<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://indianpedia.org/index.php?action=history&amp;feed=atom&amp;title=Dark_Basin</id>
	<title>Dark Basin - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://indianpedia.org/index.php?action=history&amp;feed=atom&amp;title=Dark_Basin"/>
	<link rel="alternate" type="text/html" href="https://indianpedia.org/index.php?title=Dark_Basin&amp;action=history"/>
	<updated>2026-08-02T12:24:41Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.45.4</generator>
	<entry>
		<id>https://indianpedia.org/index.php?title=Dark_Basin&amp;diff=430186&amp;oldid=prev</id>
		<title>Ajay Kumar at 18:40, 25 September 2023</title>
		<link rel="alternate" type="text/html" href="https://indianpedia.org/index.php?title=Dark_Basin&amp;diff=430186&amp;oldid=prev"/>
		<updated>2023-09-25T18:40:02Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Infobox organization&lt;br /&gt;
| name = Dark Basin&lt;br /&gt;
| native_name =&lt;br /&gt;
| native_name_lang =&lt;br /&gt;
| named_after = &lt;br /&gt;
| image = &lt;br /&gt;
| alt = &lt;br /&gt;
| formation =&lt;br /&gt;
| type = [[Advanced persistent threat]]&lt;br /&gt;
| purpose = [[Cyberespionage]]&lt;br /&gt;
| motto = &lt;br /&gt;
| part of =&lt;br /&gt;
| region = [[India]]&lt;br /&gt;
| methods = [[Spear phishing]]&lt;br /&gt;
| membership = &lt;br /&gt;
| language =&lt;br /&gt;
| parent_organization = BellTroX InfoTech Services&lt;br /&gt;
| affiliations = [[Wirecard]], [[ExxonMobil]]&lt;br /&gt;
| formerly =&lt;br /&gt;
| website = &lt;br /&gt;
| remarks =&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{short description|Cybercrime organization}}&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Dark Basin&amp;#039;&amp;#039;&amp;#039; is a hack-for-hire group, discovered in 2017 by [[Citizen Lab]].&amp;lt;ref name=&amp;quot;cl&amp;quot;&amp;gt;{{Cite web |last=Scott-Railton |first=John |last2=Hulcoop |first2=Adam |last3=Razzak |first3=Bahr Abdul |last4=Marczak |first4=Bill |last5=Anstis |first5=Siena |last6=Deibert |first6=Ron |date=2020-06-09 |title=Dark Basin - Uncovering a Massive Hack-For-Hire Operation |url=https://citizenlab.ca/2020/06/dark-basin-uncovering-a-massive-hack-for-hire-operation/ |url-status=live |archive-url=https://web.archive.org/web/20200930184856/https://citizenlab.ca/2020/06/dark-basin-uncovering-a-massive-hack-for-hire-operation/ |archive-date=2020-09-30 |access-date=2021-02-28 |publisher=[[Citizen Lab]]}}&amp;lt;/ref&amp;gt; They are suspected to have acted on the behalf of companies such as [[Wirecard]]&amp;lt;ref name=&amp;quot;npr&amp;quot;&amp;gt;{{Cite news |last=Rosin |first=Hanna |date=2020-06-09 |title=Dark Basin: Global Hack-For-Hire Organization That Targeted Thousands Over The Years |work=[[All Things Considered]] |publisher=[[NPR]] |url=https://www.npr.org/2020/06/09/873349773/dark-basin-global-hack-for-hire-organization-that-targeted-thousands-over-the-ye |url-status=live |access-date=2021-02-28 |archive-url=https://web.archive.org/web/20201115130625/https://www.npr.org/2020/06/09/873349773/dark-basin-global-hack-for-hire-organization-that-targeted-thousands-over-the-ye |archive-date=2020-11-15}}&amp;lt;/ref&amp;gt; and [[ExxonMobil]].&amp;lt;ref&amp;gt;{{Cite news |last=Murphy |first=Paul |date=2020-06-09 |title=Paid hackers targeted thousands of people and hundreds of institutions worldwide, report says |work=[[Financial Times]] |url=https://www.latimes.com/world-nation/story/2020-06-09/paid-hackers-dark-basin-targeted-thousands-people-hundreds-institutions |url-status=live |access-date=2021-02-28 |archive-url=https://web.archive.org/web/20200626130949/https://www.latimes.com/world-nation/story/2020-06-09/paid-hackers-dark-basin-targeted-thousands-people-hundreds-institutions |archive-date=2020-06-26 |via=the &amp;#039;&amp;#039;[[Los Angeles Times]]&amp;#039;&amp;#039;}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Background ==&lt;br /&gt;
