CSIDB logo
Threat actor

Tiger Mate

Attribution profile

Type
Sensationalist
Location
Bangladesh
Known incidents
5 incidents
First seen
2015-04-15
Last seen
2016-05-28
Updated
2026-08-01 08:15
Aliases
3 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor referenced in the source material is identified as a group of Bangladeshi hackers who operate under several public aliases, including Ne0‑h4ck3r, TiGER‑M@TE, F0RTYS3V3N and the earlier moniker Tiger M@te. The material explicitly describes them as Bangladeshi individuals who have carried out a series of website defacements targeting prominent internet properties. Their observed activity includes the defacement of Google Malaysia’s domain (google.com.my) and associated services such as ns2.google.com.my, images.google.com.my and youtube.my, as well as the Yahoo.my portal. In addition to the Malaysian targets, the same actors are credited with the defacement of Google Kenya’s domain (google.co.ke) in 2013, indicating a pattern of targeting Google‑branded services across different geographic regions. The defacements were accompanied by a characteristic message that displayed the pseudonyms Ne0‑h4ck3r, TiGER‑M@TE and F0RTYS3V3N, included the tagline “Mirror on the wall | #Hackers r0x Lamers Sux | How are you? | Here we are again!” and provided a contact e‑mail address for communication.

The source material notes that at least one of the actors, Tiger M@te, achieved the Google Malaysia defacement by exploiting a DNS redirection, suggesting that manipulation of domain name system settings is among the tactics they have employed. The repeated defacement of the same Google Malaysia domain within a short time frame indicates a capability to regain access or re‑exploit a vulnerability after initial remediation. No explicit statement regarding the group’s size, financial motives, sponsorship, or ideological orientation is provided in the source, so any description of motive, sponsorship or sophistication would be speculative and is therefore omitted. The documented behavior centers on website defacement and possible DNS manipulation against search‑engine and web‑portal domains in Malaysia and Kenya, carried out by individuals identifying themselves with the aliases Ne0‑h4ck3r, TiGER‑M@TE, F0RTYS3V3N and Tiger M@te. No further affiliations, sponsorships or strategic objectives are disclosed in the available information.

Incidents

Attributed incidents are available to members.

5 incidents
CSIDB