How an obscure Indian cyber firm spied on politicians, investors through horoscopes and porn

News Network
June 27, 2020

Jun 27: Alittle-known Indian IT firm offered its hacking services to help clients spy on more than 10,000 email accounts over a period of seven years.

New Delhi-based BellTroX InfoTech Services targeted government officials in Europe, gambling tycoons in the Bahamas, and well-known investors in the United States including private equity giant KKR and short seller Muddy Waters, according to three former employees, outside researchers, and a trail of online evidence.

Aspects of BellTroX's hacking spree aimed at American targets are currently under investigation by U.S. law enforcement, five people familiar with the matter told Reuters. The U.S. Department of Justice declined to comment.

Reuters does not know the identity of BellTroX's clients. In a telephone interview, the company's owner, Sumit Gupta, declined to disclose who had hired him and denied any wrongdoing.

Muddy Waters founder Carson Block said he was "disappointed, but not surprised, to learn that we were likely targeted for hacking by a client of BellTroX." KKR declined to comment.

Researchers at internet watchdog group Citizen Lab, who spent more than two years mapping out the infrastructure used by the hackers, released a report that BellTroX employees were behind the espionage campaign.

"This is one of the largest spy-for-hire operations ever exposed," said Citizen Lab researcher John Scott-Railton.

Although they receive a fraction of the attention devoted to state-sponsored espionage groups or headline-grabbing heists, "cyber mercenary" services are widely used, he said. "Our investigation found that no sector is immune."

A cache of data reviewed by Reuters provides insight into the operation, detailing tens of thousands of malicious messages designed to trick victims into giving up their passwords that were sent by BellTroX between 2013 and 2020. The data was supplied on condition of anonymity by online service providers used by the hackers after Reuters alerted the firms to unusual patterns of activity on their platforms.

The data is effectively a digital hit list showing who was targeted and when. Reuters validated the data by checking it against emails received by the targets.

On the list: judges in South Africa, politicians in Mexico, lawyers in France and environmental groups in the United States. These dozens of people, among the thousands targeted by BellTroX, did not respond to messages or declined comment.

Reuters was not able to establish how many of the hacking attempts were successful.

BellTroX's Gupta was charged in a 2015 hacking case in which two U.S. private investigators admitted to paying him to hack the accounts of marketing executives. Gupta was declared a fugitive in 2017, although the U.S. Justice Department declined to comment on the current status of the case or whether an extradition request had been issued.

Speaking by phone from his home in New Delhi, Gupta denied hacking and said he had never been contacted by law enforcement. He said he had only ever helped private investigators download messages from email inboxes after they provided him with login details.

"I didn't help them access anything, I just helped them with downloading the mails and they provided me all the details," he told Reuters. "I am not aware how they got these details but I was just helping them with the technical support."

Reuters could not determine why the private investigators might need Gupta to download emails. Gupta did not return follow-up messages. Spokesmen for Delhi police and India's foreign ministry did not respond to requests for comment.

HOROSCOPES AND PORNOGRAPHY

Operating from a small room above a shuttered tea stall in a west-Delhi retail complex, BellTroX bombarded its targets with tens of thousands of malicious emails, according to the data reviewed by Reuters. Some messages would imitate colleagues or relatives; others posed as Facebook login requests or graphic notifications to unsubscribe from pornography websites.

Fahmi Quadir's New York-based short selling firm Safkhet Capital was among 17 investment companies targeted by BellTroX between 2017 and 2019. She said she noticed a surge in suspicious emails in early 2018, shortly after she launched her fund.

Initially "it didn't seem necessarily malicious," Quadir said. "It was just horoscopes; then it escalated to pornography."

Eventually the hackers upped their game, sending her credible-sounding messages that looked like they came from her coworkers, other short sellers or members of her family. "They were even trying to emulate my sister," Quadir said, adding that she believes the attacks were unsuccessful.

U.S. advocacy groups were also repeatedly targeted. Among them were digital rights organizations Free Press and Fight for the Future, both of whom have lobbied for net neutrality. The groups said a small number of employee accounts were compromised, but the wider organizations' networks were untouched. The spying on those groups was detailed in a report by the Electronic Frontier Foundation in 2017, but has not been publicly tied to BellTroX until now.