In 2015, Matthew Earl, a managing partner at ShadowFall Capital &amp;amp; Research, began to study [[Wirecard AG]] hoping to [[Short (finance)|short sell]] them. Wirecard had just announced the purchase of Great Indian Retail Group for $254 million,&amp;lt;ref&amp;gt;{{Cite news |date=2015-10-27 |title=Wirecard buys Great Indian Retail Group payments business |work=[[Reuters]] |url=https://www.reuters.com/article/us-wirecard-acquisition-india/wirecard-buys-great-indian-retail-group-payments-business-idUSKCN0SL1L520151027 |url-status=live |access-date=2021-02-28 |archive-url=https://web.archive.org/web/20210301025220/https://www.reuters.com/article/us-wirecard-acquisition-india/wirecard-buys-great-indian-retail-group-payments-business-idUSKCN0SL1L520151027 |archive-date=2021-03-01}}&amp;lt;/ref&amp;gt; which seemed overpriced to Earl. In February 2016, he started to write publicly about his discoveries under the alias Zatarra Research &amp;amp; Investigations,&amp;lt;ref&amp;gt;{{Cite news |last=O&amp;#039;Donnell |first=John |date=2020-07-16 |title=Germany&amp;#039;s long, lonely campaign: Battling Wirecard&amp;#039;s short sellers |work=[[Reuters]] |url=https://www.reuters.com/article/us-wirecard-accounts-germany-insight/germanys-long-lonely-campaign-battling-wirecards-short-sellers-idUSKCN24H0KM |url-status=live |access-date=2021-02-28 |archive-url=https://web.archive.org/web/20201119071324/https://www.reuters.com/article/us-wirecard-accounts-germany-insight/germanys-long-lonely-campaign-battling-wirecards-short-sellers-idUSKCN24H0KM |archive-date=2020-11-19}}&amp;lt;/ref&amp;gt; accusing Wirecard of corruption, corporate fraud, and [[money laundering]].&amp;lt;ref&amp;gt;{{Cite news |last=Davies |first=Paul J. |date=2020-06-22 |title=Short sellers made $2.6 bln off Wirecard plunge |publisher=[[MarketWatch]] |url=https://www.marketwatch.com/story/short-sellers-made-26-bln-off-wirecard-plunge-2020-06-22 |url-status=live |access-date=2021-02-28 |archive-url=https://web.archive.org/web/20210205050934/https://www.marketwatch.com/story/short-sellers-made-26-bln-off-wirecard-plunge-2020-06-22 |archive-date=2021-02-05}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Soon after, the identity of Zatarra Research &amp;amp; Investigations was revealed online, along with surveillance pictures of Earl in front of his house. Earl quickly realized that he was being followed. Employees from [[Jones Day]], a law firm representing Wirecard,&amp;lt;ref&amp;gt;{{Cite news |last=Davies |first=Paul J. |last2=Chung |first2=Juliet |date=2020-06-20 |title=Short Sellers Made $2.6 Billion Off Wirecard&amp;#039;s Plunge, but Not Without Scars |work=[[The Wall Street Journal]] |url=https://www.wsj.com/articles/short-sellers-made-2-6-billion-off-wirecards-plunge-but-not-without-scars-11592654586 |url-status=live |url-access=subscription |access-date=2021-02-28 |archive-url=https://archive.today/20200620170207/https://www.wsj.com/articles/short-sellers-made-2-6-billion-off-wirecards-plunge-but-not-without-scars-11592654586 |archive-date=2020-06-20}}&amp;lt;/ref&amp;gt; came to visit Earl and gave him a letter, accusing him of collusion, conspiracy, defamation, libel, and market manipulation.&amp;lt;ref name=&amp;quot;dnd&amp;quot;&amp;gt;{{Cite web |date=2020-10-24 |title=Dark Basin – Darknet Diaries |url=https://darknetdiaries.com/transcript/79/ |publisher=[[Darknet Diaries]]}}&amp;lt;/ref&amp;gt; Earl also started to receive targeted [[phishing]] emails, appearing to be from his friends and family members.&amp;lt;ref name=&amp;quot;npr&amp;quot; /&amp;gt; In the spring of 2017, Earl shared those emails with [[Citizen Lab]], a research laboratory specializing in information control.&amp;lt;ref name=&amp;quot;dnd&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Citizen Lab&amp;#039;s investigation ==&lt;br /&gt;
