How an obscure Indian cyber firm spied on politicians, investors through horoscopes and porn

News Network
June 27, 2020

Jun 27: Alittle-known Indian IT firm offered its hacking services to help clients spy on more than 10,000 email accounts over a period of seven years.

New Delhi-based BellTroX InfoTech Services targeted government officials in Europe, gambling tycoons in the Bahamas, and well-known investors in the United States including private equity giant KKR and short seller Muddy Waters, according to three former employees, outside researchers, and a trail of online evidence.

Aspects of BellTroX's hacking spree aimed at American targets are currently under investigation by U.S. law enforcement, five people familiar with the matter told Reuters. The U.S. Department of Justice declined to comment.

Reuters does not know the identity of BellTroX's clients. In a telephone interview, the company's owner, Sumit Gupta, declined to disclose who had hired him and denied any wrongdoing.

Muddy Waters founder Carson Block said he was "disappointed, but not surprised, to learn that we were likely targeted for hacking by a client of BellTroX." KKR declined to comment.

Researchers at internet watchdog group Citizen Lab, who spent more than two years mapping out the infrastructure used by the hackers, released a report that BellTroX employees were behind the espionage campaign.

"This is one of the largest spy-for-hire operations ever exposed," said Citizen Lab researcher John Scott-Railton.

Although they receive a fraction of the attention devoted to state-sponsored espionage groups or headline-grabbing heists, "cyber mercenary" services are widely used, he said. "Our investigation found that no sector is immune."

A cache of data reviewed by Reuters provides insight into the operation, detailing tens of thousands of malicious messages designed to trick victims into giving up their passwords that were sent by BellTroX between 2013 and 2020. The data was supplied on condition of anonymity by online service providers used by the hackers after Reuters alerted the firms to unusual patterns of activity on their platforms.

The data is effectively a digital hit list showing who was targeted and when. Reuters validated the data by checking it against emails received by the targets.

On the list: judges in South Africa, politicians in Mexico, lawyers in France and environmental groups in the United States. These dozens of people, among the thousands targeted by BellTroX, did not respond to messages or declined comment.

Reuters was not able to establish how many of the hacking attempts were successful.

BellTroX's Gupta was charged in a 2015 hacking case in which two U.S. private investigators admitted to paying him to hack the accounts of marketing executives. Gupta was declared a fugitive in 2017, although the U.S. Justice Department declined to comment on the current status of the case or whether an extradition request had been issued.

Speaking by phone from his home in New Delhi, Gupta denied hacking and said he had never been contacted by law enforcement. He said he had only ever helped private investigators download messages from email inboxes after they provided him with login details.

"I didn't help them access anything, I just helped them with downloading the mails and they provided me all the details," he told Reuters. "I am not aware how they got these details but I was just helping them with the technical support."

Reuters could not determine why the private investigators might need Gupta to download emails. Gupta did not return follow-up messages. Spokesmen for Delhi police and India's foreign ministry did not respond to requests for comment.

HOROSCOPES AND PORNOGRAPHY

Operating from a small room above a shuttered tea stall in a west-Delhi retail complex, BellTroX bombarded its targets with tens of thousands of malicious emails, according to the data reviewed by Reuters. Some messages would imitate colleagues or relatives; others posed as Facebook login requests or graphic notifications to unsubscribe from pornography websites.

Fahmi Quadir's New York-based short selling firm Safkhet Capital was among 17 investment companies targeted by BellTroX between 2017 and 2019. She said she noticed a surge in suspicious emails in early 2018, shortly after she launched her fund.

Initially "it didn't seem necessarily malicious," Quadir said. "It was just horoscopes; then it escalated to pornography."

Eventually the hackers upped their game, sending her credible-sounding messages that looked like they came from her coworkers, other short sellers or members of her family. "They were even trying to emulate my sister," Quadir said, adding that she believes the attacks were unsuccessful.

U.S. advocacy groups were also repeatedly targeted. Among them were digital rights organizations Free Press and Fight for the Future, both of whom have lobbied for net neutrality. The groups said a small number of employee accounts were compromised, but the wider organizations' networks were untouched. The spying on those groups was detailed in a report by the Electronic Frontier Foundation in 2017, but has not been publicly tied to BellTroX until now.

