Blacksmith Hackers Team
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor known as the Blacksmith Hackers Team also operates under the alias Blacksmith Hacker’s team. The group is based in Bangladesh, as indicated in open‑source reporting. They have been observed conducting cyber operations against government entities in the region. Their activity appears to be part of a broader tit‑for‑tat exchange between Bangladeshi and Pakistani hacker communities. The actor first gained public attention for a series of website defacements that targeted Pakistani state domains.
Their primary targets have been Pakistani government websites, including the official presidential portal and numerous affiliated administrative sites. This focus indicates a sectoral emphasis on public‑sector infrastructure rather than commercial or financial networks. The stated objective of the attacks is to retaliate against prior cyber incidents attributed to Pakistani hackers, aiming to disrupt the availability of the targeted online services. To achieve this, the actors compromised a central proxy server used by the Pakistani government to manage multiple web domains. Once inside the proxy environment they deployed defacement pages, posted explanatory messages and included screenshots of earlier Pakistani hacker activity, without referencing any specific malware families or custom tooling.
Public sources do not link the Blacksmith Hackers Team to any state sponsor or formal criminal consortium, describing them instead as an independent hacker collective. The most documented operation occurred in mid‑July 2015 when the group defaced the President of Pakistan’s website and approximately seventy‑two other government sites. The defacement remained visible for over two days, demonstrating a sustained disruption effect. Prior to this campaign the actors claimed to have repeatedly targeted both Pakistani and Bangladeshi government domains, indicating a pattern of reciprocal attacks. These actions illustrate the actor’s reliance on server‑level access and website alteration as their principal method of exerting pressure.
Incidents
Attributed incidents are available to members.
1 incident