dispute. Their activities are primarily characterized by website defacements that display national flags, political slogans and images of public figures to convey messages of dissent and solidarity.

Targeting has focused on Pakistani governmental, educational and utility sector entities, as well as political party platforms. Incidents have included the defacement of the National University of Modern Languages Lahore campus, the Pakistan Electric Power Company website and the official site of the Pakistan Peoples Party, where attackers posted Indian flags, mocked leadership and referenced the Kashmir conflict. In a separate episode, a Pakistani hacker’s defacement of a Kerala government portal prompted a coordinated response that compromised more than forty Pakistani government and educational websites, displaying burned Pakistani flags and taunting references to the original incident. The actors’ strategic objectives appear limited to disruption and political signaling, with no evidence of financial gain, espionage or data theft in the reported operations.

Observed tactics involve gaining unauthorized access to web servers to replace homepage content with custom graphics, flags and textual messages; no specific malware families, exploit kits or initial access vectors have been documented in the sources. Attribution to state sponsorship or criminal consortia has not been established publicly, and the groups remain described as independent hacker collectives. Notable campaigns comprise the October 2014 defacements of NUML, PEPCO and PPP sites, the October 2014 PPP defacement by the actor using the alias Black Dragon and the September 2015 wave of over forty Pakistani website defacements conducted by Mallu Cyber Soldiers alongside allied groups. These actions collectively illustrate a pattern of retaliatory, politically motivated website disruption originating from Indian‑based hacker collectives.

Incidents

Attributed incidents are available to members.

4 incidents
CSIDB