ddos
OpIndia Campaign Continues, Cyber Team Indonesia Hits Kamat.org
> By Clara | Sep 02, 2026 | 7 min read
Coordinated distributed denial of service strikes escalated over the weekend as Cyber Team Indonesia Hits Kamat.org under the long-running #OpIndia banner. The assault caused temporary latency spikes and connection failures across the Indian cultural archive, with third-party check-host telemetry recording sporadic unreachable states before edge filtering stabilized incoming request rates.

The incident adds to a growing list of cases involving regional hacktivist groups targeting Indian digital assets, amid rising geopolitical and social tensions that have repeatedly fueled cross border cyber campaigns across Asia and beyond.
What Happened
According to the screenshot that circulated, the Telegram channel operated by Cyber Team Indonesia published an announcement titled “ATTACK BY CYBER TEAM INDONESIA” that named kamat.org as the target site, included a link to a check report on check-host.net with a permanent reference code, and carried a short message aimed at the party the group considers its target, written in a provocative tone toward India.
The check-host.net report cited as evidence shows the results of a scan performed against kamat.org on Sunday, August 30, 2026, at 10.11 UTC. Out of dozens of check points spread across different countries, most results showed a connection failure of some kind. A number of locations, including Austria, France, Germany, Hong Kong, India, Indonesia, Israel, Italy, Japan, the Netherlands, Slovenia, Spain, Sweden, Turkey, Ukraine, and the United States, recorded a 503 Service Unavailable error, indicating the server was unable to process incoming requests. Meanwhile, other locations such as Brazil, Bulgaria, Canada, Finland, Iran, Moldova, Poland, Portugal, Romania, Russia, Serbia, Singapore, and Vietnam recorded connections that either timed out or were refused entirely.

Every check point that managed to connect to the server pointed to the same IP address, 45.43.3.21, which according to the report sits under a hosting provider identified as M Host. The consistent pattern of failures across multiple regions and continents is in line with a disruption at the server infrastructure level, which can be caused by several technical factors, including a large volume of requests being sent toward the target server at once.
Who Is Affected
The party most directly affected by this incident is the operator and visitors of kamat.org. The site is a digital property based in India, though as of this report there has been no official statement from the site operator regarding the exact cause of the disruption or the recovery steps that have been or will be taken.
In a broader context, this incident is also part of a pattern of attacks under the #OpIndia and #AntiIndia banners that have repeatedly targeted domains and digital services affiliated with or originating from India in recent months. This pattern typically targets organizations with high public visibility as a form of statement from the group behind the campaign, rather than aiming for direct financial gain.
Technical Details
From a technical standpoint, the most notable indicator in this incident is the combination of 503 Service Unavailable errors and connection timed out statuses appearing simultaneously across dozens of different countries within a single check window. This kind of pattern is commonly found in distributed service disruption incidents, where a target server receives a volume of requests far beyond its normal capacity and is unable to respond to legitimate requests from other users.
Response times recorded at the points that did manage to connect were also inconsistent. Some locations logged response times under one second, while others, such as Italy, logged response times of more than twenty seconds before the server eventually returned an error code. This kind of imbalance in response time further supports the indication that the server was under strain at the time the check was performed.
There is currently no further detail on the specific technical vector used in this incident, such as the type of traffic sent, the number of nodes involved, or the total duration of the disruption. CyberAsia will not disclose or detail any operational method that could provide technical guidance for others to replicate a similar incident, in line with the principles of responsible cybersecurity journalism.
The Actor Behind the Action
Cyber Team Indonesia is a fairly well known name within the regional hacktivist ecosystem, frequently appearing in cyber campaigns carrying themes of digital nationalism or cross border solidarity around particular geopolitical issues. The group’s name has surfaced repeatedly in various #OpIndia themed operations over recent months.

One notable element of the post related to the kamat.org incident is a list of acknowledgments to a number of other hacktivist collectives said to have taken part or provided support within the same campaign. That list includes names such as Keymous, Dunia Maya Team, Tegal Cyber Team, Dr4k7h Cyber Team, Nation of Saviors, Garuda Kernel Error System, NoName057, AnonPioneers, DigitalStormSec, Khilafah Hackers, Babayo Eror System, BNCT 1360, DisruptOr, XH4X CYB3R, Karawang Error System, Dark Storm Team, VirusGroup21, RBL Leviathan Ghost, ForcloseSystem, Moroccon Black Cyber Army, Philippines Cyber Eagle Crew, RipperSec, We Are Cyber Force, and K3llLeakers.

The length of this list of collectives suggests that the action against kamat.org did not stand alone, but rather forms part of a wider #OpIndia campaign network involving numerous hacktivist groups across countries, spanning Southeast Asia, the Middle East, and North Africa. This kind of cross group collaboration has become a defining feature of contemporary hacktivism, where collectives with different backgrounds can unite under a single campaign hashtag for a period of time.
Potential Impact
A service disruption on a site can carry a range of consequences depending on its function and the scale of its operations. For sites that serve as information channels or public services, unavailability over a certain period can disrupt user experience, lower public trust in the platform’s reliability, and potentially affect long term digital reputation if similar incidents recur in the future.
Beyond the direct impact on service availability, incidents like this also tend to draw attention within the cybersecurity community as an indicator of ongoing hacktivist campaign activity. For other organizations with a similar profile, particularly those connected to the themes driving the #OpIndia campaign, this incident can serve as an early warning signal to strengthen their infrastructure readiness against the possibility of a similar disruption.
Response and Mitigation
As of this writing, there has been no official statement published by the kamat.org operator regarding the incident, including the exact cause of the disruption, the expected recovery timeline, or the technical steps taken to restore the service to normal.
Generally speaking, when facing a large scale service disruption of this kind, common mitigation steps taken by service providers include temporarily increasing server capacity, rerouting traffic through a content delivery network, applying filtering mechanisms against suspicious traffic, and coordinating with the hosting provider to continuously monitor for anomalous patterns. CyberAsia will update this report if an official statement from the parties involved becomes available, or if there are further developments regarding the recovery status of kamat.org.
Conclusion
The incident affecting kamat.org stands as the latest example of the ongoing #OpIndia campaign pattern, one that involves a wide network of hacktivist collectives across borders. With Cyber Team Indonesia being one of the names most frequently associated with campaigns of this kind, the kamat.org incident underscores that regional hacktivism remains a real threat to digital service availability, particularly for entities that fall within the thematic scope of a given campaign. The situation highlights the importance of solid infrastructure readiness and a well prepared incident response plan for any organization that could become a target amid the constantly evolving dynamics of digital geopolitics.
Disclaimer: CyberAsia is an independent Cyber Threat Intelligence (CTI) research organization. The information provided in this report is derived from public intelligence gathering, dark web monitoring, and threat actor claims. It is published strictly for educational purposes, defensive analysis, and public awareness. CyberAsia does not endorse, verify, or facilitate any cyberattacks or illegal activities.
> INTELLIGENCE_NOTICE
The report above detailing OpIndia Campaign Continues, Cyber Team Indonesia Hits Kamat.org is part of the CyberAsia public archive. For organizations requiring real-time attack telemetry, check-host latency records, and edge firewall mitigation strategies for ddos incidents, please refer to our Secure Drop or contact the research desk.