You are exploring the Free preview. To unlock full read-only access to all public profiles and in-app notifications, create a free research account. For analyst / premium plans capabilities (editing, advanced tabs, exports), please contact us

Threat Actor Characterization

You’re viewing the read-only version. Sign in for analyst tools (editors, promote draft, file/relations management, etc.)
Nation Of Saviors

Nation Of Saviors

ID: cf294afa67a2b6b7f0b8f1a741db720e
Hacktivist Group Hacktivism
Threat types: Hacktivism, Intrusion, Defacement, DDoS, Pro-Palestine, Pro-Iran
Unknown BGD, IND, ISR, KWT, SAU, GBR, USA
Updated: 2026-04-12
Created: 2026-01-20
Progress: 95% Completeness: 96% Freshness: 100%
Operation zone: Bangladesh, India, Israel, Kuwait, Saudi Arabia, United Kingdom, United States
Aliases Limited alias preview
NationOfsaviors NOS NO************** NO******************
NO******** NO****************
Showing 2 of 6 aliases in free preview.
Actor Network Graph
Open Network Graph
Read-only preview for anonymous visitors. Sign in with a free Research account for full workspace.
MITRE ATT&CK®

Nation Of Saviors is a coalition-aligned hacktivist collective publicly associated with pro-Palestinian and pro-Pakistan narratives. Open reporting ties it most strongly to DDoS-led disruptive campaigns against Indian state-linked targets and, later, anti-Israel and Gulf-related conflict activity.


Technique Technique name Tactics Evidence
T1498 Network Denial of Service TA0040
  • 2025-05-09 — Cyble reported that Nation Of Saviors launched two concentrated waves of DDoS attacks targeting India’s state infrastructure, including defense, law enforcement, education, and e-governance. · ref
  • 2025-06-19 — SOCRadar recorded the group’s claim that it took down Israel’s Alon Group website via DDoS. · ref
  • 2026-03-02 — Radware / downstream reporting described a Nation Of Saviors claim promising to hold a DDoS attack against Israel’s Alon Group for more than 20 hours. · ref
T1491.001 Internal Defacement TA0040
  • 2025-05-15 — INFERENCE (confidence: medium): Public reporting on the broader India-focused campaign describes loose hacktivist collectives, including Nation Of Saviors, as espousing defacements alongside DDoS. This supports conservative mapping to website impact / defacement behavior. · ref
  • 2025-00-00 — INFERENCE (confidence: medium): Profile-style OSINT describes Nation Of Saviors as combining anti-India operations with defacement and DDoS activity. · ref
T1595 Active Scanning TA0043
  • 2026-03-09 — INFERENCE (confidence: medium): The actor’s recurring focus on symbolic public web targets implies routine target discovery and exposed-service identification before campaigns. · ref
  • 2025-05-08 — INFERENCE (confidence: medium): Repeated targeting of public institutions and exposed services is consistent with active reconnaissance for visible internet-facing assets. · ref
T1589 Gather Victim Identity Information TA0043
  • 2025-05-12 — INFERENCE (confidence: medium): Sustained India-related posting and symbolic target focus suggest collection of target identity and contextual information for narrative-driven operations. · ref
  • 2025-00-00 — INFERENCE (confidence: medium): OSINT profiling describes the group as targeting Indian public and private sector entities and named institutions such as the Indian Air Force, implying purposeful target selection rather than random disruption. · ref
T1020 Automated Exfiltration TA0010
  • 2026-03-09 — INFERENCE (confidence: low-medium): SOCRadar’s dashboard attributes a 21GB exfiltration claim against Saudi engineering firm Baran Company to Nation Of Saviors, but independent verification remains limited. · ref
Strategic Intelligence
Limited preview
Last updated: 2026-04-12T15:03:10+00:00
Nation Of Saviors — pro-Palestinian / pro-Pakistan hacktivist collective

Classification: Unclassified / Open Source Intelligence (OSINT) — TLP:WHITE

Category: Hacktivism / Ideologically aligned disruptive operations — Origin: likely South Asian nexus with strong anti-India and pro-Palestinian alignment; precise home base unconfirmed

Author: iQBlacl CTI Team


Executive Summary

Nation Of Saviors appears to be a relatively recent hacktivist collective that became visibly active during 2024 and accelerated through 2025 into early 2026. Public reporting consistently places the group inside a broader pro-Palestinian and pro-Pakistan online militant ecosystem, with recurring anti-India targeting and later participation in anti-Israel and Gulf-focused campaigns. The group’s public behavior is heavily claim-driven and shaped by Telegram-native amplification.


