How an obscure Indian cyber firm spied on politicians, investors through horoscopes and porn

News Network
June 27, 2020

Jun 27: Alittle-known Indian IT firm offered its hacking services to help clients spy on more than 10,000 email accounts over a period of seven years.

New Delhi-based BellTroX InfoTech Services targeted government officials in Europe, gambling tycoons in the Bahamas, and well-known investors in the United States including private equity giant KKR and short seller Muddy Waters, according to three former employees, outside researchers, and a trail of online evidence.

Aspects of BellTroX's hacking spree aimed at American targets are currently under investigation by U.S. law enforcement, five people familiar with the matter told Reuters. The U.S. Department of Justice declined to comment.

Reuters does not know the identity of BellTroX's clients. In a telephone interview, the company's owner, Sumit Gupta, declined to disclose who had hired him and denied any wrongdoing.

Muddy Waters founder Carson Block said he was "disappointed, but not surprised, to learn that we were likely targeted for hacking by a client of BellTroX." KKR declined to comment.

Researchers at internet watchdog group Citizen Lab, who spent more than two years mapping out the infrastructure used by the hackers, released a report that BellTroX employees were behind the espionage campaign.

"This is one of the largest spy-for-hire operations ever exposed," said Citizen Lab researcher John Scott-Railton.

Although they receive a fraction of the attention devoted to state-sponsored espionage groups or headline-grabbing heists, "cyber mercenary" services are widely used, he said. "Our investigation found that no sector is immune."

A cache of data reviewed by Reuters provides insight into the operation, detailing tens of thousands of malicious messages designed to trick victims into giving up their passwords that were sent by BellTroX between 2013 and 2020. The data was supplied on condition of anonymity by online service providers used by the hackers after Reuters alerted the firms to unusual patterns of activity on their platforms.

The data is effectively a digital hit list showing who was targeted and when. Reuters validated the data by checking it against emails received by the targets.

On the list: judges in South Africa, politicians in Mexico, lawyers in France and environmental groups in the United States. These dozens of people, among the thousands targeted by BellTroX, did not respond to messages or declined comment.

Reuters was not able to establish how many of the hacking attempts were successful.

BellTroX's Gupta was charged in a 2015 hacking case in which two U.S. private investigators admitted to paying him to hack the accounts of marketing executives. Gupta was declared a fugitive in 2017, although the U.S. Justice Department declined to comment on the current status of the case or whether an extradition request had been issued.

Speaking by phone from his home in New Delhi, Gupta denied hacking and said he had never been contacted by law enforcement. He said he had only ever helped private investigators download messages from email inboxes after they provided him with login details.

"I didn't help them access anything, I just helped them with downloading the mails and they provided me all the details," he told Reuters. "I am not aware how they got these details but I was just helping them with the technical support."

Reuters could not determine why the private investigators might need Gupta to download emails. Gupta did not return follow-up messages. Spokesmen for Delhi police and India's foreign ministry did not respond to requests for comment.

HOROSCOPES AND PORNOGRAPHY

Operating from a small room above a shuttered tea stall in a west-Delhi retail complex, BellTroX bombarded its targets with tens of thousands of malicious emails, according to the data reviewed by Reuters. Some messages would imitate colleagues or relatives; others posed as Facebook login requests or graphic notifications to unsubscribe from pornography websites.

Fahmi Quadir's New York-based short selling firm Safkhet Capital was among 17 investment companies targeted by BellTroX between 2017 and 2019. She said she noticed a surge in suspicious emails in early 2018, shortly after she launched her fund.

Initially "it didn't seem necessarily malicious," Quadir said. "It was just horoscopes; then it escalated to pornography."

Eventually the hackers upped their game, sending her credible-sounding messages that looked like they came from her coworkers, other short sellers or members of her family. "They were even trying to emulate my sister," Quadir said, adding that she believes the attacks were unsuccessful.

U.S. advocacy groups were also repeatedly targeted. Among them were digital rights organizations Free Press and Fight for the Future, both of whom have lobbied for net neutrality. The groups said a small number of employee accounts were compromised, but the wider organizations' networks were untouched. The spying on those groups was detailed in a report by the Electronic Frontier Foundation in 2017, but has not been publicly tied to BellTroX until now.

Timothy Karr, a director at Free Press, said his organization "sees an uptick in breach attempts whenever we're engaged in heated and high-profile public policy debates." Evan Greer, deputy director of Fight for the Future, said: "When corporations and politicians can hire digital mercenaries to target civil society advocates, it undermines our democratic process."

