Kerala Cyber Hackers
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The Kerala Cyber Hackers, also known by their alias Kerala Cyber Hackers, are a threat actor based in India. They have been identified primarily through a single publicly reported incident in which they targeted a government health mission website in New Delhi. Their activity is confined to the Indian region and focuses on the healthcare sector, specifically systems handling COVID‑19 patient data. The group’s stated purpose, as expressed in their own communications, is to protest what they perceive as inadequate protection and support for healthcare workers during the pandemic, rather than to pursue financial gain, espionage, or destructive disruption.
In the reported operation, the Kerala Cyber Hackers claimed to have breached the Delhi State Health Mission website in under ten minutes, indicating the use of a web‑application exploitation vector to gain initial access. They accessed a database containing personal information—names, ages, addresses, and test results—of approximately eighty thousand COVID‑19 patients. After demonstrating the breach by posting screenshots of patient records, the group asserted that they would not release the stolen data publicly. No mention is made of specific malware families, custom tooling, or additional intrusion techniques beyond the web‑based intrusion described.
The most notable campaign attributed to the Kerala Cyber Hackers is the June 27 2020 intrusion into the Delhi Government’s Delhi State Health Mission website. This operation highlighted vulnerabilities in the storage of citizens’ health information and occurred amid broader concerns about data security practices within Indian government systems, including prior issues with pandemic‑related tracing apps and national biometric databases. At the time of reporting, authorities had not issued a formal response to the allegations, and the group’s actions were framed as a protest against perceived shortcomings in personal protective equipment provision and overall healthcare worker safety. This incident remains the sole publicly documented activity linking the alias to a specific target, objective, and method.
Incidents
Attributed incidents are available to members.
2 incidents