Timothy Karr, a director at Free Press, said his organization "sees an uptick in breach attempts whenever we're engaged in heated and high-profile public policy debates." Evan Greer, deputy director of Fight for the Future, said: "When corporations and politicians can hire digital mercenaries to target civil society advocates, it undermines our democratic process."

While Reuters was not able to establish who hired BellTroX to carry out the hacking, two former employees said the company and others like it were usually contracted by private investigators on behalf of business rivals or political opponents.

Bart Santos of San Diego-based Bulldog Investigations was one of a dozen private detectives in the United States and Europe who told Reuters they had received unsolicited advertisements for hacking services out of India - including one from a person who described himself as a former BellTroX employee. The pitch offered to carry out "data penetration" and "email penetration."

Santos said he ignored those overtures, but could understand why some people didn't. "The Indian guys have a reputation for customer service," he said.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
March 6,2020

Riyadh, Mar 6: Saudi Arabia on Thursday emptied Islam's holiest site for sterilisation over fears of the new coronavirus, an unprecedented shutdown state media said will last while the year-round Umrah pilgrimage is suspended.

The kingdom halted the pilgrimage for its own citizens and residents on Wednesday, on top of restrictions announced last week on foreign pilgrims to stop the disease from spreading.

State television relayed images of an empty white-tiled area surrounding the Kaaba -- a large black cube structure inside Mecca's Grand Mosque -- which is usually packed with tens of thousands of pilgrims.

As a "precautionary measure", the area will remain closed as long as the umrah suspension lasts but prayers will be allowed inside the mosque, state-run Saudi Press Agency cited a mosque official as saying.

Additionally, the Grand Mosque and the Prophet's Mosque in the city of Medina will be closed an hour after the evening "Isha" prayer and will reopen an hour before the dawn "Fajr" prayer to allow cleaning and sterilisation, the official added.

A group of cleaners was seen scrubbing and mopping the tiles around the Kaaba, a structure draped in gold-embroidered gold cloth towards which Muslims around the world pray.

A Saudi official told news agency the decision to close the area was "unprecedented".

On Wednesday, Saudi Arabia suspended the umrah for its own citizens and residents over fears of the coronavirus spreading to Islam's holiest cities.

The move came after authorities last week suspended visas for the umrah and barred citizens from the six-nation Gulf Cooperation Council from entering Mecca and Medina.

Saudi Arabia on Thursday declared three new coronavirus cases, bringing the total number of reported infections to five.

The umrah, which refers to the Islamic pilgrimage to Mecca that can be undertaken at any time of year, attracts millions of Muslims from across the globe annually.

The decision to suspend the umrah mirrors a precautionary approach across the Gulf to cancel mass gatherings from concerts to sporting events.

It comes ahead of the holy fasting month of Ramadan starting in late April, which is a favoured period for pilgrimage.

It is unclear how the coronavirus will affect the hajj, due to start in late July.

Some 2.5 million faithful travelled to Saudi Arabia from across the world in 2019 to take part in the hajj, which is one of the five pillars of Islam as Muslim obligations are known.

The event is a massive logistical challenge for Saudi authorities, with colossal crowds cramming into relatively small holy sites, making attendees vulnerable to contagion.

Already reeling from slumping oil prices, the kingdom risks losing billions of dollars annually from religious tourism as it tightens access to the sites.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
January 30,2020

New Delhi, Jan 30: In a major shift of strategy ahead of the Delhi assembly polls, the Bharatiya Janata Party (BJP) has decided to rope in its senior leaders for massive public rallies.

Its star campaigners like Prime Minister Narendra Modi, Union Home Minister Amit Shah, BJP chief JP Nadda, Uttar Pradesh Chief Minister Yogi Adityanath, and other union ministers would now be addressing massive public rallies in addition to ongoing neighbourhood meetings.

"The big rallies would begin from February 1. While 'Nukkad' meetings will take place till the last day of campaigning, there would be big rallies of the top leadership of the party, " informed a senior party leader.

