Dark Basin, also tracked as Mercenary.Amanda, is an India-linked commercial hack-for-hire operation attributed with high confidence to BellTroX InfoTech Services, also known as BellTroX D|G|TAL Security. Active by at least the mid-2010s and publicly exposed in 2020, it conducted large-scale, highly tailored credential-phishing campaigns against thousands of individuals and hundreds of organizations across six continents. Its targets included civil-society and environmental advocacy organizations, journalists, elected and government officials, prosecutors, law firms, financial institutions, hedge funds, short sellers, corporate and offshore-finance entities, and energy-sector organizations. Prominent targeting clusters included organizations associated with the #ExxonKnew campaign, net-neutrality advocates, and people reporting on or investigating Wirecard. The operation used self-hosted URL-shortening services and customized spear-phishing lures impersonating trusted contacts, news and social-media services, and webmail platforms. These links led to cloned authentication pages designed to collect usernames and passwords. Dark Basin demonstrated sustained targeting, repeatedly sending varied lures to selected victims over extended periods. Evidence indicates that operators obtained credentials and accessed some victim accounts using commercial VPN services. Attribution to BellTroX was supported by overlap in phishing infrastructure, operational timing consistent with India Standard Time, employee activity, and use of personal materials in testing and lure development. Available evidence does not conclusively identify the end clients responsible for particular campaigns, including those involving ExxonKnew-related organizations or Wirecard critics.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
13 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Hack-for-hire operation linked to BellTroX InfoTech Services and related entities. It conducted targeted espionage against U.S. citizens, businesses, lawyers representing them, and advocacy nonprofits.
A large hack-for-hire mercenary phishing operation that targeted critics of Wirecard, environmental NGOs involved in the ExxonKnew campaign, journalists, financial actors, political targets, and others in order to steal email credentials and gather intelligence for clients.
Hack-for-hire espionage campaign conducting large-scale phishing and email account targeting worldwide for corporate and other clients.
Commercial espionage operation conducted on behalf of clients seeking advantage in political, legal, and financial disputes.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.