Citizen Lab and NortonLifeLock linked the Dark Basin hacking campaign with high confidence to Delhi-based BellTroX InfoTech Services, exposing a large-scale hack-for-hire operation that targeted thousands of people and organizations across six continents. Reported victims included journalists, advocacy groups, elected officials, senior government personnel, hedge funds, legal and energy firms, and U.S. nonprofits focused on climate change and net neutrality. Investigators said the campaign relied on tailored phishing emails, fake Google News alerts, spoofed Twitter direct messages, and shortened links using Indian-themed words such as Holi and Rangoli to lure targets into credential theft and account compromise.
The reporting placed BellTroX at the center of a broader narrative about an Indian cyber-mercenary ecosystem in which private firms allegedly provide offensive cyber services to commercial and political clients, including interests in the Gulf. Later commentary cited BellTroX alongside other India-linked operators and firms accused of phishing, surveillance, disinformation, and related abuses, arguing that weak oversight and opaque client relationships have allowed hack-for-hire activity to persist. Citizen Lab said it could not conclusively identify Dark Basin's clients, but it notified hundreds of affected individuals and institutions and shared evidence with the U.S. Department of Justice.

Get the infrastructure and lures behind it.
4 events from the most recent confirmed update back to the earliest known activity.
Citizen Lab said it shared evidence from its investigation with the U.S. Department of Justice and notified hundreds of affected individuals and institutions. It also said it could not conclusively identify the clients behind the operation.
The reporting disclosed that Dark Basin targeted thousands of individuals and organizations across six continents, including journalists, advocacy groups, government officials, businesses, hedge funds, legal and energy sector entities, and U.S. nonprofits. The operation reportedly used tailored phishing emails, fake Google News alerts, fake Twitter direct messages, and themed URL shorteners.
Citizen Lab reported with high confidence that Delhi-based Belltrox Infotech Services was connected to the Dark Basin hack-for-hire operation. It said the conclusion was supported by work with NortonLifeLock that connected Dark Basin activity to Belltrox employees.
Citizen Lab said it began investigating the Dark Basin operation in 2017 after a journalist reported phishing attempts. The investigation later expanded to a broader hack-for-hire campaign targeting thousands of individuals and institutions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
6 references tracked. Mallory keeps watching after this page renders.
mahdiabbastech.medium.com
Open sourcemahdiabbastech.medium.com
Open sourcemahdiabbastech.medium.com
Open sourceweb.archive.org
Open sourceredcanary.com
Open sourcecitizenlab.ca
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.