Appin was an India-based offensive-security and hack-for-hire operation that marketed cyber-espionage, email-monitoring, social-engineering, and intrusion services to private investigators and other clients. It operated a client portal through which customers could request compromises, monitor work, and obtain stolen material. The operation has been linked to compromises of political figures, business executives, attorneys, journalists, and other individuals internationally, including the theft of corporate email from Telenor. Google tracked Appin-linked actors targeting tens of thousands of email accounts over approximately a decade. Appin-linked activity involved credential phishing and compromise of email and network accounts, followed by collection and exfiltration of victim data. The group has also been associated with Operation Hangover and targeted activity involving human-rights-related victims. Appin's business entities were subsequently rebranded: Appin Technology became Sunkissed Organic Farms, while Appin Software Security became Adaptive Control Security Global Corporate (ACSG). Appin alumni and related Indian hack-for-hire operators have continued to feature in reporting on the wider commercial intrusion ecosystem. Appin's founders denied involvement in illegal hacking and maintained that the company provided cybersecurity training and defensive services.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
India-based hack-for-hire operation alleged to conduct paid cyberattacks and espionage against Americans and FIFA officials, reportedly at the behest of the Qatari government. It is also accused of using legal pressure and foreign court actions to suppress reporting on its activities.
An India-based hack-for-hire organization tied to historical operations including Operation Hangover, industrial espionage, and targeting involving custom Mac malware against human rights-related victims.
India-based hack-for-hire / cyber-mercenary operation providing cyberespionage services at scale to private investigators, law firms, corporations, and (earlier) Indian government/intelligence customers. Operations included email account compromise, network intrusion, credential theft, and social-engineering-driven delivery of malicious links/sites; also ran a client-facing tasking portal ('My Commando') to manage intrusions and exfiltration via dead drops.
Indian hack-for-hire company described as pioneering the country’s hack-for-hire industry and spawning copycat firms.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.