Timothy Karr, a director at Free Press, said his organization "sees an uptick in breach attempts whenever we're engaged in heated and high-profile public policy debates." Evan Greer, deputy director of Fight for the Future, said: "When corporations and politicians can hire digital mercenaries to target civil society advocates, it undermines our democratic process."

While Reuters was not able to establish who hired BellTroX to carry out the hacking, two former employees said the company and others like it were usually contracted by private investigators on behalf of business rivals or political opponents.

Bart Santos of San Diego-based Bulldog Investigations was one of a dozen private detectives in the United States and Europe who told Reuters they had received unsolicited advertisements for hacking services out of India - including one from a person who described himself as a former BellTroX employee. The pitch offered to carry out "data penetration" and "email penetration."

Santos said he ignored those overtures, but could understand why some people didn't. "The Indian guys have a reputation for customer service," he said.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
April 23,2020

New Delhi, Apr 23: The nationwide lockdown in India which started about a month ago has impacted nearly 40 million internal migrants, the World Bank has said.

The lockdown in India has impacted the livelihoods of a large proportion of the country's nearly 40 million internal migrants. Around 50,000 60,000 moved from urban centers to rural areas of origin in the span of a few days, the bank said in a report released on Wednesday.

According to the report -- 'COVID-19 Crisis Through a Migration Lens' -- the magnitude of internal migration is about two-and-a-half times that of international migration.

Lockdowns, loss of employment, and social distancing prompted a chaotic and painful process of mass return for internal migrants in India and many countries in Latin America, it said.

Thus, the COVID-19 containment measures might have contributed to spreading the epidemic, the report said.

Governments need to address the challenges facing internal migrants by including them in health services and cash transfer and other social programmes, and protecting them from discrimination, it said.

World Bank said that coronavirus crisis has affected both international and internal migration in the South Asia region.

As the early phases of the crisis unfolded, many international migrants, especially from the Gulf countries, returned to countries such as India, Pakistan, and Bangladesh until travel restrictions halted these flows.

Some migrants had to be evacuated by governments, such as those of China and Iran, it said.

Before the coronavirus crisis, migrant outflows from the region were robust, the report said.

The number of recorded, primarily low-skilled emigrants from India and Pakistan rose in 2019 relative to the prior year but is expected to decline in 2020 due to the pandemic and oil price declines impacting the Gulf countries.

In India, the number of low-skilled emigrants seeking mandatory clearance for emigration rose slightly by eight percent to 368,048 in 2019.

In Pakistan, the number of emigrants jumped 63 per cent to 6,25,203 in 2019, largely due to a doubling of emigration to Saudi Arabia, it said.

According to the bank, migration flows are likely to fall, but the stock of international migrants may not decrease immediately, since migrants cannot return to their countries due to travel bans and disruption to transportation services.

In 2019, there were around 272 million international migrants.

The rate of voluntary return migration is likely to fall, except in the case of a few cross-border migration corridors in the South (such as Venezuela-Colombia, Nepal-India, Zimbabwe South Africa, Myanmar-Thailand), it said.

Migrant workers tend to be vulnerable to the loss of employment and wages during an economic crisis in their host country, more so than native-born workers.

Lockdowns in labour camps and dormitories can also increase the risk of contagion among migrant workers.

Many migrants have been stranded due to the suspension of transport services. Some host countries have granted visa extensions and temporary amnesty to migrant workers, and some have suspended the involuntary return of migrants, it said.

Observing that government policy responses to the COVID-19 crisis have largely excluded migrants and their families back home, the World Bank said there is a strong case for including migrants in the near-term health strategies of all countries, given the externalities associated with the health status of an entire population in the face of a highly contagious pandemic.

The Bank said governments would do well to consider short, medium and long-term interventions to support stranded migrants, remittance infrastructure, loss of subsistence income for families back home, and access to health, housing, education, and jobs for migrant workers in host/transit countries and their families back home.

The pandemic has also highlighted the global shortage of health professionals and an urgent need for global cooperation and long-term investments in medical training, it said.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
March 5,2020

Mumbai, Mar 5: Jet Airways founder Naresh Goyal and few others have been booked by the ED in a money laundering case even as the agency is conducting searches at his premises, officials said on Thursday.

