Full Report
Group-IB reveals the identity of alleged members of the Islamic hacker group United Islamic Cyber Force
Analysis Summary
# Threat Actor: United Islamic Cyber Force (UICF)
## Attribution & Identity
* **Actor Identification:** UICF is described as an umbrella collective of Islamic hacktivists.
* **Alleged Members/Leadership:** Group-IB identified key members using the aliases **"KromSec"** (identified as a 19-year-old Indian national) and **"Lrd_Krom"**.
* **Associated Groups:** UICF acts as a coalition that has included or collaborated with:
* **KromSec** (a specific cell/sub-group)
* **Pan-Islamist Cyber Force**
* **Various smaller Islamic hacker groups** from regions including Indonesia, Pakistan, and North Africa.
## Activity Summary
* **Recent Campaigns:** The group has been highly active in conducting large-scale, automated "defacement" and DDoS campaigns targeting organizations perceived as anti-Islamic or supporting specific geopolitical interests.
* **Historical Activity:** While many members are young (students/schoolchildren), they have transitioned from uncoordinated attacks to organized campaigns under the UICF banner.
* **Publicity Stunts:** The group frequently shares "proof" of their hacks on social media and Telegram to garner media attention.
## Tactics, Techniques & Procedures
* **Website Defacement:** Replacing website homepages with political or religious messages.
* **DDoS (Distributed Denial of Service):** Overwhelming web resources to cause downtime.
* **Mass Exploitation:** Using automated scanners to find and exploit known vulnerabilities in common CMS (Content Management Systems) like WordPress and Joomla.
* **Data Leaks:** Exfiltrating and publicly releasing sensitive information from poorly secured databases.
* **Social Engineering:** Using social platforms for recruitment and propaganda.
**MITRE ATT&CK IDs:**
* **T1498:** Network Denial of Service
* **T1491:** Defacement
* **T1190:** Exploit Public-Facing Application
* **T1567:** Exfiltration Over Web Service
## Targeting
* **Sectors:** Government, Healthcare, Education, and Critical Infrastructure (though primarily limited to public-facing websites).
* **Geography:** Global targeting, with a focus on India, Israel, the United States, and various European nations.
* **Victims:** Small-to-medium-sized organizations with weak web security, as well as high-profile government portals in targeted countries.
## Tools & Infrastructure
* **Malware & Tools:**
* Custom and leaked DDoS scripts.
* Automated vulnerability scanners.
* SQL injection tools for database exfiltration.
* **Infrastructure:**
* **Communication:** Telegram channels and Discord for coordination.
* **Social Media:** Twitter (X) and Facebook for publicity.
* **Defanged Assets:** Examples include `hXXps[:]//uicf[.]org` (historical/defaced sites) and various Telegram bot IDs used for automated reporting.
## Implications
UICF represents a "low-to-medium" technical threat that compensates for a lack of sophistication with high volume and automation. While their current focus is on publicity and nuisance-level attacks (defacements/DDoS), their recruitment of young, impressionable individuals poses a long-term risk. There is a strategic concern that these actors could transition from symbolic "hacktivism" to more destructive attacks on infrastructure if they obtain more powerful digital weaponry or state sponsorship.
## Mitigations
* **Web Resource Audit:** Regularly conduct penetration testing and vulnerability assessments on all public-facing assets (specifically targeting CMS vulnerabilities).
* **DDoS Protection:** Implement robust traffic filtration services from established providers to mitigate high-volume denial-of-service attempts.
* **Web Application Firewall (WAF):** Deploy a next-gen WAF to block SQL injection and cross-site scripting (XSS) attempts used by the group to gain unauthorized access.
* **Threat Intelligence:** Monitor hacktivist communication channels (Telegram/Dark Web) to anticipate upcoming "ops" or campaigns targeting specific sectors.
* **Data Protection:** Ensure backup copies are protected and offline to prevent data loss during ransom or leak scenarios.