How an obscure Indian cyber firm spied on politicians, investors through horoscopes and porn

News Network
June 27, 2020

Jun 27: Alittle-known Indian IT firm offered its hacking services to help clients spy on more than 10,000 email accounts over a period of seven years.

New Delhi-based BellTroX InfoTech Services targeted government officials in Europe, gambling tycoons in the Bahamas, and well-known investors in the United States including private equity giant KKR and short seller Muddy Waters, according to three former employees, outside researchers, and a trail of online evidence.

Aspects of BellTroX's hacking spree aimed at American targets are currently under investigation by U.S. law enforcement, five people familiar with the matter told Reuters. The U.S. Department of Justice declined to comment.

Reuters does not know the identity of BellTroX's clients. In a telephone interview, the company's owner, Sumit Gupta, declined to disclose who had hired him and denied any wrongdoing.

Muddy Waters founder Carson Block said he was "disappointed, but not surprised, to learn that we were likely targeted for hacking by a client of BellTroX." KKR declined to comment.

Researchers at internet watchdog group Citizen Lab, who spent more than two years mapping out the infrastructure used by the hackers, released a report that BellTroX employees were behind the espionage campaign.

"This is one of the largest spy-for-hire operations ever exposed," said Citizen Lab researcher John Scott-Railton.

Although they receive a fraction of the attention devoted to state-sponsored espionage groups or headline-grabbing heists, "cyber mercenary" services are widely used, he said. "Our investigation found that no sector is immune."

A cache of data reviewed by Reuters provides insight into the operation, detailing tens of thousands of malicious messages designed to trick victims into giving up their passwords that were sent by BellTroX between 2013 and 2020. The data was supplied on condition of anonymity by online service providers used by the hackers after Reuters alerted the firms to unusual patterns of activity on their platforms.

The data is effectively a digital hit list showing who was targeted and when. Reuters validated the data by checking it against emails received by the targets.

On the list: judges in South Africa, politicians in Mexico, lawyers in France and environmental groups in the United States. These dozens of people, among the thousands targeted by BellTroX, did not respond to messages or declined comment.

Reuters was not able to establish how many of the hacking attempts were successful.

BellTroX's Gupta was charged in a 2015 hacking case in which two U.S. private investigators admitted to paying him to hack the accounts of marketing executives. Gupta was declared a fugitive in 2017, although the U.S. Justice Department declined to comment on the current status of the case or whether an extradition request had been issued.

Speaking by phone from his home in New Delhi, Gupta denied hacking and said he had never been contacted by law enforcement. He said he had only ever helped private investigators download messages from email inboxes after they provided him with login details.

"I didn't help them access anything, I just helped them with downloading the mails and they provided me all the details," he told Reuters. "I am not aware how they got these details but I was just helping them with the technical support."

Reuters could not determine why the private investigators might need Gupta to download emails. Gupta did not return follow-up messages. Spokesmen for Delhi police and India's foreign ministry did not respond to requests for comment.

HOROSCOPES AND PORNOGRAPHY

Operating from a small room above a shuttered tea stall in a west-Delhi retail complex, BellTroX bombarded its targets with tens of thousands of malicious emails, according to the data reviewed by Reuters. Some messages would imitate colleagues or relatives; others posed as Facebook login requests or graphic notifications to unsubscribe from pornography websites.

Fahmi Quadir's New York-based short selling firm Safkhet Capital was among 17 investment companies targeted by BellTroX between 2017 and 2019. She said she noticed a surge in suspicious emails in early 2018, shortly after she launched her fund.

Initially "it didn't seem necessarily malicious," Quadir said. "It was just horoscopes; then it escalated to pornography."

Eventually the hackers upped their game, sending her credible-sounding messages that looked like they came from her coworkers, other short sellers or members of her family. "They were even trying to emulate my sister," Quadir said, adding that she believes the attacks were unsuccessful.

U.S. advocacy groups were also repeatedly targeted. Among them were digital rights organizations Free Press and Fight for the Future, both of whom have lobbied for net neutrality. The groups said a small number of employee accounts were compromised, but the wider organizations' networks were untouched. The spying on those groups was detailed in a report by the Electronic Frontier Foundation in 2017, but has not been publicly tied to BellTroX until now.

