Human rights defenders in India were targeted in a coordinated spearphishing operation that used impersonation lures and links hosted on Firefox Send to deliver NetWire spyware to Windows systems. Amnesty International and Citizen Lab said at least nine activists, lawyers, academics, and a journalist connected to advocacy or legal work around the Bhima Koregaon 11 were targeted between January and October 2019, in what researchers assessed was an unlawful surveillance effort rather than ordinary cybercrime. Technical analysis tied the activity to NetWire payloads communicating with researchplanet.zapto[.]org over port 1810, and the report noted that some of the same individuals had also previously been targeted with Pegasus spyware.
A separate but related campaign described by Cisco Talos showed continued use of NetWireRAT in targeted attacks across the Indian subcontinent, this time aimed at Indian government employees and military personnel. Active since late 2020, the operation used malicious Office documents, archives, compromised websites, and fake domains, with lures themed around Indian government matters such as the Kavach two-factor authentication application; operators also deployed WarzoneRAT, persistence mechanisms, process hollowing, and custom file-enumerator malware. Talos said the tactics and lures resembled activity linked to Transparent Tribe and SideCopy, highlighting sustained use of commercial remote-access malware in espionage-focused campaigns against Indian civil society and state-linked targets.

TTPs, infrastructure, and targeting history in one profile.
9 events from the most recent confirmed update back to the earliest known activity.
In June 2021, the attackers experimented with using Pastebin as a platform to host payloads. Talos documented this as part of the campaign's evolving infrastructure and delivery methods.
In May 2021, the operators used a C# downloader that contacted a decoy URL and only executed malicious logic when the communication failed. This marked a change in the campaign's delivery technique.
During March and April 2021, the attackers used downloader malware that fetched and executed RAT payloads from remote locations. Early variants used RunPE DLLs to inject malware into processes such as InstallUtil.exe.
Cisco Talos said the earliest observed instance of Operation Armor Piercer dated to December 2020, targeting Indian government employees and military personnel. The campaign used malicious Office documents and archives to deliver NetWireRAT and WarzoneRAT.
Amnesty International reported that three of the nine NetWire targets—Shalini Gera, Nihal Singh Rathod, and Degree Prasad Chouhan—were also targeted in 2019 with NSO Group's Pegasus spyware, indicating a broader pattern of surveillance against the same community. The report also noted Pegasus targeting of Anand Teltumbde.
Between January and October 2019, a coordinated spearphishing campaign targeted at least nine human rights defenders in India, including activists, lawyers, academics, and a journalist. The emails attempted to install NetWire spyware on Windows systems using impersonation themes and malicious links.
Cisco Talos disclosed Operation Armor Piercer as an ongoing campaign active since late 2020 that targeted Indian government and military personnel with NetWireRAT and WarzoneRAT. Talos said the lures, themes, and infrastructure resembled activity associated with Transparent Tribe and SideCopy.
Amnesty International and Citizen Lab reported a coordinated spyware operation targeting Indian human rights defenders and linked it to NetWire malware and related infrastructure. The researchers said the activity appeared intended for unlawful surveillance rather than ordinary cybercrime.
FireEye published research on APT33, describing Iranian cyber-espionage activity targeting aerospace and energy organizations and noting ties to destructive malware. The provided reference does not include further dated event details beyond the publication itself.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 202 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
blog.talosintelligence.com
Open sourceamnesty.org
Open sourcefireeye.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.