“Choices Have Consequences”: Inside The Night Hunters’ Retaliatory Cyber Campaign

The Night Hunters present themselves as more than a typical hacktivist group. Emerging around 2022 and identifying strongly with India, the group has built its online identity around a simple idea: retaliation. Its messaging consistently mixes cyber activity with nationalist language, particularly the recurring use of “Jai Hind” and statements portraying attacks as a response to hostile activity against India. The group is primarily associated with an anti-Pakistan stance, while its public messaging has also shown support for Israel and hostility toward actors it considers opposed to India.

What makes the Night Hunters worth examining is the gap between that straightforward ideological messaging and the range of activity attributed to the group. Their operations have involved claimed breaches, database and document leaks, website compromises and attacks against industrial control systems, while their public channels have been used to publish screenshots, videos and other material presented as proof of access. Their targeting has not remained limited to one country either, with activity linked to Pakistan as well as infrastructure in countries such as Indonesia and Malaysia.

By August 2026, however, the group’s Telegram presence had become fragmented. Several of the channels referenced in its own network were no longer accessible, while replacement and redirection channels continued to circulate its material and connect followers to other hacktivist communities. This raised a more interesting question than simply what the Night Hunters had claimed to breach: how much of the group’s wider online network could still be traced after parts of its original infrastructure disappeared?

The First Signs of Activity

The investigation started with StealthMole's Defacement Alert module. A search for The Night Hunters returned seven victims, giving us the first concrete indication of the group's activity rather than relying on its own descriptions of who it was or what it had done.

The results covered activity between May 2024 and January 2025 and showed that the group had been associated with defacements across several countries. The visible results included targets in Pakistan, Bangladesh, Colombia and the United States.

One example from the results was a defaced Bangladeshi website:

  • http://ha***********school.edu.bd/

What makes this useful is that the StealthMole result gives us something we can actually follow, a specific URL, a named actor and a detection timestamp. Other entries in the same result set pointed to targets in the United States, Colombia, Pakistan and Bangladesh, showing that the group's claimed activity had already crossed borders well before the August 2026 messaging that became the focus of the investigation.

What stood out at this stage was not simply the number of websites. The alerts showed that The Night Hunters was already appearing as a named actor across separate incidents and targets, giving us a starting point from which to investigate the group beyond individual defacement events. But the alerts could only tell us where activity had been observed. They did not explain how the group communicated, how operations were announced, or how different incidents might fit together.

That meant the next step was to follow the group itself.

Following the Telegram Trail

After the defacement search, the next step was to search “The Night Hunters” in StealthMole's Telegram Tracker. This opened up a much broader trail. Rather than finding one clean, permanent channel, the investigation uncovered a collection of channels, groups, redirects and historical references. Some were still available; others had become inaccessible. That fragmentation turned out to be useful in its own way, because surviving references allowed us to follow where the group's audience and communications had moved.

The Telegram identifiers encountered during the investigation included:

  • @op********y
  • @n********op
  • @hack******ic
  • night*******og
  • Night********ic

There was also an important active channel that needs to be distinguished from the expired ones:

  • Telegram: https://t.me/+eS***********U1
  • X account: https://x.com/Th******H

This channel was still active when captured, so it should not be treated as an archived or offline source. At the same time, several other links encountered during the investigation were no longer accessible:

  • https://t.me/+DCO_JVFORXI5ZGQ1
  • https://t.me/+c9c8pNElK21iMWNl

This is where StealthMole's historical visibility becomes particularly useful. Even when individual Telegram destinations were no longer available, references to them remained visible elsewhere.

One example was Night Hunters Main Channel Redirection, where a pinned message directed users toward the group's main channel and chat group. The same material contained another Telegram invite:

  • https://t.me/+vb***********Q1

The messages themselves added another layer to the investigation. Among the surviving material were short operational statements such as:

  • “OP_PRALAY COMING”
  • “Be Ready For Tomorrow”
  • “United We Stand Divided We Fall”

The August 4–15 messaging was particularly notable because the posts moved beyond general slogans and referred to targets and planned activity. The timing also coincided with the group's broader Independence Day messaging, which became more apparent once its other social-media accounts were examined.

The active Night Hunters channel also contained posts discussing alleged compromises of government and infrastructure systems. One visible post referred to Pakistan Metrological Department access credentials, while another discussed .gov.bd infrastructure and DDoS activity.

The Telegram material therefore gave us something the defacement alerts could not: a view into how the group communicated before, during and after its claimed operations.

And because parts of that Telegram presence had already disappeared, the investigation became less about finding a single channel and more about piecing together the surviving trail.

Network Hidden in Plain Sight

The Telegram trail eventually led back to the group's social-media footprint.

The Instagram account identified during the investigation was:

  • Instagram: the*********5
  • Followers shown: 375
  • Following: 9
  • Display name: THE NIGHT HUNTERS 🇮🇳
  • Bio included: “Hunting in the shadows of cyberspace”, “Intelligence • Research • Operations”, and “No noise. No limits”
  • Telegram link in the profile: https://t.me/+DCO_JVFORXI5ZGQ1

The account used the same distinctive green Night Hunters emblem seen across the Telegram material.

The X account provided another direct point of comparison:

  • X: @The*******H
  • Display name: The Night Hunters
  • 18 posts shown in the captured profile
  • 67 followers
  • Telegram link displayed on the profile: https://t.me/+c9c8pNElK21iMWNl

The X profile described itself simply as: “If wanna know us Google us”

Together, the Instagram and X accounts provided an important connection between the group's public-facing identity and the Telegram ecosystem. The Telegram channels were not operating in complete isolation; the same branding, names and links were being used to move users between platforms.

The investigation also encountered a number of other Telegram communities and identities through these links and forwarded material. One example was a channel titled Night Hunters Main Channel Redirection, while another a group profile for FIaxB8M, using the handle @FlA**********nt, with 664 members.

The Night Hunters also listed supposed “allied teams” and “comrades.” The message referenced:

  • 7 Proxies
  • Team UCC
  • SoloAPT
  • Crack Codes
  • GodFather
  • SoLVEIG
  • Teo Miro
  • Mr Anonymous
  • Cryptic@1337
  • ItachiH4X
  • BlurryFace98
  • Odiyan911
  • Krishna404
  • IndixFalcon
  • Mynk
  • King Renger
  • Jeager
  • Red Eagles
  • Kochimona

The important point is that these names were presented by the Night Hunters themselves as allies or comrades. That is evidence of a claimed relationship, not independent confirmation that every named account or group actually collaborated with them.

The same distinction matters when looking at forwarded content. For example, one Night Hunters-related Telegram screenshot contained material forwarded from “TeAm UcC OpErAtIoNs”, alongside logos of several hacktivist groups. Again, this establishes that the material circulated within the ecosystem; it does not by itself establish operational control or direct collaboration.

This distinction becomes increasingly important as we move from the group's communications to its actual attack claims.

From Retaliation to Action

The Telegram material contained a number of claims involving government institutions, databases and industrial infrastructure. These claims provide the clearest picture of what The Night Hunters wanted its audience to believe it had achieved.

One of the most concrete examples concerned Pakistan Railways. A post presented SQL database files and identified the target as Pakistan Railways.

The files shown were:

  • ncs_railway_uat_b_u.sql
  • ncs_railway2.sql

The accompanying text stated that the material included land assets, user accounts, administrative modules and internal workflows.

Another post claimed a breach of a Pakistan Government SQL Server and described the material as office documents. Additional material in the investigation referenced the Pakistan Military Accounts Department, including a claimed 88-page PDF containing stolen data.

A separate post presented an alleged AJ&K Official Portal COVID-19 database leak. The post claimed that the database contained patient-related information and displayed server information alongside the claim.

The group's activity was not limited to conventional databases and websites.

One post claimed access to the Water Consumption Server (PLC) of the Dhaka Water Supply and Sewerage Authority (DWASA). The accompanying screenshot showed a water-management interface containing pump and system readings.

Another post claimed access to Tenaga Nasional Berhad (TNB) infrastructure in Malaysia. The screenshot showed an industrial control interface, while the accompanying statement claimed that the group had gained access to PLC infrastructure associated with the electricity provider.

The group framed the Malaysia operation explicitly as retaliation. Its message stated that the action was carried out in response to attacks by Malaysian actors targeting Indian servers, websites and networks, while insisting that the purpose was to send a warning rather than cause destruction.

The investigation also identified a claimed operation against an Indonesian solar-energy monitoring system, accompanied by a proof-of-concept video.

These incidents show why the Night Hunters' activity cannot be understood purely through its website defacements. Its own posts describe a much broader range of activity, extending from websites and SQL databases to government systems and industrial-control environments.

The important qualification is that these are not all independently verified intrusions. In several cases, the strongest evidence available to us is the group's own publication of screenshots, files or videos claiming successful access.

The Message Behind the Breaches

The technical claims make more sense when read alongside the group's messaging.