They said a criminal case against the former chairman of the airlines has been filed under the Prevention of Money Laundering Act (PMLA) after taking cognisance of a recent Mumbai Police FIR filed against him.

The Enforcement Directorate carried out raids at Goyal's premises in Mumbai on Wednesday and also questioned him after filing the case, they said.

The action is continuing, they added.

The Mumbai Police FIR pertains to charges of alleged fraud by Goyal and others against a Mumbai-based travel company.

Goyal has earlier been grilled by the central probe agency in a case filed under the Foreign Exchange Management Act (FEMA) in September last year.

The agency had carried out similar raids, under the FEMA, in August last year against Goyal, his family and others.

ED has alleged in the past that the businessman's empire had 19 privately-held companies, five of which were registered abroad.

The agency is probing charges that these firms allegedly carried out “doubtful” transactions under the guise of selling, distribution and operating expenses.

The ED suspects that expenses at these companies were allegedly booked at fake and high costs and as a result, they “projected” huge losses.

Alleged shady aircraft lease transactions with non-existent offshore entities are also under the ED scanner and it is suspected that Jet Airways made payments for lease rental to “ghost firms”, which purportedly routed the ill-gotten money in Goyal's companies.

A full-service carrier, Jet Airways shut its operations in April last year after running out of cash.

A month earlier, Goyal had stepped down as the chairman of Jet Airways.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
January 31,2020

New Delhi, Jan 31: Substantial competition and low tariff rates by telecom operators since 2016 have led to a financial stress in the sector, the Economic Survey said on Friday.

The data price in the country came down by over 99 per cent during 2016-2019, making it among the lowest tariff in the world, according to the survey.

"Since 2016, the sector has witnessed substantial competition and price cutting by the telecom service providers (TSPs), creating financial stress in the sector. As a result, the sector is experiencing consolidation. While some operators have filed for bankruptcy, others have merged, in their quest to improve viability," the survey report said.

In April-June 2019, the price of data was Rs 7.7 per gigabyte (GB) as compared to Rs 200 per GB in June 2016, it added.

"The Average Revenue Per User (ARPU) for GSM based mobile services has also gone down substantially from Rs 126 in June 2016 to Rs 74.30 in June 2019," the survey said.

The tariff war started in the market with entry of new telecom operator Reliance Jio in September 2016.

"BSNL and MTNL are also affected by the tariff war that has impacted their cash flow resulting in mounting losses," the survey said.

The financial health of the public sector telecom firms plummeted to a level where they have been finding hard to pay employees salaries in time.

The government has drawn up a plan to revive these PSUs which is still in works.

The revival plan consists of several measures, including reduction of staff cost through voluntary retirement scheme, allotment of spectrum for 4G services, monetisation of land and building, tower and fibre assets of BSNL and MTNL, debt restructuring through sovereign guarantee bonds and ''in-principle'' approval for merger of BSNL and MTNL.

The survey said that the wireless telephony now constitutes 98.27 per cent of all subscriptions whereas share of landline telephones now stands at only 1.73 per cent where market share is dominated by private sector players.

"The overall tele-density in India stands at 90.45 per cent, the rural tele-density being 57.35 per cent and urban teledensity being 160.71 per cent at the end of September 2019. The private sector dominates with a share of 88.81 per cent (106.06 crore connections) at the end of September, 2019 while the share of public sector was 11.19 per cent (13.36 crore connections)," the survey said.

The lower price of data has also lead in surge of broadband connections and average consumption of the internet.

Total broadband connections increased by about ten times, from 6.1 crore in 2014 to 59.46 crore in June 2019, the survey said.

The number of internet subscribers (both broadband and narrowband put together) stood at 66.53 crore at the end of June 2019 as compared to 25.16 crore in 2014.

The number of mobile internet subscribers was 64.36 lakh at the end of June 2019 while the number of wireline internet subscribers was 2.17 crore.

"India is now the global leader in monthly data consumption, with average consumption per subscriber per month increasing 157 times from 62 MB in 2014 to 9.8 GB in June 2019. The cost of data has also reduced substantially, enabling affordable internet access for millions of citizens," the survey said.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.