Three US lawmakers have asked the Trump administration to blacklist three Indian companies accused of involvement in long-running hack-for-hire operations targeting American citizens, businesses and lawyers.
Senators Ron Wyden and Sheldon Whitehouse, both Democrats, joined Republican Representative Pat Harrigan in writing to US Commerce Secretary Howard Lutnick. They want BellTroX, CyberRoot and Sunkissed Organic Farms Pvt. Ltd., formerly known as Appin Technology Pvt. Ltd., and its subsidiaries added to the Commerce Department’s Entity List.
The lawmakers allege the companies are linked to more than 15 years of targeted cyber espionage against US interests.
The companies have previously denied wrongdoing. No final US government decision to blacklist them has yet been announced.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
Hackers allegedly hired to gain advantage in legal and business disputes
At the centre of the allegations is the hack-for-hire industry.
Unlike ordinary cybercriminals who steal information for themselves, a hack-for-hire operator allegedly breaks into email accounts, devices or online services for a paying client.
The client may want confidential information about a commercial rival, litigation opponent, activist, journalist or another person.
Reuters reported in 2022 that BellTroX and CyberRoot had emerged as important players in the cybermercenary industry and were allegedly used by Western lawyers and private investigators during business and legal disputes.
A later Reuters investigation described Appin as an early player in the sector, alleging that it grew from an educational technology venture into an operation involved in obtaining information from executives, politicians, military officials and wealthy individuals worldwide. Appin-linked interests have disputed such allegations.
The new congressional push argues that such activities create more than an ordinary cybercrime problem.
When hacking is offered as a commercial service, clients can potentially distance themselves from the intrusion while private operators conduct the technical work.
What would the US Entity List actually do?
The Entity List is a US Commerce Department trade restriction mechanism.
Being placed on it does not automatically amount to a criminal conviction.
Instead, US companies generally require government permission before supplying listed entities with specified American-origin goods, software or technology.
For a technology company, that can be highly disruptive.
The lawmakers say listing the Indian firms could restrict their access to US software licences, cloud infrastructure and cybersecurity tools — services that modern technology companies may depend on to operate.
The request is therefore designed to attack the technical infrastructure that alleged mercenary hackers need rather than merely publicly naming them.
The Commerce Department has not announced whether it will accept the lawmakers’ request.
BellTroX was linked to a massive operation called Dark Basin
The allegations against BellTroX have a documented history extending well beyond the latest congressional letter.
In 2020, researchers at the University of Toronto’s Citizen Lab published a multi-year investigation into a hack-for-hire operation they called Dark Basin.
Citizen Lab said the operation had targeted thousands of individuals and hundreds of institutions across six continents, including journalists, advocacy groups, government officials, hedge funds and senior executives.
Researchers said they linked Dark Basin with “high confidence” to BellTroX InfoTech Services and related entities.
The attacks frequently relied on phishing.
Targets received links designed to resemble legitimate login pages. If a victim entered an email password, the information could be captured by the attacker.
Citizen Lab identified almost 28,000 phishing links while investigating the operation and said it notified hundreds of people and organisations that had been targeted. It also shared material with the US Department of Justice at the request of some victims.
The network allegedly targeted American groups involved in climate-related campaigns and organisations advocating for net neutrality.
Tech companies have also tracked alleged cybermercenary activity
The concerns do not come only from media investigations.
Reuters notes that Meta and Google have previously published reports linking hacking activity to some of the firms named in the congressional letter. The New Yorker and the Bureau of Investigative Journalism have also investigated the wider Indian hack-for-hire ecosystem.
The latest letter adds another allegation: that organisations connected with the industry have used litigation and foreign courts to suppress reporting about their activities.
Reuters itself remains involved in litigation in India with the Association of Appin Training Centers, which says it represents former Appin students and training centres and alleges Reuters reporting damaged their reputations. Reuters disputes that claim.
For US lawmakers, the question is now whether the evidence collected over years by researchers, technology companies and journalists is enough to justify direct economic restrictions.
If the Commerce Department agrees, the case would mark a significant escalation from documenting alleged mercenary hacking to restricting the companies accused of enabling it.
What this means for you: Hack-for-hire attacks often begin with highly convincing phishing emails rather than obvious malware. Lawyers, executives, journalists and others involved in sensitive disputes should use phishing-resistant multi-factor authentication and independently verify unusual login requests.
The420 Insight: The important shift is enforcement. Hack-for-hire groups have been documented for years, but Washington is now being pushed to treat private cybermercenaries more like national-security threats by cutting them off from the American technology infrastructure they rely on.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics