syndicate
Pakistani Hackers Target Press Freedom: Akatsuki Cyber Team & JundAlNabi Threaten CyberAsia
> By Haider | Aug 28, 2026 | 9 min read
When threat intelligence reporting hits a nerve in the hacktivist underground, the backlash rarely arrives in court. Instead, it plays out in Telegram channels through broken grammar, fake white-hat outreach, botnet floods, and outright blackmail. That is exactly what happened when CyberAsia began tracking the Akatsuki Cyber Team and their Pakistani ally JundAlNabi.
What started as a routine community advisory warning that JundAlNabi was compromised quickly escalated into a full-blown intimidation campaign. Over forty-eight hours, the Akatsuki Cyber Team and their regional network cycled through every trick in the amateur playbook: threatening our editors in public chat rooms, attempting to doctor private conversations, launching an automated 71,000-request port scan from Pakistani internet blocks, hammering our web servers with a non-stop two-hour DDoS flood, and finally threatening to hit our newsroom with ransomware.
Here is the full investigative breakdown of how the confrontation unfolded, how the operators exposed their own identities, and why the Akatsuki Cyber Team intimidation campaign failed to silence independent cybersecurity reporting.
> INCIDENT_TIMELINE // 48_HOURS_OF_ESCALATION
- Hour 01: The Spark. Underground channels circulate a Red Defense Notice calling JundAlNabi suspected state moles. JundAlNabi and the Akatsuki Cyber Team issue heated denials.
- Hour 06: The Meltdown. JundAlNabi leader Bbq Heit enters CyberAsia’s group chat hurling insults over broken English, triggering a live public grammar lesson.
- Hour 14: The Staged White-Hat Trap. Akatsuki Cyber Team owner Xanark poses as a friendly researcher offering bug fixes in exchange for clearing his friend’s name, then doctors chat screenshots when refused.
- Hour 22: Traffic Spike & DDoS. 71,520 automated requests originate from Pakistan PTCL networks, followed immediately by a 2-hour Layer 7 stresser attack that forces edge rate limits into action.
- Hour 36: Insider Leaks Location. A disillusioned community contact leaks unredacted phone records linking JundAlNabi’s admin directly to Pakistani mobile carriers matching the attack IP block.
- Hour 42: Alliance Splits. Partner hacktivist groups (Nation of Saviors, RipperSec) call out the Akatsuki Cyber Team leadership for doctoring chat logs and stand with CyberAsia.
- Hour 48: The Ransomware Bluff. Former Akatsuki Cyber Team chief billa_Uchiha steps in with an ultimatum: shut down reporting or face ransomware attacks on all newsroom machines.
> TABLE_OF_CONTENTS [toggle]
- > 1. How It Began: A Community Spy Warning and Stamped Denials
- > 2. The Meltdown: When Broken English Turned into a Public Grammar Lesson
- > 3. The White-Hat Trap: Xanark’s Failed Chat Manipulation Scheme
- > 4. Under The Hood: 71,000 Automated Hits and a 2-Hour DDoS Surge
- > 5. The Leak: Insider Intelligence Unmasks the JundAlNabi Operator
- > 6. The Ransomware Bluff: Former Akatsuki Cyber Team Chief Delivers Ultimatum
- > 7. Practical Defense: How Independent Newsrooms Survive Cyber Intimidation
- > Frequently Asked Questions
1. How It Began: A Community Spy Warning and Stamped Denials
The feud started inside the regional hacktivist network. A widely shared community warning, titled the “Red Defense Notice,” began circulating across regional channels. It warned that Pakistani group JundAlNabi PK was collecting reconnaissance data on peer hacktivists, leaking sensitive domestic healthcare and student data, and acting as an intelligence mole.
Panicked by the leak, JundAlNabi published an urgent bilingual statement citing Quranic verses (Surah Al-Hujurat and Surah Al-Isra), protesting their innocence and claiming that any domestic files they had touched were deleted immediately.

