Appin was an India-based offensive-security and technology business widely identified in investigations as a pioneering hack-for-hire operation. It allegedly provided intrusion and intelligence-collection services to private investigators, corporate clients, and, during an earlier period, Indian government intelligence customers. Its reported targets included political figures, executives, attorneys, journalists, military officials, wealthy individuals, and organizations involved in commercial and legal disputes. Appin-operated services reportedly enabled clients to commission intrusions, monitor their progress, and obtain stolen data. Reported Appin activity included credential-phishing and social-engineering operations, compromise of email accounts and enterprise networks, and collection and exfiltration of communications and other information. Investigations linked Appin to industrial espionage, surveillance of political and civil-society figures, and targeting connected to litigation and commercial disputes. The group was also publicly associated with attacks against telecommunications personnel and with targeting of Pakistani officials. Appin’s leadership denied involvement in unlawful hacking and characterized the company as a cybersecurity training and defensive-security enterprise. Appin was run by Rajat Khare and Anuj Khare. Its corporate presence later changed through rebranding, with Appin Technology reported as becoming Sunkissed Organic Farms and Appin Software Security reported as becoming Adaptive Control Security Global Corporate. Appin alumni and related Indian hack-for-hire firms have been linked to the broader Indian cyber-mercenary ecosystem, including BellTroX, CyberRoot, and Rebsec. Appin and associated individuals have also used legal threats and litigation against reporting on alleged mercenary-hacking operations; an Indian court order temporarily restricted publication of an investigation before being overturned.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as the subject of prior reporting concerning alleged hack-for-hire operations and legal attempts to suppress reporting.
A cyber-mercenary / hack-for-hire operation accused of long-running targeted espionage against U.S. citizens, businesses, law firms, private-equity firms, pharmaceutical companies, and attorneys. It allegedly conducted operations for the Qatari government, including against opponents of Qatar's World Cup bid, and pursued global legal pressure campaigns to suppress reporting on its activities.
India-based hack-for-hire operation alleged to conduct paid cyberattacks and espionage against Americans and FIFA officials, reportedly at the behest of the Qatari government. It is also accused of using legal pressure and foreign court actions to suppress reporting on its activities.
An India-based hack-for-hire organization tied to historical operations including Operation Hangover, industrial espionage, and targeting involving custom Mac malware against human rights-related victims.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.