Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 20:40:48 UTC Other threat group: Dark Basin Names Dark Basin (Citizen Lab) Mercenary.Amanda (NortonLifeLock) Country India Sponsor BellTroX InfoTech Services Motivation Information theft and espionage First seen 2013 Description (Citizen Lab) We give the name Dark Basin to a hack-for-hire organization that has targeted thousands of individuals and organizations on six continents, including senior politicians, government prosecutors, CEOs, journalists, and human rights defenders. With high confidence, we link Dark Basin to BellTroX InfoTech Services (“BellTroX”), an India-based technology company. Over the course of our multi-year investigation, we found that Dark Basin likely conducted commercial espionage on behalf of their clients against opponents involved in high profile public events, criminal cases, financial transactions, news stories, and advocacy. This report highlights several clusters of targets. In future reports, we will provide more details about specific clusters of targets and Dark Basin’s activities. Observed Sectors: Financial, Government, Manufacturing, Media, NGOs, Non-profit organizations and journalists, law and consulting firms. Countries: Austria, Belgium, Brazil, Canada, Cyprus, Czech, France, Germany, Iceland, India, Israel, Italy, Kenya, Mexico, Nigeria, Norway, Russia, South Korea, Sweden, Switzerland, UK, Ukraine, USA. Tools used Information AlienVault OTX Last change to this card: 27 August 2020 https://apt.etda.or.th/cgi-bin/showcard.cgi?u=03011e9d-5ddb-4d43-82a1-bf89a51b5709 Page 1 of 2 Download this actor card in PDF or JSON format Source: https://apt.etda.or.th/cgi-bin/showcard.cgi?u=03011e9d-5ddb-4d43-82a1-bf89a51b5709 https://apt.etda.or.th/cgi-bin/showcard.cgi?u=03011e9d-5ddb-4d43-82a1-bf89a51b5709 Page 2 of 2