Their closest ally stepped in right behind them. The Akatsuki Cyber Team republished the warning banner with an oversized red “REJECTED” stamp, turning an internal peer dispute into a formal declaration of cyber war: “The Al JundAlNabi team is an ally to us and to other hackers… This is personal: anyone who dares to go after my comrades will face war. No one can stop us, and no one has ever beaten the Akatsuki Cyber Team.”

2. The Meltdown: When Broken English Turned into a Public Grammar Lesson
Much of the initial rage was not driven by factual disputes, but by basic reading comprehension failures. JundAlNabi’s admin, operating under the moniker Bbq Heit, stormed into CyberAsia’s open discussion channel hurling insults. He claimed our journalists were fabricating stories, shouting: “The information is wrong who say i am selling data behind my allowances.”
The threat actor had completely misread an analytical paragraph defining how rogue cells monetize stolen data. He mistook an objective explanation of how threat groups operate as a personal accusation, all while confusing the English word “alliances” with “allowances”. Rather than trading insults, CyberAsia Editor-in-Chief Haider took time in the open channel to methodically break down the grammar, syntax, and vocabulary of the sentence, showing the actor why his anger was based on his own misunderstanding.

3. The White-Hat Trap: Xanark’s Failed Chat Manipulation Scheme
Humiliated in open chat, Akatsuki Cyber Team owner Xanark (who also uses the handle El Drago) switched tactics. He approached CyberAsia posing as a friendly “white-hat” researcher, offering to point out web vulnerabilities on our platform. But the offer came with an ultimatum: CyberAsia had to publish an apology clearing JundAlNabi’s name and declare that the Akatsuki Cyber Team and their partners were honorable.
Our editorial stance was clear and non-negotiable. Editor-in-Chief Haider told him directly: “We never accept to change the fact but we say that we will investigate further. Manipulating our chat was unacceptable.”
When coercion failed, Xanark took screenshots of the conversation, cropped out critical context, and distributed them across underground Telegram rooms to claim CyberAsia was working against Muslim communities. The trick fell flat almost immediately. Respected regional collectives, including Nation of Saviors, Cyber Team Indonesia (CTI), and RipperSec, stepped in and posted the complete, unedited chat logs, publicly warning the community: “Attack Confirmation Proof & Trying to chat manipulation. Shame on them.”

4. Under The Hood: 71,000 Automated Hits and a 2-Hour DDoS Surge
With their social engineering plot dismantled, the actors turned to brute force. Between 03:00 and 04:00 GMT+8, CyberAsia’s web perimeter registered a sudden spike of 71,520 automated requests aimed at administrative endpoints. Our origin servers never flinched, but edge firewall logs traced the entire burst back to an IP block (39.50.213.xx) owned by Pakistan Telecommunication Company Limited (PTCL, AS17557).
When editors confronted the group with the IP addresses, the Akatsuki Cyber Team administrator admitted the traffic originated from Pakistani infrastructure, casually brushing off the attack as an “accidental vulnerability scan.”

Minutes later, a commercial stresser attack kicked in. For two hours straight, an anonymous botnet pumped Layer 7 junk traffic into the site. The edge firewall adapted instantly, serving HTTP 429 (“Too Many Requests”) challenge pages to filter the noise while keeping the core database safe and intact.

5. The Leak: Insider Intelligence Unmasks the JundAlNabi Operator
Threat actors who bully journalists often forget that their own circles are rarely loyal. Shortly after the DDoS assault failed, an insider with direct access to JundAlNabi’s private operations contacted CyberAsia with verified account records.
The leak linked the group’s active administrative handles (@TO34**, Telegram ID: 69470*****) directly to an active Pakistani carrier SIM card starting with +92 347 804**** (Telenor Pakistan / PTCL route). The cellular carrier footprint lined up perfectly with the geographic location and ASN recorded during the 71,000-request scan hours earlier. By trying to intimidate reporters, the adversary handed over the exact evidence needed to confirm their physical jurisdiction.

