Anonymous Pakistan
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Anonymous Pakistan, also known as ASOR Hack Team and Anonymous Op Pakistan, is a hacktivist collective that has operated from Pakistan and publicly aligns itself with the global Anonymous network. The group uses the aliases interchangeably in its communications and has been identified in open‑source reporting as the actor behind a series of website defacements, distributed denial of service attacks, and data leaks targeting Pakistani institutions. While the collective claims no fixed leadership structure, its activities have been documented in news articles that attribute specific incidents to the ASOR Hack Team moniker.
The collective’s observed targeting focuses on government ministries, security force agencies, media outlets, and political party websites within Pakistan, reflecting a pattern of disruption aimed at state‑related and politically affiliated online assets. Their strategic objectives, as expressed in statements accompanying attacks, include disrupting service availability through DDoS floods and defacing web pages to convey political messages, while also leaking private employee data such as usernames, passwords, contact details, and sensitive military designations to expose perceived wrongdoing. The tactics, techniques, and procedures referenced in the reporting consist primarily of volumetric DDoS attacks that render sites inaccessible, straightforward web defacement involving the replacement of content with derogatory imagery and text, and the exfiltration and publication of stolen databases without mention of specific malware families, exploit kits, or initial access vectors like phishing or supply‑chain compromise. No public evidence links the group to a state sponsor or a formal criminal consortium; its affiliations are limited to the self‑declared connection with the broader Anonymous movement.
Among its reported campaigns, the September 2014 operation stands out as a representative example, during which the group defaced the Ministry of Interior’s website with offensive remarks against the Interior Minister and doctored images of senior officials, rendered the Government of Pakistan portal inaccessible via DDoS, and leaked personal data from the Faisalabad Police Department website. The same wave of activity included attacks on the District Courts Gujranwala portal, the Jaag TV, CNBC Pakistan, and Samaa FM media sites, as well as the defacement of PTI‑related domains such as fundyourtsunami.com and fundyourtsunami.insaf.pk, accompanied by messages criticizing the political system while intermittently expressing support for the military and former leaders like Retd General Pervez Musharraf. These incidents illustrate the group’s reliance on disruption and data exposure as core components of its hacktivist methodology within the Pakistani cyber landscape.
Incidents
Attributed incidents are available to members.
1 incident