Timothy Karr, a director at Free Press, said his organization "sees an uptick in breach attempts whenever we're engaged in heated and high-profile public policy debates." Evan Greer, deputy director of Fight for the Future, said: "When corporations and politicians can hire digital mercenaries to target civil society advocates, it undermines our democratic process."

While Reuters was not able to establish who hired BellTroX to carry out the hacking, two former employees said the company and others like it were usually contracted by private investigators on behalf of business rivals or political opponents.

Bart Santos of San Diego-based Bulldog Investigations was one of a dozen private detectives in the United States and Europe who told Reuters they had received unsolicited advertisements for hacking services out of India - including one from a person who described himself as a former BellTroX employee. The pitch offered to carry out "data penetration" and "email penetration."

Santos said he ignored those overtures, but could understand why some people didn't. "The Indian guys have a reputation for customer service," he said.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
April 25,2020

New Delhi, Apr 25: With 1,429 more COVID-19 cases reported in the last 24 hours, India's count of coronavirus cases has reached 24,506, said Ministry of Health and Family Welfare on Friday.

Out of these, 18,668 patients are active cases and 5063 cases have been cured, discharged, or migrated.

The death toll stands at 775, with as many as 57 deaths reported in the last 24 hours.

According to the morning update by the ministry, Maharashtra continues to be the worst-hit State with 6,817 cases of which 840 patients have recovered and 301 patients have died.

Gujarat now stands in the second spot with 2,815 cases, of which 265 have recovered and 127 people have died. Meanwhile, Delhi's count stands at 2,514 of which 857 patients have recovered, while 53 patients have lost their lives.

Tamil Nadu's COVID-19 figure stands at 1,755 with 866 patients recovered and 22 fatalities. Rajasthan has reported 2,034 cases of which 230 have recovered and 27 patients are dead.

Madhya Pradesh has reported 1,852 positive cases so far of which 210 patients have recovered and 92 patients have lost their lives due to the virus. In Uttar Pradesh, as many as 1,621 people have confirmed COVID-19, of which 247 recovered and 25 people have succumbed to it.

In Kerala, which reported the country's first COVID-19 case, 450 people have been detected positive for coronavirus.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
July 1,2020

Chennai, Jul 1: In a case of cluster infection, 58 of the 65 mourners who attended the funeral a Central government official, Selvam, 56, who had worked in the Ministry of Foreign Trade and who died in Coimbatore and was brought for burial at Pannavaadi near Kolathur near Mettur in Salem district, tested positive for Covid-19, after three of them initially tested positive as they neither wore face masks not observed social distancing during the funeral, sources said.

Even as Dr Vijayabaskar said AIADMK MLA from Sriperumbudur, K Palani who tested positive for Covid-19 has recovered and will be discharged from hospital in couple of days, the MIOT International Hospital in Chennai said that the State Higher Education Minister, K P Anbazhagan, who initially showed no symptoms of coronavirus, subsequently tested positive in his second sample. He was now under treatment, his condition very stable and all his vital parameters are normal, MIOT said in a statement.

In what continues to be an unrestrained run, Tamil Nadu added its biggest day-wise spike so far of 3,943 positive Covid-19 cases, while another 60 deaths due to the novel coronavirus confirmed on Tuesday took the total death toll in the state to 1,201.

Of the new positive cases, Chennai alone accounted for its highest per-day jump of 2,393 positives with the number of persons tested today across Tamil Nadu put at 30,053. The total number os Covid-19 positive cases in the State as a whole till date is racing towards the one lakh mark at 90,167.

However, these outcomes are all on anticipated lines with the ICMR's push for more aggressive testing, even if they want lockdown controls to be now more focused at the district level, and want the Chennai model to be taken to the districts.

In this backdrop, the Health minister, Dr C Vijayabaskar chaired a detailed Covid review meeting this evening through video conference with all the hospital deans and other top officials on different facets of the disease prevention and control measures and the state's overall preparedness.

Chief Minister, Mr. Edappadi K Palaniswami in a statement in Chennai assured that with the 'full lockdown' continuing in greater Chennai, parts of three neighbouring districts of Chengalpattu, Thiruvallur and Kancheepuram and parts of Madurai district till July 5, the free community kitchens for the elderly, disabled and destitute will continue to function in those places till July 5 and hygienically cooked food packets served to them.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
April 23,2020

Apr 23: Mukesh Ambani is again Asia's richest person after a deal with Mark Zuckerberg's Facebook Inc. sent his conglomerate's stock surging.