[FIELD ANALYST OBSERVATION] “When threat groups launch noisy, emotional retaliatory attacks, they leave enormous digital footprints. In this case, trying to silence a small advisory ended up fully exposing their telecom accounts, geographic location, and inner network.”
6. The Ransomware Bluff: Former Akatsuki Cyber Team Chief Delivers Ultimatum
With their technical attacks absorbed and their identity exposed, the former leader of the Akatsuki Cyber Team, operating as billa_Uchiha (@Billah****), stepped forward to deliver a final threat.
Forwarded across JundAlNabi’s main channel, the message issued an explicit warning to shut down all investigations immediately: “Who is CEO of cyber Asia. I hear a lot about them… That all the time works for Islam. I am by his side and will always be. I do not want to hear anything more about cyber Asia and if you do not stop these then I will hack your system all computers ransomware attack.”

This empty extortion attempt fits the exact pattern seen across amateur hacktivist drama: loud threats designed to scare junior bloggers, with zero capacity to compromise hardened newsroom infrastructure. Furthermore, as documented in our separate investigation into Billa Uchiha hosting and selling Bangladeshi citizen data, the operator frequently relies on bravado to conceal underlying illicit monetization schemes.
Intelligence monitoring further indicates that the Akatsuki Cyber Team and JundAlNabi coordinate with loyalist auxiliary cells, including Cyber Squad 313. This auxiliary support network echoes operational communiques, amplifying distributed harassment campaigns and coordinating volunteer botnet stresser attacks across underground Telegram channels.
7. Practical Defense: How Independent Newsrooms Survive Cyber Intimidation
Independent cyber intelligence blogs and journalism outlets face constant harassment from rogue cells like the Akatsuki Cyber Team. Defending against these threats does not require enterprise budgets, it requires disciplined security basics:
- Air-Gapped Encrypted Backups: Keep offline, immutable daily snapshots of your database and media files. When adversaries threaten ransomware, having detached backups strips away all their leverage.
- Aggressive Edge Rate Limiting: Use Cloudflare or similar reverse proxies to drop high-frequency Layer 7 attacks before requests ever hit your PHP origin server.
- Hardware Security Keys (FIDO2): Require physical YubiKeys for all WordPress and server SSH logins. Threat actors love credential stuffing, but hardware keys stop password compromises cold.
- Secure Whistleblower Channels: Never communicate with threat actors on personal accounts. Security researchers and community members can securely send tips and breach evidence via the encrypted CyberAsia Secure Drop.
Frequently Asked Questions
Q1: Did the Akatsuki Cyber Team manage to compromise CyberAsia’s servers or steal reader data?
No. The attack consisted of automated directory scans and a Layer 7 botnet flood. Our origin servers remained isolated behind edge firewall rate-limiting, and no unauthorized access, database breach, or data exfiltration took place.
Q2: How was the adversary’s physical location confirmed so quickly?
Network traffic from the 71,000 automated scan requests pointed straight to an autonomous system belonging to Pakistan Telecommunication Company Limited (AS17557). Shortly after, an insider leaked unredacted account records showing the primary admin’s phone number registered to a Pakistani mobile operator under the exact same network.
Q3: What should journalists or researchers do if a hacktivist group threatens ransomware?
Do not engage in private negotiations or alter reporting under duress. Document all chat timestamps and sender IDs, preserve server firewall logs, isolate administrative endpoints behind hardware MFA, and verify that clean offline backups are intact.
Disclaimer: The information presented in this threat intelligence report is for educational and cybersecurity research purposes only. CyberAsia reports on cyber incidents to help organizations understand and defend against emerging threats. We do not provide hacking instructions, host stolen data, or endorse illegal activities.
> INTELLIGENCE_NOTICE
The report above detailing Pakistani Hackers Target Press Freedom: Akatsuki Cyber Team & JundAlNabi Threaten CyberAsia is part of the CyberAsia public archive. For organizations requiring Indicators of Compromise (IoCs), YARA signatures, and specialized malware containment guidelines for syndicate threats, please refer to our Secure Drop or contact the research desk.
> related_intel --suggest
syndicate
syndicate