How an obscure Indian cyber firm spied on politicians, investors through horoscopes and porn

News Network
June 27, 2020

Jun 27: Alittle-known Indian IT firm offered its hacking services to help clients spy on more than 10,000 email accounts over a period of seven years.

New Delhi-based BellTroX InfoTech Services targeted government officials in Europe, gambling tycoons in the Bahamas, and well-known investors in the United States including private equity giant KKR and short seller Muddy Waters, according to three former employees, outside researchers, and a trail of online evidence.

Aspects of BellTroX's hacking spree aimed at American targets are currently under investigation by U.S. law enforcement, five people familiar with the matter told Reuters. The U.S. Department of Justice declined to comment.

Reuters does not know the identity of BellTroX's clients. In a telephone interview, the company's owner, Sumit Gupta, declined to disclose who had hired him and denied any wrongdoing.

Muddy Waters founder Carson Block said he was "disappointed, but not surprised, to learn that we were likely targeted for hacking by a client of BellTroX." KKR declined to comment.

Researchers at internet watchdog group Citizen Lab, who spent more than two years mapping out the infrastructure used by the hackers, released a report that BellTroX employees were behind the espionage campaign.

"This is one of the largest spy-for-hire operations ever exposed," said Citizen Lab researcher John Scott-Railton.

Although they receive a fraction of the attention devoted to state-sponsored espionage groups or headline-grabbing heists, "cyber mercenary" services are widely used, he said. "Our investigation found that no sector is immune."

A cache of data reviewed by Reuters provides insight into the operation, detailing tens of thousands of malicious messages designed to trick victims into giving up their passwords that were sent by BellTroX between 2013 and 2020. The data was supplied on condition of anonymity by online service providers used by the hackers after Reuters alerted the firms to unusual patterns of activity on their platforms.

The data is effectively a digital hit list showing who was targeted and when. Reuters validated the data by checking it against emails received by the targets.

On the list: judges in South Africa, politicians in Mexico, lawyers in France and environmental groups in the United States. These dozens of people, among the thousands targeted by BellTroX, did not respond to messages or declined comment.

Reuters was not able to establish how many of the hacking attempts were successful.

BellTroX's Gupta was charged in a 2015 hacking case in which two U.S. private investigators admitted to paying him to hack the accounts of marketing executives. Gupta was declared a fugitive in 2017, although the U.S. Justice Department declined to comment on the current status of the case or whether an extradition request had been issued.

Speaking by phone from his home in New Delhi, Gupta denied hacking and said he had never been contacted by law enforcement. He said he had only ever helped private investigators download messages from email inboxes after they provided him with login details.

"I didn't help them access anything, I just helped them with downloading the mails and they provided me all the details," he told Reuters. "I am not aware how they got these details but I was just helping them with the technical support."

Reuters could not determine why the private investigators might need Gupta to download emails. Gupta did not return follow-up messages. Spokesmen for Delhi police and India's foreign ministry did not respond to requests for comment.

HOROSCOPES AND PORNOGRAPHY

Operating from a small room above a shuttered tea stall in a west-Delhi retail complex, BellTroX bombarded its targets with tens of thousands of malicious emails, according to the data reviewed by Reuters. Some messages would imitate colleagues or relatives; others posed as Facebook login requests or graphic notifications to unsubscribe from pornography websites.

Fahmi Quadir's New York-based short selling firm Safkhet Capital was among 17 investment companies targeted by BellTroX between 2017 and 2019. She said she noticed a surge in suspicious emails in early 2018, shortly after she launched her fund.

Initially "it didn't seem necessarily malicious," Quadir said. "It was just horoscopes; then it escalated to pornography."

Eventually the hackers upped their game, sending her credible-sounding messages that looked like they came from her coworkers, other short sellers or members of her family. "They were even trying to emulate my sister," Quadir said, adding that she believes the attacks were unsuccessful.

U.S. advocacy groups were also repeatedly targeted. Among them were digital rights organizations Free Press and Fight for the Future, both of whom have lobbied for net neutrality. The groups said a small number of employee accounts were compromised, but the wider organizations' networks were untouched. The spying on those groups was detailed in a report by the Electronic Frontier Foundation in 2017, but has not been publicly tied to BellTroX until now.

Timothy Karr, a director at Free Press, said his organization "sees an uptick in breach attempts whenever we're engaged in heated and high-profile public policy debates." Evan Greer, deputy director of Fight for the Future, said: "When corporations and politicians can hire digital mercenaries to target civil society advocates, it undermines our democratic process."

While Reuters was not able to establish who hired BellTroX to carry out the hacking, two former employees said the company and others like it were usually contracted by private investigators on behalf of business rivals or political opponents.

Bart Santos of San Diego-based Bulldog Investigations was one of a dozen private detectives in the United States and Europe who told Reuters they had received unsolicited advertisements for hacking services out of India - including one from a person who described himself as a former BellTroX employee. The pitch offered to carry out "data penetration" and "email penetration."

Santos said he ignored those overtures, but could understand why some people didn't. "The Indian guys have a reputation for customer service," he said.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
January 26,2020

Jaipur, Jan 26: Rajasthan on Saturday on Saturday became the third state in the country to pass a resolution urging the Centre to repeal the Citizenship Amendment Act (CAA).

he resolution was passed in the state Assembly amid opposition by the BJP which accused the ruling Congress of pursuing appeasement politics.

