Meta Banning Delhi-based Belltrox From ‘hacking-for-hire Activities

Meta banning Delhi-based BellTroX from ‘hacking-for-hire activities

New Delhi, Dec 17 : IT company BellTroX InfoTech Services, based at Netaji Subhash Place in Shakurpur area of East Delhi, is back in news as Meta has removed 400 Facebook accounts linked to the India-based ‘hack-for-hire’ firm — known for social engineering and to send malicious links to hack influential people around the globe.

 Meta Banning Delhi-based Belltrox From ‘hacking-for-hire Activities-TeluguStop.com

Hiding under the radar for some time after its activities were exposed last year, BellTroX InfoTech Services targeted advocacy groups and journalists, elected and senior government officials, hedge funds and multiple industries on the six continents, creating ripples among the powers-that-be.

In June last year, Citizen Lab, a laboratory based at the Munk School of Global Affairs and Public Policy of the University of Toronto, broke the story around BelltroX and its ‘hack-for-hire’ activities.

Meta said that BellTroX is based in India and sells what’s known as ‘hacking for hire’ services.

“We removed about 400 Facebook accounts, the vast majority of which were inactive for years, linked to BellTroX and used for reconnaissance, social engineering and to send malicious links,” Meta said.

“Its activity on our platform was limited and sporadic between 2013 to 2019, after which it paused,” Meta added in a blog post late on Thursday.

“BellTroX operated fake accounts to impersonate a politician and pose as journalists and environmental activists in an attempt to social-engineer its targets to solicit information, including their email addresses, likely for phishing attacks at a later stage,” the social network added.

This activity, based on the exact same playbook, re-started in 2021 with a small number of accounts impersonating journalists and media personalities to send phishing links and solicit the targets’ email addresses.

“Among those targeted were lawyers, doctors, activists, and members of the clergy in countries, including Australia, Angola, Saudi Arabia, and Iceland,” Meta informed.

Following an investigation by researchers at Citizen Lab and Facebook’s new parent company, Meta, seven surveillance-for-hire groups in total have been banned from using the social media giant’s platforms to target other users.

Last year, Citizen Lab, as part of its multi-year ‘Dark Basin’ investigation, collaborated with consumer cybersecurity brand NortonLifeLock and unearthed numerous technical links between the campaigns and individuals associated with BellTroX.

BellTroX, owned by Sumit Gupta who was indicted in California in 2015 for his role in a similar hack-for-hire scheme, targeted government officials in Europe and well-known investors in the US.

The ‘hack-for-hire’ organisation extensively targeted American nonprofits, including organisations working on a campaign called #ExxonKnew, which asserted that ExxonMobil hid information about climate change for decades.”In at least one case, Dark Basin repurposed a stolen internal email to re-target other individuals.This incident led us to conclude that Dark Basin had some success in gaining access to the email accounts of one or more advocacy groups,” said the report.BellTroX employees sent phishing emails masquerading as targets’ colleagues and friends.The individuals that Dark Basin chose to target showed that it had a deep knowledge of informal organisational hierarchies (masquerading as individuals with greater authority than the target).”We concluded that Dark Basin operators were likely provided with detailed instructions not only about whom to target, but what kinds of messages specific targets might be responsive to,” the report had said.

na/dpb

Meta bans Delhi-based firm BellTroX for ‘hack-for-hire’ activities

Hack-for-hire targeted American non-profits extensively, and included organizations working on #ExxonKnew.This campaign asserted ExxonMobil had hidden information regarding climate change for many decades.
Dark Basin used stolen email from its internal network to target other people in at least one instance.The report stated that this incident had led to us concluding Dark Basin was able to gain access to email accounts for one or more advocacy organizations.

BellTroX workers sent out phishing emails pretending to be friends and colleagues of the targets.Dark Basin targeted individuals who had deep knowledge about informal organizational hierarchies.

This meant that they could masquerade as people with more authority than their target.

The report stated that Dark Basin operators had likely been given detailed instructions about who to target and what messages they might respond to.

#exxonknew, #exxonknew.this #Meta #Delhi #BellTroX #hire # Asin #Delhi #New Delhi #Toronto #Zen #Facebook #Cybersecurity

.

Follow Us on FacebookFollow Us on WhatsAppFollow Us on Twitter