&lt;br /&gt;
=== Initial findings ===&lt;br /&gt;
&lt;br /&gt;
Citizen Lab discovered that the attackers were using a custom [[URL shortening|URL shortener]] that allowed [[enumeration]], giving them access to a list of 28,000 [[URL|URLs]]. Some of those URLs redirected to websites looking like [[Gmail]], [[Facebook]], [[LinkedIn]], [[Dropbox (service)|Dropbox]] or various webmails – each page customized with the name of the victim, asking the user to re-enter their password.&amp;lt;ref&amp;gt;{{Cite web |last=Galperin |first=Eva |last2=Quintin |first2=Cooper |date=2017-09-27 |title=Phish For the Future |url=https://www.eff.org/deeplinks/2017/09/phish-future |url-status=live |archive-url=https://web.archive.org/web/20210116110032/https://www.eff.org/deeplinks/2017/09/phish-future |archive-date=2021-01-16 |access-date=2021-02-28 |publisher=[[Electronic Frontier Foundation]]}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Citizen Lab baptized this hacker group &amp;#039;Dark Basin&amp;#039; and identified several clusters among the victims:&amp;lt;ref name=&amp;quot;cl&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* American environmental organizations linked to the [[ExxonMobil climate change controversy|#ExxonKnew campaign]]:&amp;lt;ref&amp;gt;{{Cite news |last=Hong |first=Nicole |last2=Meier |first2=Barry |last3=Bergman |first3=Ronen |date=2020-06-10 |title=Environmentalists Targeted Exxon Mobil. Then Hackers Targeted Them. |work=[[The New York Times]] |url=https://www.nytimes.com/2020/06/09/nyregion/exxon-mobil-hackers-greenpeace.html |url-status=live |url-access=limited |access-date=2021-02-28 |archive-url=https://web.archive.org/web/20210201145437/https://www.nytimes.com/2020/06/09/nyregion/exxon-mobil-hackers-greenpeace.html |archive-date=2021-02-01}}&amp;lt;/ref&amp;gt; [[Rockefeller Brothers Fund]], Climate Investigations Center, [[Greenpeace]], [[Center for International Environmental Law]], Oil Change International, [[Public Citizen]], [[Conservation Law Foundation]], [[Union of Concerned Scientists]], M+R Strategic Services or [[350.org]]&lt;br /&gt;
* US media outlets&lt;br /&gt;
* Hedge funds, short sellers and financial journalists&lt;br /&gt;
* International banks and investment firms&lt;br /&gt;
* Legal firms in the [[United States|US]], [[United Kingdom|UK]], [[Israel]], [[France]], [[Belgium]], [[Norway]], [[Switzerland]], [[Iceland]], [[Kenya]], and [[Nigeria]]&lt;br /&gt;
* Petroleum and energy companies&lt;br /&gt;
* Eastern European, Central European and Russian oligarchs&lt;br /&gt;
* Well-resourced people involved in divorces or other legal matters&lt;br /&gt;
&lt;br /&gt;
The variety of targets made Citizen Lab think of a mercenary activity. The research laboratory confirmed that some of these attacks were successful.&lt;br /&gt;
&lt;br /&gt;
=== Links to India ===&lt;br /&gt;
&lt;br /&gt;
Several clues allowed Citizen Lab to assert &amp;#039;&amp;#039;with high confidence&amp;#039;&amp;#039; that Dark Basin was based in [[India]].&amp;lt;ref name=&amp;quot;cl&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Working hours ====&lt;br /&gt;
&lt;br /&gt;
Timestamps in Dark Basin phishing emails were consistent with working hours in India, which has only one timezone: [[UTC+5:30]].&amp;lt;ref name=&amp;quot;cl&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Cultural references ====&lt;br /&gt;
&lt;br /&gt;