It is the second Congress-ruled state to pass such a resolution after Punjab. The Kerala Assembly too had passed such a resolution against the CAA moved jointly by the ruling Left Front alliance and the opposition Congress-led UDF.

The Rajasthan Assembly resolution, passed by voice vote, also asked the Centre to withdraw the new fields of information that have been sought for updation of the National Population Register (NPR) 2020.

"It is evident that the CAA violates the provisions of the Constitution. Therefore, the House resolves to urge upon the government of India to repeal the CAA to avoid any discrimination on the basis of religion in granting citizenship and to ensure equality before law for all religious groups of India," the state's parliamentary affairs minister Shanti Dhariwal said, moving the resolution.

Leader of the opposition Gulab Chand Kataria of the BJP questioned the state's right to challenge the Act.

"Granting citizenship is a matter for the Centre. In such a situation do we have the right to challenge the CAA? The Congress should stop doing appeasement and vote bank politics," he said.

Comments

abdullah
 - 
Sunday, 26 Jan 2020

Salute to Rajasthan Govt for rejecting communal and black CAA bill.   This bill is agaisnt the teach of our Constitution and bjp has never done anything as per our constitutin.   Its trying its best to scrap the constitution and restore it with RSS agenda.    We should oppose any move by bjp against the value of constitution.   As bjp has no respect to our constitution, it has no right to be in power.    Many of bjp leaders are giving statemetns against the value of constitution and such leaders should be treated as anti indians and action be taken on them.   

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
January 31,2020

New Delhi, Jan 31: The Supreme Court Friday dismissed the plea filed by one of the four death row convicts in the Nirbhaya gang-rape and murder case, Pawan Gupta, seeking review of its order rejecting his juvenility claim.

The review plea filed earlier in the day was taken up for consideration in-chamber by a bench comprising Justices R Banumathi, Ashok Bhushan and A S Bopanna. 

On January 20, the apex court had rejected the plea by Pawan who had challenged the Delhi High Court's order dismissing his juvenility claim.

Advocate A P Singh, who is representing Pawan in the case, said he filed a petition on his behalf seeking review of the top court's January 20 order on Friday.

While dismissing the plea, the top court had said there was no ground to interfere with the high court order that rejected Pawan's plea and his claim was rightly rejected by the trial court as also the high court.

It had said the matter was raised earlier in the review petition before the apex court which rejected plea of juvenility taken by Pawan and another co-accused Vinay Kumar Sharma and that order has attained finality.

Singh had argued that as per his school leaving certificate, he was a minor at the time of the offence and none of the courts, including trial court and high court, ever considered his documents.

Solicitor General Tushar Mehta, appearing for the Delhi Police, had said Pawan's claim of juvenility was considered at each and every judicial forum and it will be a travesty of justice if the convict is allowed to raise the claim of juvenility repeatedly and at this point of time.

The trial court on January 17 issued black warrants for the second time for the execution of all the four convicts in the case -- Mukesh Kumar Singh (32), Pawan (25), Vinay (26) and Akshay (31) -- in Tihar jail at 6 am on February 1. Earlier, on January 7, the court had fixed January 22 as the hanging date.

As of now, only Mukesh has exhausted all his legal remedies including the clemency plea which was dismissed by President Ram Nath Kovind on January 17 and the appeal against the rejection was thrown out by the Supreme Court on January 29.

Convict Akshay's curative petition was dismissed by the top court on January 30. Another death row convict Vinay moved mercy plea before President on January 29, which is pending.

Singh has also approached the trial court seeking stay on the execution scheduled on February 1, saying the legal remedies of some of the convicts are yet to be availed.

A 23-year-old paramedic student, referred to as Nirbhaya, was gang-raped and brutally assaulted on the intervening night of December 16-17, 2012, in a moving bus in south Delhi by six people before she was thrown out on the road.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
April 3,2020

New Delhi, Apr 3: Jamiat Ulema-e-Hind leader Mahmood Madani on Thursday said that misbehaviour with doctors cannot be tolerated as they are working to protect everyone.

"We can only spread awareness about coronavirus that its only cure is by taking precautions. The government shared the precautions that people should not take part in any gathering, be clean and maintain social distance. After the reports, it will clear that how it is spread in the country," Madani told news agency.

"People who are objecting to testing in Lok Nayak Jai Prakash Narayan Hospital are very wrong and they should follow the instructions.

Hospital authorities and administration should talk to them. Today doctors are our soldiers who protect us and wrong behaviour with doctors cannot be tolerated," he added.

He further said that Jamiat wrote to the PM Narendra Modi that they will provide a place for 10,000 people in different states. Our workers also distributed food to one lakh people, he added.

People who attended a religious prayer meeting from March 13-15 at Markaz in the Nizamuddin area of Delhi were sent to Lok Nayak Hospital for coronavirus test on March 30.

The Union Ministry of Health and Family Welfare on Thursday said that there are 2,069 coronavirus positive cases in India, including 1,860 active cases, 156 cured/discharged/migrated people and 53 deaths.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.