{"id":4674,"date":"2026-09-02T02:42:55","date_gmt":"2026-09-02T02:42:55","guid":{"rendered":"https:\/\/cyberasia.io\/?p=4674"},"modified":"2026-09-05T08:01:06","modified_gmt":"2026-09-05T08:01:06","slug":"opindia-campaign-continues-cyber-team-indonesia-hits-kamat-org","status":"publish","type":"post","link":"https:\/\/cyberasia.io\/article\/ddos\/opindia-campaign-continues-cyber-team-indonesia-hits-kamat-org\/","title":{"rendered":"OpIndia Campaign Continues, Cyber Team Indonesia Hits Kamat.org"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Coordinated distributed denial of service strikes escalated over the weekend as <span style=\"color: #fb923c;border-radius: 4px;padding: 2px 7px;font-weight: 600\">Cyber Team Indonesia Hits Kamat.org<\/span> under the long-running <span style=\"color: #facc15;border-radius: 4px;padding: 2px 7px;font-weight: 600\">#OpIndia<\/span> banner. The assault caused temporary latency spikes and connection failures across the Indian cultural archive, with third-party check-host telemetry recording sporadic unreachable states before edge filtering stabilized incoming request rates.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"819\" height=\"1024\" src=\"https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/09\/IMG_20260902_085710_489-819x1024.jpg\" alt=\"\" class=\"wp-image-4676\" \/ loading=\"eager\" fetchpriority=\"high\" srcset=\"https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/09\/IMG_20260902_085710_489-819x1024.jpg 819w, https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/09\/IMG_20260902_085710_489-240x300.jpg 240w, https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/09\/IMG_20260902_085710_489-768x960.jpg 768w, https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/09\/IMG_20260902_085710_489.jpg 1024w\" sizes=\"(max-width: 819px) 100vw, 819px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The incident adds to a growing list of cases involving regional hacktivist groups targeting <strong><mark class=\"has-inline-color has-vivid-green-cyan-color\">Indian digital assets<\/mark><\/strong>, amid rising geopolitical and social tensions that have repeatedly fueled cross border cyber campaigns across Asia and beyond.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><mark class=\"has-inline-color has-luminous-vivid-amber-color\">What Happened<\/mark><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">According to the screenshot that circulated, the Telegram channel operated by Cyber Team Indonesia published an announcement titled &#8220;<strong><mark class=\"has-inline-color has-vivid-green-cyan-color\">ATTACK BY CYBER TEAM INDONESIA<\/mark><\/strong>&#8221; that named kamat.org as the target site, included a link to a check report on check-host.net with a permanent reference code, and carried a short message aimed at the party the group considers its target, written in a provocative tone toward India.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The check-host.net report cited as evidence shows the results of a scan performed against kamat.org on Sunday, August 30, 2026, at 10.11 UTC. Out of dozens of check points spread across different countries, most results showed a connection failure of some kind. A number of locations, including Austria, France, Germany, Hong Kong, India, Indonesia, Israel, Italy, Japan, the Netherlands, Slovenia, Spain, Sweden, Turkey, Ukraine, and the United States, recorded a <strong><mark class=\"has-inline-color has-vivid-red-color\">503 Service Unavailable error<\/mark><\/strong>, indicating the server was unable to process incoming requests. Meanwhile, other locations such as Brazil, Bulgaria, Canada, Finland, Iran, Moldova, Poland, Portugal, Romania, Russia, Serbia, Singapore, and Vietnam recorded connections that either timed out or were refused entirely.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"819\" height=\"1024\" src=\"https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/09\/IMG_20260902_085712_706-819x1024.jpg\" alt=\"\" class=\"wp-image-4677\" \/ loading=\"lazy\" srcset=\"https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/09\/IMG_20260902_085712_706-819x1024.jpg 819w, https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/09\/IMG_20260902_085712_706-240x300.jpg 240w, https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/09\/IMG_20260902_085712_706-768x960.jpg 768w, https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/09\/IMG_20260902_085712_706.jpg 1024w\" sizes=\"auto, (max-width: 819px) 100vw, 819px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Every check point that managed to connect to the server pointed to the same IP address, 45.43.3.21, which according to the report sits under a hosting provider identified as M Host. The consistent pattern of failures across multiple regions and continents is in line with a disruption at the server infrastructure level, which can be caused by several technical factors, including a large volume of requests being sent toward the target server at once.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><mark class=\"has-inline-color has-luminous-vivid-amber-color\">Who Is Affected<\/mark><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The party most directly affected by this incident is the operator and visitors of kamat.org. The site is a digital property based in India, though as of this report there has been no official statement from the site operator regarding the exact cause of the disruption or the recovery steps that have been or will be taken.