Shell Haxor
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor known as the Pakistani Haxors Crew, also referenced as the Pakistan Haxors Crew, is a self‑identified hacktivist group that originates from Pakistan and frames its actions around political messages such as “Free Kashmir, Free Syria, Stop Spying On Us, Stop Killing Muslims.” This stated motivation appears in the defacement messages they leave on compromised websites and frames their activity as a form of protest rather than financially driven crime. The group presents itself as a collective of hackers rather than a state‑sponsored unit, and no public source has explicitly linked them to a governmental intelligence or military service.
Their observed targeting pattern focuses on government and public‑service websites in South Asia, with a clear emphasis on Indian domains and occasional incursions into Nepalese infrastructure. They have claimed responsibility for defacing the West Bengal Public Health Engineering Department’s website (wbphed.gov.in) and the Nepal Community Irrigation Program portal (cip.gov.np), and they have asserted that they have targeted numerous Indian websites over an extended period. The sectors they appear to favor include civil engineering, public health, and irrigation services, reflecting a focus on civilian administrative sites rather than military or financial institutions. No public reporting indicates that they have pursued commercial entities, critical energy infrastructure, or espionage‑oriented targets.
The group’s documented tactics consist primarily of website defacement, wherein they upload a message‑laden page to the “applications” section of the compromised site, as seen in the West Bengal and Nepal incidents. No specific malware families, exploit kits, or initial‑access vectors such as phishing emails or supply‑chain compromises have been disclosed in the available sources, so the only confirmed technique is the defacement of web front‑ends to broadcast their political slogans. Attribution to a Pakistani hacktivist milieu is explicitly stated in the reporting, but no definitive evidence ties the crew to a state sponsor or a broader criminal consortium. Their most notable public operations remain the defacement of the West Bengal Public Health Engineering Department site and the Nepal Community Irrigation Program site, alongside a broader claim of repeated incursions against Indian government‑linked web properties.
Incidents
Attributed incidents are available to members.
1 incident