Appin was a New Delhi-based Indian hack-for-hire operation that Reuters described as pioneering India’s cyber-mercenary industry and spawning copycat firms. The company was run by brothers Rajat Khare and Anuj Khare and began as a technology training startup, but reporting cited in the content says it also operated a customer-facing intrusion service, including a portal dubbed "My Commando," through which clients could request hacks, track progress, and retrieve stolen data. Reuters reviewed Appin materials advertising capabilities including cyber spying, email monitoring, cyber warfare, and social engineering, and reported that Appin created malicious code and websites to support operations. The content states Appin targeted political leaders, executives, attorneys, journalists, activists, and other victims globally, and that Google observed Appin-linked actors targeting tens of thousands of Google email accounts over the last decade. Reuters reviewed logs showing about 70 clients, largely private investigators from the U.S., Britain, Switzerland, and other countries, seeking hacks of hundreds of targets. Reported victims and targeting included Chuck Randall of the Shinnecock Nation, Aegis-related targeting, and broader industrial espionage activity. The content also states that previously unconfirmed historical activity has since been attributed to Appin, including Operation Hangover and targeting involving human-rights-related malware with custom Mac malware. The content links Appin to credential theft and account compromise operations and describes broader hack-for-hire tradecraft consistent with phishing-based intrusions and data exfiltration for paying clients. Reuters also reported that Appin initially supported Indian government intelligence work through Appin Software Security Pvt. Ltd., also referred to as the Appin Security Group, and worked with India’s Research & Analysis Wing and Intelligence Bureau according to former insiders cited there. Reported activity included targeting Pakistani officials and using fake dating websites to lure Pakistani military officers. An Appin memo also described "Operation Rainbow" as penetrating Chinese military computers, although Reuters could not independently confirm that intrusion. The content further states that researchers from SentinelOne, Mandiant, and Symantec independently matched Appin-linked infrastructure to publicly known cyberespionage campaigns, and that Oslo-based Norman Shark publicly linked the 2013 Telenor intrusion to Appin. Reuters reported investigations in the U.S., Switzerland, Norway, and the Dominican Republic into Appin-linked intrusions, but said these largely ended without major enforcement outcomes against Appin leadership. The content also notes that Appin’s web presence faded after 2013 and that associated entities were rebranded, while alumni and successor or copycat firms continued similar activity. Google TAG said that since 2012 it has tracked an interwoven set of Indian hack-for-hire actors, many of whom previously worked for Appin and BellTroX, and linked former employees of Appin and BellTroX to Rebsec. Known aliases directly mentioned in the content are Appin and Appin Security Group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An India-based hack-for-hire organization tied to historical operations including Operation Hangover, industrial espionage, and targeting involving custom Mac malware against human rights-related victims.
India-based hack-for-hire / cyber-mercenary operation providing cyberespionage services at scale to private investigators, law firms, corporations, and (earlier) Indian government/intelligence customers. Operations included email account compromise, network intrusion, credential theft, and social-engineering-driven delivery of malicious links/sites; also ran a client-facing tasking portal ('My Commando') to manage intrusions and exfiltration via dead drops.
Indian hack-for-hire company described as pioneering the country’s hack-for-hire industry and spawning copycat firms.
Referenced as an Indian offensive security provider whose former employees are associated with Indian hack-for-hire activity clusters.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.