The most consistently supported activity pattern is disruptive rather than stealthy. Public reporting links the group primarily to DDoS claims, periodic website defacement narratives, and a smaller number of data-leak or doxxing claims. The available record does not currently support treating Nation Of Saviors as a high-maturity intrusion actor with a well-documented proprietary malware stack. It is better modeled as a coalition-era hacktivist node that exploits political momentum, alliance branding, and symbolic target selection.

Full strategic intelligence is available in Analyst and Premium plans.
Executive Analyst Brief for CISO
Saved Limited preview

Executive Analyst Brief for CISO — Nation Of Saviors

Classification: Unclassified / Open Source Intelligence (OSINT) — TLP:WHITE

Upgrade to access the full executive brief.
Tip: Hover the section title to learn what’s included in Analyst / Premium plans.
Executive brief now
Saved successfully.
Hunting Playbook
Saved Limited preview

Hunting Playbook — Nation Of Saviors


Upgrade to access the full hunting playbook.
Tip: Hover the section title to learn what’s included in Analyst / Premium plans.
Hunting Playbook now
Saved successfully.
IOC Appendix
Saved Limited preview
Last updated: 2026-04-12T15:02:14+00:00

IOC Appendix — Nation Of Saviors

Classification: Unclassified / Open Source Intelligence (OSINT) — TLP:WHITE

More IOC context for Research. Full appendix for Analyst and Premium plans.
IOC Appendix now
Saved successfully.
OSINT Library
Saved Limited preview
Last saved: 2026-04-12T15:02:30+00:00

OSINT Library — Nation Of Saviors


2025-05-08 — Radware — “Escalating Hacktivist Attacks Amidst India-Pakistan Tensions”

Full OSINT references available for Research / Analyst.
OSINT Library now
Saved successfully.
Social Medial & Communication
SOCMINT integrated: 0/18

Address Verification SOCMINT
x.com/Nat************ Restricted Not integrated
Address Verification SOCMINT
t.me/+e4************** Restricted Not integrated
t.me/+XE************** Restricted Not integrated
t.me/nos************** Restricted Not integrated
t.me/+9u************** Restricted Not integrated
t.me/+-0************** Restricted Not integrated
t.me/+Sh************** Restricted Not integrated
t.me/+UE************** Restricted Not integrated
t.me/dat************* Restricted Not integrated
t.me/nat********************* Restricted Not integrated
t.me/Nat**************** Restricted Not integrated
t.me/nos***** Restricted Not integrated
t.me/+X0************** Restricted Not integrated
t.me/+q-************** Restricted Not integrated
t.me/+tI************** Restricted Not integrated
t.me/+-S************** Restricted Not integrated
t.me/+S5************** Restricted Not integrated
Address Verification SOCMINT
dsc.gg/nos******* Restricted Not integrated
Notes: preview mode hides sensitive social/contact details.
Reference Images/Associated Evidence Limited

Showing 1–12 of 28 images
Alliance with 7thDay Free Preview
Alliance with 7thDay
Propaganda Free Preview
Propaganda
Propaganda Free Preview
Propaganda
Alliance with Black Hat Zombie Free Preview
Alliance with Black Hat Zombie
Propaganda Free Preview
Propaganda
Propaganda Free Preview
Propaganda
Alliance with BD Anonymous Team Free Preview
Alliance with BD Anonymous Team
Alliance with Team Insane Pakistan Free Preview
Alliance with Team Insane Pakistan
Alliance with Cyber Team Indonesia Free Preview
Alliance with Cyber Team Indonesia
Statement / Termination of alliance with Wolf Cyber Army Free Preview
Statement / Termination of alliance with Wolf Cyber Army
Alliance with Red Wolf Cyber Team Free Preview
Alliance with Red Wolf Cyber Team
Propaganda Free Preview
Propaganda
Propaganda Free Preview
Propaganda
Alliance with Team DB Dark Force Free Preview
Alliance with Team DB Dark Force
Propaganda Free Preview
Propaganda
Propaganda Free Preview
Propaganda
Alliance with Garuda Eror System (aka GHOSTNET-X) Free Preview
Alliance with Garuda Eror System (aka GHOSTNET-X)
Hacked website Free Preview
Hacked website
Propaganda Free Preview
Propaganda
Propaganda Free Preview
Propaganda
Alliance with CIR Free Preview
Alliance with CIR
Propaganda Free Preview
Propaganda
X Account Free Preview
X Account
Propaganda Free Preview
Propaganda
Propaganda Free Preview
Propaganda
Alliance with RipperSec Team Free Preview
Alliance with RipperSec Team
Alliance with V For Vendetta Cyber Team Free Preview
Alliance with V For Vendetta Cyber Team
Logo Free Preview
Logo
Showing 4 of 28 images in preview mode. Additional evidence is restricted for Analyst and Premium plans.