The instances of the URL shortening service used by Dark Basin had names related to [[Culture of India|Indian culture]]: [[Holi]], Rongali and Pochanchi.&amp;lt;ref name=&amp;quot;cl&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Phishing kit ====&lt;br /&gt;
&lt;br /&gt;
Dark Basin let their phishing kit source code, including some log files, available online. The source code was configured to print timestamps in [[Indian Standard Time|India&amp;#039;s timezone]]. The log file, that showed some testing activity, included an [[IP address]] based in India.&amp;lt;ref name=&amp;quot;cl&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Links to BellTroX ===&lt;br /&gt;
&lt;br /&gt;
Citizen Lab believes with high confidence, that BellTroX, also known as BellTroX InfoTech Services and BellTroX D|G|TAL Security, is the company behind Dark Basin.&amp;lt;ref name=&amp;quot;cl&amp;quot; /&amp;gt; BellTroX, a [[New Delhi|Delhi]]-based company,&amp;lt;ref name=&amp;quot;Stubbs-2020&amp;quot;&amp;gt;{{Cite news |last=Stubbs |first=Jack |last2=Satter |first2=Raphael |last3=Bing |first3=Christopher |date=9 June 2020 |title=Obscure Indian cyber firm spied on politicians, investors worldwide |work=[[Reuters]] |url=https://www.reuters.com/article/us-india-cyber-mercenaries-exclusive/exclusive-obscure-indian-cyber-firm-spied-on-politicians-investors-worldwide-idUSKBN23G1GQ |url-status=live |archive-url=https://web.archive.org/web/20210126014516/https://www.reuters.com/article/us-india-cyber-mercenaries-exclusive/exclusive-obscure-indian-cyber-firm-spied-on-politicians-investors-worldwide-idUSKBN23G1GQ |archive-date=26 January 2021}}&amp;lt;/ref&amp;gt; advertises on its website doing activities such as [[penetration testing]], certified [[ethical hacking]], and medical transcription. BellTroX employees are described as noisy&amp;lt;ref name=&amp;quot;cl&amp;quot; /&amp;gt; and were often posting publicly about their illegal activities.&amp;lt;ref name=&amp;quot;cl&amp;quot; /&amp;gt; BellTroX&amp;#039;s founder Sumit Guptra&amp;lt;ref&amp;gt;{{Cite news |last=Kumar |first=Ankit |date=2020-06-09 |title=Dark Basin: Delhi-based &amp;quot;Hack-for-Hire&amp;quot; firm exposed for hacking politicians, non-profits globally |work=[[India Today]] |url=https://www.indiatoday.in/india/story/dark-basin-delhi-based-hack-for-hire-firm-exposed-for-hacking-politicians-non-profits-globally-1687292-2020-06-09 |url-status=live |access-date=2021-02-28 |archive-url=https://web.archive.org/web/20200627075331/https://www.indiatoday.in/india/story/dark-basin-delhi-based-hack-for-hire-firm-exposed-for-hacking-politicians-non-profits-globally-1687292-2020-06-09 |archive-date=2020-06-27}}&amp;lt;/ref&amp;gt; has been previously indicted and charged in the [[United States]] for a hack-for-hire scheme on the behalf of [[ViSalus#Racketeering|ViSalus]].&amp;lt;ref&amp;gt;{{Cite press release |title=Private Investigators Indicted In E-Mail Hacking Scheme |date=2015-02-11 |publisher=[[United States Attorney for the Northern District of California]] |url=https://www.justice.gov/usao-ndca/pr/private-investigators-indicted-e-mail-hacking-scheme |access-date=2021-02-28 |url-status=live |archive-url=https://web.archive.org/web/20210107082006/https://www.justice.gov/usao-ndca/pr/private-investigators-indicted-e-mail-hacking-scheme |archive-date=2021-01-07}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