Ambani's fortune rose about $4.7 billion to $49.2 billion on Wednesday, after Reliance Industries Ltd. gained 10%. The jump put Ambani about $3.2 billion ahead of China's Jack Ma, according to the Bloomberg Billionaires Index. The ranking updates after the close of each trading day in the U.S.

Facebook Inc. will invest $5.7 billion in the U.S. social-networking giant's biggest deal since the 2014 purchase of WhatsApp as it seeks a broader foothold in its biggest global market. The U.S. company will buy about 10% of Jio Platforms, which brings together digital apps and a wireless platform under one umbrella, the Mumbai-based company said in a statement Wednesday.

Before Wednesday, Ambani -- who owns the world's largest oil refinery -- had declined by $14 billion on the index in 2020, the biggest dollar fall of anyone in Asia. Alibaba Group Holding Ltd.'s Ma, whose foundation this week donated 100 million masks to the World Health Organization to fight the Covid-19 pandemic, had lost almost $1 billion through Tuesday.

"At the core of our partnership is the commitment that Mark Zuckerberg, founder of Facebook, and I share for the all-around digital transformation of India," Ambani said in a web video posted on Jio's Facebook page, adding that Facebook's brands have become household names in India. "WhatsApp in particular, has entered our people's daily vocabulary in all the 23 official languages of India."

The partnership with Jio would allow Zuckerberg to step up his expansion in a country that is rapidly embracing online payment and e-commerce as more people get smartphones. Jio Infocomm quickly moved into a position of dominance by offering free plans and undercutting wireless market rivals.

With its half-billion internet users, the South Asian country is a key market for the world's largest technology companies, including Amazon.com Inc., Apple Inc., Microsoft Corp. and Alphabet Inc.'s Google. In India, Facebook has about 250 million users, while WhatsApp has more than 400 million.

That should help Jio bolster its reach, according to James Crabtree, author of 'The Billionaire Raj,' a book on the country's wealthiest people. But the transaction also shows the extent of Ambani's own influence, he said.

"This deal clearly shows that if you want to play big in Indian tech, you need to play nice with Mukesh Ambani."

Ambani's fortune rose about $4.7 billion to $49.2 billion on Wednesday, after Reliance Industries Ltd. gained 10%. The jump put Ambani about $3.2 billion ahead of China's Jack Ma, according to the Bloomberg Billionaires Index. The ranking updates after the close of each trading day in the U.S.

Facebook Inc. will invest $5.7 billion in the U.S. social-networking giant's biggest deal since the 2014 purchase of WhatsApp as it seeks a broader foothold in its biggest global market. The U.S. company will buy about 10% of Jio Platforms, which brings together digital apps and a wireless platform under one umbrella, the Mumbai-based company said in a statement Wednesday.

Before Wednesday, Ambani -- who owns the world's largest oil refinery -- had declined by $14 billion on the index in 2020, the biggest dollar fall of anyone in Asia. Alibaba Group Holding Ltd.'s Ma, whose foundation this week donated 100 million masks to the World Health Organization to fight the Covid-19 pandemic, had lost almost $1 billion through Tuesday.

"At the core of our partnership is the commitment that Mark Zuckerberg, founder of Facebook, and I share for the all-around digital transformation of India," Ambani said in a web video posted on Jio's Facebook page, adding that Facebook's brands have become household names in India. "WhatsApp in particular, has entered our people's daily vocabulary in all the 23 official languages of India."

The partnership with Jio would allow Zuckerberg to step up his expansion in a country that is rapidly embracing online payment and e-commerce as more people get smartphones. Jio Infocomm quickly moved into a position of dominance by offering free plans and undercutting wireless market rivals.

With its half-billion internet users, the South Asian country is a key market for the world's largest technology companies, including Amazon.com Inc., Apple Inc., Microsoft Corp. and Alphabet Inc.'s Google. In India, Facebook has about 250 million users, while WhatsApp has more than 400 million.

That should help Jio bolster its reach, according to James Crabtree, author of 'The Billionaire Raj,' a book on the country's wealthiest people. But the transaction also shows the extent of Ambani's own influence, he said.

"This deal clearly shows that if you want to play big in Indian tech, you need to play nice with Mukesh Ambani."

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.