CSIDB logo
Threat actor

Dr.MwNs

Attribution profile

Type
Activist
Location
Sri Lanka
Known incidents
2 incidents
Sources
1 source
First seen
2015-08-05
Last seen
2015-08-05
Updated
2026-07-31 02:29
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Dr.MwNs is a hacktivist operating under the alias Dr.MwNs, with the actor’s location identified as Sri Lanka in available reporting. The individual first came to public attention through the defacement of Sri Lanka’s Prime Minister’s Office website in August 2015, where a “Hacked by Dr.MwNs” message was displayed alongside an Islamic devotional song. The actor’s online presence includes a Twitter handle used to claim responsibility for intrusions and to demonstrate proficiency in Arabic, as noted in the coverage of the incident.

Targeting appears focused on governmental and telecommunications entities, with the actor compromising the official website of a national leader, breaching the servers of Bhutan Telecom, and allegedly accessing the associated Google Bhutan domain. Additionally, the actor claims to have defaced hundreds of Turkish websites, indicating a pattern of hitting state‑related or critical infrastructure sites across multiple regions. The stated strategic objective is hacktivist in nature, driven by the #ForSyria campaign, and the actions are characterized by disruption through website defacement and the insertion of audio content rather than financial gain or espionage.

No explicit affiliation with a state sponsor, criminal consortium, or other organized group has been established in the sources; attribution remains limited to the individual alias. Notable operations cited include the Sri Lankan Prime Minister’s Office defacement, the intrusion into Bhutan Telecom that facilitated access to Google Bhutan’s domain, and the widespread defacement of Turkish web properties. These examples illustrate the actor’s recurrent use of web‑defacement tactics, reliance on social media for claim‑making, and the exploitation of compromised telecommunications infrastructure to reach further domains. The profile is confined to these confirmed details, with no extrapolation beyond the provided information.

Incidents

Attributed incidents are available to members.

2 incidents

Sources

Sources available to members: 1 source.

CSIDB