While Reuters was not able to establish who hired BellTroX to carry out the hacking, two former employees said the company and others like it were usually contracted by private investigators on behalf of business rivals or political opponents.

Bart Santos of San Diego-based Bulldog Investigations was one of a dozen private detectives in the United States and Europe who told Reuters they had received unsolicited advertisements for hacking services out of India - including one from a person who described himself as a former BellTroX employee. The pitch offered to carry out "data penetration" and "email penetration."

Santos said he ignored those overtures, but could understand why some people didn't. "The Indian guys have a reputation for customer service," he said.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
January 3,2020

Mumbai, Jan 3: The Shiv Sena on Friday targeted the Centre by questioning the "efficacy" of the 2016 surgical strike and said the perception that it would demoralise Pakistani terrorists remained an "illusion" as Indian soldiers continue to get killed in terror attacks in Kashmir.

Accusing the Modi government of boasting about how Pakistan was straightened out after the surgical strike, the Sena sought to know whether it has really happened.

It also observed that troubled borders were not good for the country's well-being.

The Sena's remarks come in the wake of the death of an Army soldier from Maharashtra, Naik Sandip Raghunath Sawant, who was killed during a counter-insurgency operation in Jammu and Kashmir on Wednesday.

"The New Year did not begin on a positive note in Kashmir. Our jawan from Satara, Sandip Sawant, attained martyrdom in Kashmir along with two other soldiers. In the last one month, seven to eight jawans from Maharashtra were killed in the line of duty. The Maha Vikas Aghadi government in Maharashtra is not responsible for this," the Sena said in an editorial in party mouthpiece 'Saamana'.

The party also questioned whether the situation in Kashmir has improved after the surgical strike and abrogation of Article 370 provisions.

The party, however, maintained that scrapping Article 370 was a good move.

India had conducted the surgical strike on September 29, 2016, across the Line of Control (LoC) as a response to a terrorist attack on an Indian Army base in Uri sector of Jammu and Kashmir earlier that month.

Without naming the Centre, the Sena alleged, "Circulating news that only the Pakistanis were getting killed in Kashmir will not change the reality as tricolour-draped bodies of Indian soldiers, like Sawant, are reaching their respective villages."

"There is a bloodshed along the Kashmir border and mounting anger among the families of martyred jawans. The perception that surgical strike will demoralise Pakistani terrorists has turned out to be an illusion. In fact, the (terror) attacks have increased," it added.

The Uddhav Thackeray-led party accused the ruling BJP of boasting about straightening out Pakistan after the surgical strike.

"But has Pakistan been really straightened out? Rather Pakistan has been indulging in ceasefire violations along the LoC every day," it added.

The Shiv Sena also questioned the government's claim that the situation in Kashmir was under control after the nullification of Article 370.

"It is good that Article 370 was scrapped. Before that, surgical strike was carried out in Pakistan. But has the situation in Kashmir improved? The terror attacks continue. It's only that there is a control in reporting (these incidents)," it said.

The Sena also alleged that there was no clarity as to what was transpiring in Kashmir after the scrapping of Article 370 and only the media reports of soldiers sacrificing their lives have been coming out from that state

In a veiled attack on the BJP, its erstwhile ally, the Sena, also accused it of exploiting the surgical strike for political gains.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
May 1,2020

Jeddah, May 1: The government of India and its diplomatic missions in the Gulf Cooperation Council (GCC) States have begun elaborate preparations for the massive evacuation of their nationals stranded or needing to return once the lockdown travel restrictions are lifted.

The Indian missions in Saudi Arabia, the United Arab Emirates (UAE), Kuwait, Bahrain, Oman and Qatar have started registration for the return of their nationals. The move coincides with the directive of New Delhi to the Indian Air Force and Navy to get their big engines ready to bring back citizens stuck in the GCC states.

India’s External Affairs Minister S. Jaishankar has stated that the Indian missions in the GCC states have been liaising with local authorities for repatriation of Indians. More than eight millions Indians work and live in the Gulf countries.

The Indian Embassy in Saudi Arabia said that it has issued directives to their nationals who seek repatriation to India to fill an application form so as to facilitate their travel when the authorities lift the travel restrictions. Similar advisories have also been issued by the embassies in other Gulf States.

The Riyadh Embassy said in a press statement that the purpose is only to collect data and no decision has been taken yet regarding resumption of flights to India.

The Embassy will make an announcement with regard to repatriation of Indian nationals when the government of India takes a decision in this regard, the statement said, adding that separate forms have to be filled for each individual, including Indian worker or his or her family members.

