Hacktivist group

Demon Sec Cyber Team

Demon Sec Cyber Team (D.S.C.T.) is a hacktivist-style collective with publicly archived website-defacement activity and third-party reporting of DDoS operations. The strongest technical record is a January 2026 DefacerID incident that attributes a defacement to Demon Sec Cyber Team / TokekTamvan404 and explicitly records SQL Injection as the proof-of-concept access vector.

Separate archive evidence associates the team label with notifier Zero 404 in an October 2025 defacement. TokekTamvan404 later appears under another team label, so these aliases should be treated as incident-linked operators rather than automatically promoted to permanent core membership.

Third-party monitoring in November 2025 reported DDoS claims against Indian government/trade web properties. The reporting preserves actor claims and availability checks but does not provide victim-side forensic validation. An announced alliance with BD Anonymous in December 2025 adds a coalition dimension.

The evidence supports a hybrid public-web posture: integrity attacks through defacement and availability attacks through DDoS claims. Stable malware, C2 infrastructure, credential-theft tooling and post-compromise lateral movement are not established.

Overall confidence is medium-high for the group’s existence and defacement activity; medium for DDoS activity and specific alias relationships; and low-to-medium for origin. Indonesian ecosystem ties are plausible but physical origin remains unconfirmed.

Created by iQBlack CTI Team
Contributors 1
Last updated 2026-08-18