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In a broader context, this incident is also part of a pattern of attacks under the <strong>#OpIndia<\/strong> and <strong>#AntiIndia<\/strong> banners that have repeatedly targeted domains and digital services affiliated with or originating from India in recent months. This pattern typically targets organizations with high public visibility as a form of statement from the group behind the campaign, rather than aiming for direct financial gain.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><mark class=\"has-inline-color has-luminous-vivid-amber-color\">Technical Details<\/mark><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">From a technical standpoint, the most notable indicator in this incident is the combination of <strong><mark class=\"has-inline-color has-vivid-red-color\">503 Service Unavailable errors <\/mark><\/strong>and <strong><mark class=\"has-inline-color has-vivid-red-color\">connection timed out<\/mark><\/strong> statuses appearing simultaneously across dozens of different countries within a single check window. This kind of pattern is commonly found in distributed service disruption incidents, where a target server receives a volume of requests far beyond its normal capacity and is unable to respond to legitimate requests from other users.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Response times recorded at the points that did manage to connect were also inconsistent. Some locations logged response times under one second, while others, such as Italy, logged response times of more than twenty seconds before the server eventually returned an error code. This kind of imbalance in response time further supports the indication that the server was under strain at the time the check was performed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">There is currently no further detail on the specific technical vector used in this incident, such as the type of traffic sent, the number of nodes involved, or the total duration of the disruption. <strong>CyberAsia<\/strong> will not disclose or detail any operational method that could provide technical guidance for others to replicate a similar incident, in line with the principles of responsible cybersecurity journalism.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><mark class=\"has-inline-color has-luminous-vivid-amber-color\">The Actor Behind the Action<\/mark><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Cyber Team Indonesia is a fairly well known name within the regional hacktivist ecosystem, frequently appearing in cyber campaigns carrying themes of digital nationalism or cross border solidarity around particular geopolitical issues. The group&#8217;s name has surfaced repeatedly in various <strong><mark class=\"has-inline-color has-vivid-purple-color\">#OpIndia<\/mark><\/strong> themed operations over recent months.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/09\/Cyber-Team-Indonesia-1024x576.jpg\" alt=\"\" class=\"wp-image-4679\" \/ loading=\"lazy\" srcset=\"https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/09\/Cyber-Team-Indonesia-1024x576.jpg 1024w, https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/09\/Cyber-Team-Indonesia-300x169.jpg 300w, https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/09\/Cyber-Team-Indonesia-768x432.jpg 768w, https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/09\/Cyber-Team-Indonesia.jpg 1280w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">One notable element of the post related to the kamat.org incident is a list of acknowledgments to a number of other hacktivist collectives said to have taken part or provided support within the same campaign. That list includes names such as Keymous, Dunia Maya Team, Tegal Cyber Team, Dr4k7h Cyber Team, Nation of Saviors, Garuda Kernel Error System, NoName057, AnonPioneers, DigitalStormSec, Khilafah Hackers, Babayo Eror System, BNCT 1360, DisruptOr, XH4X CYB3R, Karawang Error System, Dark Storm Team, VirusGroup21, RBL Leviathan Ghost, ForcloseSystem, Moroccon Black Cyber Army, Philippines Cyber Eagle Crew, RipperSec, We Are Cyber Force, and K3llLeakers.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"819\" height=\"1024\" src=\"https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/09\/IMG_20260902_085715_772-819x1024.jpg\" alt=\"\" class=\"wp-image-4680\" \/ loading=\"lazy\" srcset=\"https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/09\/IMG_20260902_085715_772-819x1024.jpg 819w, https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/09\/IMG_20260902_085715_772-240x300.jpg 240w, https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/09\/IMG_20260902_085715_772-768x960.jpg 768w, https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/09\/IMG_20260902_085715_772.jpg 1024w\" sizes=\"auto, (max-width: 819px) 100vw, 819px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The length of this list of collectives suggests that the action against kamat.org did not stand alone, but rather forms part of a wider #OpIndia campaign network involving numerous hacktivist groups across countries, spanning Southeast Asia, the Middle East, and North Africa. This kind of cross group collaboration has become a defining feature of contemporary hacktivism, where collectives with different backgrounds can unite under a single campaign hashtag for a period of time.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><mark class=\"has-inline-color has-luminous-vivid-amber-color\">Potential Impact<\/mark><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A service disruption on a site can carry a range of consequences depending on its function and the scale of its operations. For sites that serve as information channels or public services, unavailability over a certain period can disrupt user experience, lower public trust in the platform&#8217;s reliability, and potentially affect long term digital reputation if similar incidents recur in the future.