Sources said the BJP has changed its strategy after the success of its grassroots contact programme as the party wants to consolidate its gains.

"As part of the reworked strategy the BJP has asked its various Mandals to organise public meetings of 10,000-15,000 people in each assembly segment to reach out to the masses," sources added.

While there are two planned for Prime Minister Modi, two have been planned for JDU chief and Bihar Chief Minister Nitish Kumar along with Nadda and Amit Shah. Yogi Aadityanath too would be addressing 12 rallies.

The party is leaving no stone unturned to secure massive gains, which it feels can be converted to victory in the forthcoming polls.

Party sources feel that the relentless campaigning under the guidance of Amit Shah and Nadda has ensured that the morale of party cadre is at an all-time high.

"The neighbourhood meetings have ensured that we have been able to make the people of Delhi aware of the lack of work under the Arvind Kejriwal led Aam Aadmi Party government. They have also been apprised about the anti-national views of the opponents and we think that this is expected to turn the polls into our favour," sources added.

Delhi is scheduled for assembly polls on February 8 and the results for the 70 constituencies will be declared on February 11.

As part of the new strategy, senior leaders like JP Nadda, Amit Shah, Uttar Pradesh chief minister Yogi Adityanath, ministers like Rajnath Singh and Smriti Irani would be holding public rallies in various parts of the city. Several other chief ministers from various BJP ruled states are also expected to be roped in for the campaign.

The strategy for reach out to the masses is an attempt at weakening the hold of AAP on Delhi. With positive feedback coming after the success of the neighbourhood meetings in the past week, the BJP is now looking to increase its potential reach with polls just days away.

Till now the party had deployed 70 union ministers to hold at least one public meeting and one 'padayatra' each as part of the campaign.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
January 3,2020

Dhaka, Jan 3: Bangladesh's paramilitary force chief said on Thursday that a total of 445 Bangladeshi nationals returned from India in last two months following the publication of the National Register of Citizens (NRC) by the Indian government.

Border Guard Bangladesh (BGB) Director General Maj Gen Md Shafeenul Islam disclosed the figure during a press briefing here.

"About 1,000 people were arrested in 2019 for illegal border crossings from India to Bangladesh, with 445 of them returning home in November and December," he said.

After verifying their identities through local representatives, BGB came to know that all the intruders are Bangladeshis, Islam said, adding that 253 cases were lodged against them for illegal trespass, while initial investigations found that at least three of them were human traffickers.

The BGB Director said the trespassing did not create any tension between the border forces of Bangladesh and India.

Last week, Islam visited India where he said that the creation of the NRC is completely an "internal affair" of India and the cooperation between the border guarding forces of the two countries is very good.

He said the BGB will continue to do its work of preventing illegal border crossings as per its mandate.

A BGB delegation, led by Islam, was on a bilateral visit to India to hold DG-level border talks with its counterparts, the Border Security Force (BSF).

The talks took place from December 26-29, during which a host of issues related to cross-border smuggling and activities of criminals and others along the 4,096-km-long front were discussed.

Responding to a question, Islam said, "No discussion was held at the conference over the (NRC) issue".

He said during the five-day talks held in New Delhi, the BGB demanded that the BSF should take effective steps to prevent killings of Bangladeshis on frontiers as casualty figures sharply rose in 2019.

"The number of border killings in 2019 was highest in the last four years. As per our calculation, the number of such unexpected deaths was 35," the BGB chief said.

However, the BSF estimate of the casualty figure is much lower than our calculation, he said.

Islam said the BSF is following the policy of maintaining maximum restraint and minimal use of force even after being attacked by "armed border offenders".

A statement issued by the BSF last month in New Delhi after the conclusion of the DG-level talks said, "On the concern of the BGB regarding the death of Bangladeshi nationals on borders, it was informed to them that a non-lethal weapon policy is strictly followed by BSF personnel on borders.

"Firing is resorted to only in self-defence, when BSF patrols are gheraoed and attacked by ‘dah’ (a sharp-edged weapon) etc. It was specified that the BSF does not discriminate between criminals based on nationality," it said.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.