The Night Hunters repeatedly presents its activity through an explicitly Indian nationalist lens. “Jai Hind” appears across its Telegram material and social-media branding, while its posts frame attacks as responses to what the group describes as hostile activity against India.

The strongest example came around India's Independence Day.

In one message, the group stated:

  • “On India's Independence Day, we made our move.”

The post then described the claimed TNB operation and linked it directly to what the group portrayed as repeated attacks by Malaysian actors against Indian digital infrastructure.

A similar retaliatory framing appeared in the DWASA claim, where the group connected its alleged access to Bangladeshi cyber activity targeting Indian infrastructure.

This gives the group a consistent narrative: it does not present its attacks as random cybercrime. It presents them as retaliation and national defence.

That narrative is also visible in the group's broader language around Pakistan, Bangladesh and other countries it perceives as adversaries. The messaging repeatedly uses terms such as “anti-India groups”, while slogans such as “Jai Hind” and “Jai Bharat” reinforce the nationalist identity.

The Independence Day material also helps explain the significance of messages such as “OP_PRALAY COMING” and “Be Ready For Tomorrow.” Within the broader sequence of posts, these statements read less like generic promotional messages and more like attempts to build anticipation around upcoming activity.

There is therefore a clear relationship between the group's ideological narrative and its operational messaging: the political message provides the justification, while the breach claims are presented as proof that the group is acting on it.

How the Hunters Operate

Looking across the incidents rather than treating them individually reveals a fairly consistent pattern. The Night Hunters appear to use several different attack types rather than relying on a single technique. The activity documented in the investigation includes:

  • Website defacement
  • SQL/database compromise
  • Data and document leaks
  • Government-system breaches
  • Industrial-control/PLC access claims
  • Proof-of-concept videos
  • Public disclosure of alleged stolen information

The background intelligence associated with the group also identifies the use of tools such as SQLmap, Nikto, Wpseku and Sublist3r, alongside Weevely, GoldenEye, Hulk and Xerxes.

The significance is not that the group possesses an unusually exotic toolkit. The more interesting pattern is how it combines relatively recognizable offensive tools with public-facing hacktivist operations.

A claimed compromise is not simply kept private. It is turned into content: screenshots are published, database files are displayed, videos are released, targets are named, and political messaging is attached to the activity.

That creates a cycle:

target → claimed access → evidence or PoC → public announcement → political/retaliatory narrative.

The Telegram ecosystem appears to be an important part of that cycle. It provides the space for announcements, redirects, audience building and dissemination of claimed results, while Instagram and X extend the group's public identity beyond Telegram.

The group's apparent willingness to move between website defacement, database compromise and claimed ICS access also means that its activity should not be assessed solely through conventional hacktivist defacement metrics.

Conclusion

What began as seven StealthMole defacement alerts developed into a much broader picture of The Night Hunters.

The investigation moved from compromised websites to Telegram channels, from Telegram to Instagram and X, and from surviving channels to historical references left behind by parts of the group's disappearing infrastructure. That trail exposed more than a collection of attack claims. It showed how the group builds an identity, announces operations, mobilizes an audience and frames cyber activity as retaliation.

The group's own material points to a wide target set, including Pakistan, Bangladesh, Indonesia and Malaysia, and to an equally broad range of activity spanning website defacement, database and document leaks and claimed access to industrial-control systems.

At the same time, the investigation shows why hacktivist attribution needs to be handled carefully. Some relationships remain claims, some channels have disappeared, and several of the most serious operations are supported primarily by material published by the actor itself.

The strongest finding is therefore not any single breach claim. It is the consistency of the wider trail: the same identity, branding, platforms, messaging and operational narrative appearing across different sources and different periods of activity.

And that is what makes The Night Hunters worth following. The channel may change, a Telegram invite may expire, or an individual post may disappear but the wider trail can remain.

Editorial Note

Dark-web and cyber investigations rarely produce absolute attribution, and hacktivist groups in particular can blur the line between genuine activity, collaboration and public claims of responsibility. The Night Hunters case is a good example of why individual posts should not be viewed in isolation. Here, StealthMole's ability to connect current findings with historical Telegram activity, defacement records and cross-platform traces helped preserve a fragmented picture even when parts of the group's online presence were no longer accessible.

To access the unmasked report or full details, please reach out to us separately.

Contact us: support@stealthmole.com



Labels: ,

Learn more about StealthMole

Talk to our team of experts today to learn how you can manage your dark web exposure.
Request demo More Reports

Share this report