BellTroX used the CV of one of their employees to test Dark Basin&amp;#039;s URL shortener. They also publicly posted screenshots of links to Dark Basin&amp;#039;s infrastructure.&amp;lt;ref name=&amp;quot;cl&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Hundreds of people, working in corporate intelligence and private investigation, endorsed BellTroX on LinkedIn. Some of them are suspected to be possible clients. Those endorsements included a Canadian government official, an investigator at the [[Federal Trade Commission|US Federal Trade Commission]], law enforcement officers and private investigators with prior roles in the [[FBI]], police, military and other branches of government.&amp;lt;ref name=&amp;quot;cl&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
On June 7, 2020, BellTroX took down their website.&amp;lt;ref name=&amp;quot;cl&amp;quot; /&amp;gt;  In December 2021, [[Meta Platforms|Meta]] ([[Facebook]]) banned BellTroX as a &amp;quot;cyber-mercenary&amp;quot; group.&amp;lt;ref&amp;gt;{{Cite news |date=17 December 2021 |title=Meta releases new threat report on surveillance for hire industry |work=The Economic Times |url=https://economictimes.indiatimes.com/news/company/corporate-trends/meta-releases-new-threat-report-on-surveillance-for-hire-industry/articleshow/88330134.cms |url-status=live |archive-url=https://web.archive.org/web/20211217034644/https://economictimes.indiatimes.com/news/company/corporate-trends/meta-releases-new-threat-report-on-surveillance-for-hire-industry/articleshow/88330134.cms |archive-date=17 December 2021}}&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;{{Cite web |last=Dvilyanski |first=Mike |last2=Agranovich |first2=David |last3=Gleicher |first3=Nathaniel |date=16 December 2021 |title=Threat Report on the Surveillance-for-Hire Industry |url=https://about.fb.com/wp-content/uploads/2021/12/Threat-Report-on-the-Surveillance-for-Hire-Industry.pdf |url-status=live |archive-url=https://web.archive.org/web/20211216201907/https://about.fb.com/wp-content/uploads/2021/12/Threat-Report-on-the-Surveillance-for-Hire-Industry.pdf |archive-date=16 December 2021 |publisher=[[Meta Platforms|Meta]]}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Reactions ==&lt;br /&gt;
Both Wirecard and ExxonMobil have denied any involvement with Dark Basin.&amp;lt;ref&amp;gt;{{Cite news |last=Porter |first=Jon |date=2020-06-10 |title=Researchers detail huge hack-for-hire campaigns against environmentalists |work=[[The Verge]] |url=https://www.theverge.com/2020/6/10/21286486/dark-basin-hackers-for-hire-phishing-emails-environmental-nonprofit-groups-exxon-mobil |url-status=live |access-date=2021-02-28 |archive-url=https://web.archive.org/web/20200610192252/https://www.theverge.com/2020/6/10/21286486/dark-basin-hackers-for-hire-phishing-emails-environmental-nonprofit-groups-exxon-mobil |archive-date=2020-06-10}}&amp;lt;/ref&amp;gt;&amp;lt;ref&amp;gt;{{Cite news |last=Murphy |first=Paul |date=2021-06-09 |title=Toronto&amp;#039;s Citizen Lab uncovers massive hackers-for-hire organization &amp;#039;Dark Basin&amp;#039; that has targeted hundreds of institutions on six continents |work=[[Financial Times]] |url=https://financialpost.com/financial-times/torontos-citizen-lab-uncovers-massive-hackers-for-hire-organization-dark-basin-that-has-targeted-hundreds-of-institutions-on-six-continents |url-status=live |access-date=2021-02-28 |archive-url=https://web.archive.org/web/20210125160451/https://financialpost.com/financial-times/torontos-citizen-lab-uncovers-massive-hackers-for-hire-organization-dark-basin-that-has-targeted-hundreds-of-institutions-on-six-continents |archive-date=2021-01-25 |via=the &amp;#039;&amp;#039;[[Financial Post]]&amp;#039;&amp;#039;}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
{{reflist|30em}}&lt;br /&gt;
&lt;br /&gt;
{{Hacking in the 2010s}}&lt;br /&gt;
&lt;br /&gt;
[[Category:Cyberattacks]]&lt;br /&gt;
[[Category:Hacker groups]]&lt;br /&gt;
[[Category:Hacking in the 2010s]]&lt;br /&gt;
[[Category:Cybercrime in India]]&lt;/div&gt;</summary>
		<author><name>Ajay Kumar</name></author>
	</entry>
</feed>