Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Dark Basin

Description

Dark Basin is a hack-for-hire group that has targeted thousands of individuals and hundreds of institutions on six continents. Targets include advocacy groups and journalists, elected and senior government officials, hedge funds, and multiple industries. Dark Basin extensively targeted American nonprofits, including organisations working on a campaign called #ExxonKnew, which asserted that ExxonMobil hid information about climate change for decades. We also identify Dark Basin as the group behind the phishing of organizations working on net neutrality advocacy, previously reported by the Electronic Frontier Foundation. We link Dark Basin with high confidence to an Indian company, BellTroX InfoTech Services, and related entitie

AI Analysis

· 1 week ago

Executive Summary

Dark Basin is a hack-for-hire group with global operational reach, targeting advocacy groups, journalists, government officials, and financial institutions. With high confidence linked to BellTroX InfoTech Services in India, the group has been implicated in spear-phishing campaigns against net neutrality advocates and environmental organizations like those involved in the #ExxonKnew initiative. Their activities suggest a mix of politically motivated and financially driven objectives.

Goals & Targeting

Dark Basin's targeting profile reflects a strategic focus on sectors and individuals involved in politically sensitive campaigns, including environmental advocacy, government oversight, and financial institutions. By targeting organizations like those in the #ExxonKnew initiative and net neutrality advocates, the group likely seeks to undermine public campaigns, access confidential data, or extort financial compensation. Their selection of victims—ranging from journalists to hedge funds—suggests a dual motivation: ideological influence and monetary gain. The inclusion of government officials and nonprofits in their attack surface further implies an intent to destabilize institutions that challenge corporate or political interests, leveraging cyber operations as a tool for both disruption and intelligence gathering.

Enhanced Description

Dark Basin operates as a hack-for-hire group, executing targeted attacks across six continents with a focus on high-profile individuals and institutions. The group has been directly linked to the compromise of American nonprofits, including those involved in the #ExxonKnew campaign, which alleged that ExxonMobil concealed climate change data for decades. Additionally, Dark Basin has been identified in phishing operations targeting organizations advocating for net neutrality, as previously exposed by the Electronic Frontier Foundation. The group's connection to BellTroX InfoTech Services in India, confirmed with high confidence, suggests potential ties to local infrastructure or operational support. Their targeting pattern underscores an intent to disrupt advocacy efforts, access sensitive information, and potentially extort or blackmail high-value individuals. The group's operational methodology indicates a capacity for sustained, targeted cyber operations that blend both technical sophistication and social engineering tactics.

Key Capabilities

  • Spear-phishing campaigns with tailored email lures
  • Compromise of nonprofit and advocacy group infrastructures
  • Exploitation of insider access or compromised credentials
  • Use of financially motivated extortion tactics
  • Targeted data exfiltration from high-value individuals

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Exfiltration
Impact

ATT&CK Techniques

T1566.001 - Phishing
T1195 - Exploit Public-Facing Application
T1071.001 - Application Layer Protocol
T1059.003 - Command and Scripting Interpreter

Software / Tooling

Custom phishing kits
Tailored malware for data exfiltration
Cobalt Strike (likely for C2 infrastructure)

Campaigns & Victims

Dark Basin's campaigns exhibit a pattern of targeting advocacy groups and nonprofit organizations involved in high-profile social or environmental campaigns. Their operations often involve prolonged engagement with victims, with a focus on extracting sensitive information or leveraging compromised systems for financial gain. The group's association with BellTroX InfoTech Services in India suggests possible use of local infrastructure for command-and-control operations, though their global reach indicates a capacity for cross-border targeting. Notable past operations include the compromise of net neutrality advocates and the #ExxonKnow campaign, highlighting their interest in disrupting public discourse on politically sensitive topics.

IOC Patterns

  • Spear-phishing emails with malicious document attachments
  • C2 communication via compromised domains linked to India-based infrastructure
  • Use of stolen credentials from nonprofit and advocacy group networks
  • Malware payloads tailored for data extraction from high-profile targets

Recommended Actions

  • Implement advanced phishing detection systems with user behavior analytics
  • Conduct regular security awareness training focused on spear-phishing and social engineering
  • Monitor network traffic for anomalies in C2 patterns associated with India-based domains
  • Enforce strict access controls and multi-factor authentication for sensitive systems
  • Collaborate with threat intelligence platforms to share indicators linked to hack-for-hire groups

Suggested Tags

APT
hack-for-hire
phishing
espionage
non-profit sector
government
India-linked

Confidence Assessment

High confidence exists in the link between Dark Basin and BellTroX InfoTech Services, based on corroborated phishing campaigns and nonprofit compromises. However, data gaps remain regarding the group's full technical capabilities, specific malware tooling, and the extent of their global infrastructure beyond India. Further analysis of IOCs and TTPs is required to refine their MITRE technique associations and fully map their operational tactics.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Phishing
Government Targeting
APT
hack-for-hire
phishing
espionage
non-profit sector
government
India-linked

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.