Rebsec is an Indian hack-for-hire and corporate espionage firm linked to former employees of Appin and Belltrox. It has been identified as part of the broader Indian private-sector intrusion ecosystem that conducts operations on behalf of paying clients, including corporate espionage and account-compromise campaigns. The group is associated with opportunistic exploitation of known security flaws and with credential-phishing operations designed to gain access to victim accounts and exfiltrate information. Rebsec operates in an ecosystem known for broad, client-driven targeting rather than a single ideological mission. Reported targeting linked to this Indian hack-for-hire cluster includes government, healthcare, and telecommunications organizations in the Gulf region, as well as commercial entities such as information technology, education, fintech, and retail-related organizations in multiple countries. The wider ecosystem has also targeted journalists, activists, NGOs, and other high-risk individuals. Tactics associated with this cluster include initial access through credential phishing, compromise of webmail and cloud accounts, and data exfiltration for clients. The surrounding Indian hack-for-hire ecosystem has also been observed using intermediaries such as private investigators and freelance operators. Rebsec is notable for openly advertising corporate espionage services, distinguishing it as a commercial intrusion provider rather than a state-directed espionage unit.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.