Dr.MwNs
Attribution profile
- Type
- Activist
- Location
- Sri Lanka
- Known incidents
- 2 incidents
- Sources
- 1 source
- First seen
- 2015-08-05
- Last seen
- 2015-08-05
- Updated
- 2026-07-31 02:29
- Aliases
- 1 alias
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Dr.MwNs is a hacktivist operating under the alias Dr.MwNs, with the actor’s location identified as Sri Lanka in available reporting. The individual first came to public attention through the defacement of Sri Lanka’s Prime Minister’s Office website in August 2015, where a “Hacked by Dr.MwNs” message was displayed alongside an Islamic devotional song. The actor’s online presence includes a Twitter handle used to claim responsibility for intrusions and to demonstrate proficiency in Arabic, as noted in the coverage of the incident.
Targeting appears focused on governmental and telecommunications entities, with the actor compromising the official website of a national leader, breaching the servers of Bhutan Telecom, and allegedly accessing the associated Google Bhutan domain. Additionally, the actor claims to have defaced hundreds of Turkish websites, indicating a pattern of hitting state‑related or critical infrastructure sites across multiple regions. The stated strategic objective is hacktivist in nature, driven by the #ForSyria campaign, and the actions are characterized by disruption through website defacement and the insertion of audio content rather than financial gain or espionage.
No explicit affiliation with a state sponsor, criminal consortium, or other organized group has been established in the sources; attribution remains limited to the individual alias. Notable operations cited include the Sri Lankan Prime Minister’s Office defacement, the intrusion into Bhutan Telecom that facilitated access to Google Bhutan’s domain, and the widespread defacement of Turkish web properties. These examples illustrate the actor’s recurrent use of web‑defacement tactics, reliance on social media for claim‑making, and the exploitation of compromised telecommunications infrastructure to reach further domains. The profile is confined to these confirmed details, with no extrapolation beyond the provided information.
Incidents
Attributed incidents are available to members.
2 incidentsSources
Sources available to members: 1 source.