Evil Markhors
Evil Markhor, commonly branded Evil Markhors, is a Pakistani hacktivist and cybersecurity collective that publicly identifies itself as founded by Anony and Fusion Security. Unit 42 describes the actor as pro-Iranian and typically focused on credential harvesting and identifying unpatched critical systems, and records an actor claim against an Israeli bank website. The group's own site additionally claims 2026 access to Indian and Afghan media/government-related targets and publishes a roster and alliance information. These self-reported operations require independent validation.
Evil Markhor combines a polished public cybersecurity brand with hacktivist operational claims, creating an intentional overlap between 'ethical' security positioning and adversarial activity.
INFERENCE (confidence: high): vulnerability discovery and credential acquisition are likely the group's most strategically useful capabilities because both can support access without requiring custom malware.
INFERENCE (confidence: medium-high): the actor's current Pakistan identity is high confidence, while pro-Iran alignment is better treated as campaign alignment than proof of external control.
INFERENCE (confidence: high): claimed data leaks require provenance analysis because at least one high-profile election-data claim has been assessed as likely aggregated or scraped material.
ATT&CK
MITRE ATT&CK
Research