The Embassy is in the process of working out the modalities of evacuation of stranded Indians in line with the directions of the government of India, the statement pointed out.

The Embassy and the Consulate General in Jeddah are closely monitoring the situation and are taking all the required measures to ensure the welfare of Indian citizens.

The missions have taken all the necessary measures for the supply of food, medicines and other emergency assistance to Indians in need and that is in coordination and cooperation with volunteers of major community organizations across the Kingdom.

These initiatives have been accelerated following the interactions of Ambassador Dr. Ausaf Sayeed with community volunteers and social workers from all parts of the Kingdom. The Embassy has also been in touch with all major companies in the Kingdom that employed Indian workers to carry out regular monitoring of the workers’ health, especially in labor camps, and take all other precautionary and preventive measures to ensure their health and safety.

According to the plan drawn up by the government of India, the first commercial flights from the Gulf could start after May 3, if the nationwide lockdown restrictions are not extended.

INS Jalashwa, an amphibious assault ship, and two Magar class tank-landing ships are being readied for the evacuation purposes, India’s IANS reported.

These ships, which have a total capacity of 2,000 people, have started making arrangements as per the standard protocols laid out to deal with suspected coronavirus cases like social distancing and sanitization.

The Indian Air Force has been evacuating citizens from coronavirus hit countries such as China, Japan, Iran, Italy and Kuwait since January. The force has stated that it has kept C-17 Globemaster and C-130s on standby which can be used whenever they are required.

Apart from them, Air India flights are also being kept on standby to pick up stranded Indians from the GCC countries.

15 Indian fatalities in western region

Speaking to Saudi Gazette, Indian Consul General Mohammed Noor Rahman Sheikh said that as of Thursday a total of 15 Indian coronavirus fatalities were reported in the western region.

These included seven cases in Makkah, six in Madinah and two in Jeddah. Around 140 Indians have tested positive in the region where most of the coronavirus cases in the Kingdom have been reported.

He said that permission was not accorded from the Ministry of Haj and Umrah to use the Indian Haj mission facility in Makkah as the center to assist the community members with regard to the coronavirus related cases.

“Our medical in charge is in Makkah and with the support of some other staffers, he has been actively involved in lending a helping hand to those Indian nationals who are in distress,” he said.

“We are in regular contact with the Ministry of Health officials in ensuring quick medical assistance to those who are tested positive.” He said preparations are under way for repatriation of Indians once permission is ready to take them home. “We are maintaining a database of all those who contacted the consulate with a request for their repatriation,” he added.

Meanwhile, the bodies of two Indians from the southern state of Kerala who succumbed to the pandemic were buried in Makkah. Naletil Muhammad from Ancharakkandi of Kannoor district, a restaurant worker in Makkah, gave samples at King Faisal Hospital a few days ago after developing symptoms of the disease.

When the hospital authorities advised him to remain in medical isolation, he reportedly preferred to remain in isolation at his residence where he succumbed to the pandemic after a few days.

Muhammad’s two sons, who are working in Riyadh, alerted his colleagues when they failed to contact him over phone. They found him dead at his residence on Monday. Eventually, Ministry of Health officials sent all his six colleagues to medical isolation.

Kottuwala Ippu Musliyar from Thennala, Vengara in Malappuram district, was a well-known social worker in Makkah. He died of coronavirus at Hira Hospital on Wednesday after undergoing treatment for a couple of days.

Mujeeb Pukkottoor, a prominent Indian social worker and general secretary of Makkah chapter of Kerala Muslim Cultural Center, was authorized by their spouses to carry out their burial procedures.

Accordingly Muhammad was buried on Wednesday and Ippu Musliyar on Thursday at the designated area for the coronavirus deceased persons at Sharaie Cemetery in Makkah.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
June 8,2020

New Delhi, Jun 8: India on Monday reported the highest single-day spike of 9,983 more COVID-19 cases and 206 deaths in the last 24 hours.

With this, the country's coronavirus count has reached 2,56,611, including 1,25,381 active cases, according to the Ministry of Health and Family Welfare.

1,24,094 patients have been cured/discharged so far and 7,135 succumbed to the deadly virus. While one patient has migrated.

With 85,975 cases, Maharashtra is the worst-affected state in the country followed by Tamil Nadu at 31,667 cases.

A total of 1,08,048 samples were tested for coronavirus in the last 24 hours and overall 47,74,434 samples have been tested till now.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.