DragonForce Malaysia
Attribution profile
- Type
- Activist
- Location
- Malaysia
- Known incidents
- 1 incident
- Sources
- 1 source
- First seen
- 2022-06-08
- Last seen
- 2022-06-08
- Updated
- 2026-07-30 21:01
- Aliases
- 2 aliases
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
DragonForce Malaysia is a hacktivist group that operates under the alias DragonForce Malaysia and is known to be based in Malaysia. The group first came to public attention in June 2022 when it claimed responsibility for a series of cyberattacks against Indian online assets. It identifies itself through social media handles such as @DragonForceIO on Twitter and a corresponding Telegram channel. The actors describe their actions as a response to perceived anti‑Muslim statements made by an Indian political figure. No further details about the group's internal structure, size, or funding are publicly available.
The group’s reported targets included Indian government websites, private sector entities, educational institutions, and logistics companies, with specific mentions of the Indian Embassy of Israel, Delhi Public School, Nagpur's Institute of Science, S.M. Transport Services, and R.R. Logistics. According to the group's own statements, approximately seventy websites were defaced during the operation that spanned from Wednesday to Sunday in early June 2022. DragonForce Malaysia framed the activity as payback and claimed to have exfiltrated data from Bharathidasan University’s Entrepreneurship, Innovation and Career Hub. They also asserted that they accessed an unnamed Indian government database and posted screenshots containing names, passwords, and email addresses. These claims were not independently verified by Indian authorities at the time of reporting.
The tactics observed in the campaign consisted primarily of website defacement and the alleged exfiltration of data from compromised servers. The group used its Telegram channel to publish recruitment messages for Operation Patuk, inviting Muslim hackers, human‑rights organisations, and activists worldwide to join the effort. Similar calls were posted on Twitter, where the group shared lists of alleged victims and encouraged further participation. No specific malware families, exploit kits, or initial‑access vectors were disclosed in the reporting. The actors relied on public‑facing web applications as the apparent point of entry, leveraging known vulnerabilities to gain access and modify content.
Attribution to DragonForce Malaysia rests solely on the group's own claims and the associated social‑media activity; no government or private‑sector threat‑intelligence report has linked the actors to a state sponsor or a criminal consortium. The June 2022 operation remains the most extensively documented campaign attributed to the group, serving as a representative example of its focus on politically motivated disruption and data‑leak allegations. While the group announced plans to continue recruiting and escalating actions, no subsequent operations have been publicly confirmed in the available sources. The incident occurred just before India’s mandatory six‑hour breach‑notification rule took effect, highlighting the timing of the activity relative to emerging regulatory requirements.
Incidents
Attributed incidents are available to members.
1 incidentSources
Sources available to members: 1 source.