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Beyond the direct impact on service availability, <strong><mark class=\"has-inline-color has-vivid-cyan-blue-color\">incidents like this also tend to draw attention within the cybersecurity community<\/mark><\/strong> as an indicator of ongoing hacktivist campaign activity. For other organizations with a similar profile, particularly those connected to the themes driving the #OpIndia campaign, this incident can serve as an early warning signal to strengthen their infrastructure readiness against the possibility of a similar disruption.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><mark class=\"has-inline-color has-luminous-vivid-amber-color\">Response and Mitigation<\/mark><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">As of this writing, there has been no official statement published by the <strong>kamat.org<\/strong> operator regarding the incident, including the exact cause of the disruption, the expected recovery timeline, or the technical steps taken to restore the service to normal.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Generally speaking, when facing a large scale service disruption of this kind, common mitigation steps taken by service providers include temporarily increasing server capacity, rerouting traffic through a content delivery network, applying filtering mechanisms against suspicious traffic, and coordinating with the hosting provider to continuously monitor for anomalous patterns. <strong>CyberAsia<\/strong> will update this report if an official statement from the parties involved becomes available, or if there are further developments regarding the recovery status of kamat.org.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><mark class=\"has-inline-color has-luminous-vivid-amber-color\">Conclusion<\/mark><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The incident affecting <strong><mark class=\"has-inline-color has-vivid-green-cyan-color\">kamat.org<\/mark><\/strong> stands as the latest example of the ongoing <strong><mark class=\"has-inline-color has-luminous-vivid-orange-color\">#OpIndia<\/mark><\/strong> campaign pattern, one that involves a wide network of hacktivist collectives across borders. With <strong>Cyber Team Indonesia<\/strong> being one of the names most frequently associated with campaigns of this kind, the kamat.org incident underscores that regional hacktivism remains a real threat to digital service availability, particularly for entities that fall within the thematic scope of a given campaign. The situation highlights the importance of solid infrastructure readiness and a well prepared incident response plan for any organization that could become a target amid the constantly evolving dynamics of digital geopolitics.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\" \/>\n\n\n\n<p class=\"wp-block-paragraph\"><em><strong><mark class=\"has-inline-color has-vivid-red-color\">Disclaimer:<\/mark><\/strong> CyberAsia is an independent Cyber Threat Intelligence (CTI) research organization. The information provided in this report is derived from public intelligence gathering, dark web monitoring, and threat actor claims. It is published strictly for educational purposes, defensive analysis, and public awareness. CyberAsia does not endorse, verify, or facilitate any cyberattacks or illegal activities.<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n","protected":false},"excerpt":{"rendered":"<p>Coordinated distributed denial of service strikes escalated as Cyber Team Indonesia Hits Kamat.org under the #OpIndia banner, causing temporary latency spikes and connection failures across the Indian cultural archive.<\/p>\n","protected":false},"author":3,"featured_media":4675,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[2393,2396,1952,1656,521,152,2385,61,203,14,70,12,2394,1664,2390,2386,1965,1649,1662,1655,2392,1260,2397,2391,1945,2395,2388,2389,1665,2387,1981,1247,1462,1164],"threat_actors":[659],"class_list":["post-4674","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ddos","tag-actualite-cybersecurite","tag-anti-india-cyber-campaign","tag-ataque-cibernetico","tag-berita-keamanan-siber","tag-cyber-asia","tag-cyber-security","tag-cyber-security-news","tag-cyber-team-indonesia","tag-cyberasia","tag-ddos-attack","tag-hacker-news","tag-hacktivism","tag-kamat-org","tag-keselamatan-siber","tag-noticias-de-ciberseguridad","tag-opindia","tag-peretas-indonesia","tag-serangan-ddos","tag-serangan-penggodam","tag-serangan-siber","tag-siber-guvenlik-haberleri","tag-1260","tag-2397","tag-2391","tag-1945","tag-2395","tag-2388","tag-2389","tag-1665","tag-2387","tag-1981","tag-1247","tag-1462","tag-1164","threat_actor-cyber-team-indonesia"],"_links":{"self":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/posts\/4674","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/comments?post=4674"}],"version-history":[{"count":5,"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/posts\/4674\/revisions"}],"predecessor-version":[{"id":4782,"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/posts\/4674\/revisions\/4782"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/media\/4675"}],"wp:attachment":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/media?parent=4674"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/categories?post=4674"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/tags?post=4674"},{"taxonomy":"threat_actor","embeddable":true,"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/threat_actors?post=4674"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}