A bipartisan group of U.S. lawmakers has asked the Department of Commerce to add Indian hack-for-hire companies BellTroX, CyberRoot, and Sunkissed Organic Farms—formerly Appin—to the U.S. Entity List. The request alleges the firms spent more than a decade conducting cyberattacks and espionage against Americans, including business owners and lawyers, to obtain material intended to influence active litigation; it also alleges theft of data from thousands of U.S. victims and activity on behalf of the Qatari government.
The allegations build on reporting that mercenary hackers have been used to shape litigation disputes, as well as legal campaigns aimed at suppressing coverage of alleged cyber-mercenary activity through foreign-court actions. Entity List designation would restrict the firms' access to U.S. technology and exports, subject to licensing requirements. The Commerce Department had not said whether it would impose the requested restrictions.

See the reporting duties and controls this puts on the clock.
4 events from the most recent confirmed update back to the earliest known activity.
Senators Ron Wyden and Sheldon Whitehouse and Representative Pat Harrigan sent Commerce Secretary Howard Lutnick a letter urging the Department of Commerce to add BellTroX, CyberRoot, and Sunkissed Organic Farms (formerly Appin) to the U.S. Entity List. The department had not announced a decision at the time of reporting.
The Electronic Frontier Foundation defended Techdirt and the MuckRock Foundation against legal threats that it characterized as part of Appin's effort to suppress reporting on alleged mercenary hacking.
Appin obtained an Indian court order that temporarily required Reuters to remove reporting about the company. The order was later lifted and Reuters republished its report.
Citizen Lab published research uncovering Dark Basin, which it characterized as a massive hack-for-hire operation. This constitutes a new technical disclosure not represented in the existing timeline.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 13 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See what this changes for your reporting obligations and which controls it puts on the clock.
9 references tracked. Mallory keeps watching after this page renders.
techdirt.com
Open sourcecitizenlab.ca
Open sourcecyberscoop.com
Open sourcenextgov.com
Open sourcetechcrunch.com
Open sourcewyden.senate.gov
Open sourceeff.org
Open sourcereuters.com
Open sourcecitizenlab.ca
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.