Threat actor
Appin
Last fetched
Appin is a threat actor tracked in WhisperGraph's MITRE ATT&CK corpus, observed using 0 techniques.
Description
Appin was an Indian hack-for-hire company founded in 2003 by brothers Rajat and Anuj Khare, and involved in extensive surveillance activities. Operating through various subsidiaries including Appin Software Security Pvt. Ltd. and the Appin Security Group, the company positioned itself as a cybersecurity solutions provider. While publicly presenting itself as the "world's 4th largest Critical Infrastructure Security Solutions Company", the company was reportedly involved in hack-for-hire activities, including espionage and targeted surveillance. The company served a wide range of clients, including Israeli private detectives Aviram Halevi and Tamir Mor, who alone commissioned surveillance operations on dozens of targets. Appin has garnered attention for its aggressive legal campaign to suppress reporting about its past activities, most notably forcing Reuters to temporarily remove an investigative article through an Indian court order. The Association of Appin Training Centers, a successor organization, has pursued legal action against multiple media outlets to remove references to Appin's illegal hacking operations, though this effort has faced resistance from organizations like the Electronic Frontier Foundation and DDoSecrets. The company's influence persists through numerous successor organizations, with former Appin employees establishing and operating their own firms that continue similar surveillance and hacking operations.
Techniques by tactic
No ATT&CK techniques are recorded for Appin in WhisperGraph.
Attributed infrastructure
None published. WhisperGraph carries no ATTRIBUTED_TO edge to Appin today — this states the absence of a published link, not that Appin has no infrastructure.
References
- https://www.reuters.com/investigates/special-report/usa-hackers-appin/
- https://www.securityweek.com/researchers-dive-into-activities-of-indian-hack-for-hire-firm-appin/
- https://ddosecrets.com/article/appin-uncensored
- https://www.thedailybeast.com/who-is-killing-all-these-stories-about-rajat-khare-controversial-tech-mogul/
- https://www.wired.com/story/appin-training-centers-lawsuits-censorship/
- https://web.archive.org/web/20221105180814/https:/www.thebureauinvestigates.com/stories/2022-11-05/inside-the-global-hack-for-hire-industry
- https://www.documentcloud.org/documents/23581428-appin-companies-name-change-documents#document/p5/a2198004
© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.
Related pages
Pivot from Appin into its techniques, tactics and any attributed infrastructure.
Queries
Resolves the slug to this actor, merging every duplicate node sharing the same name.
MATCH (a:ACTOR)
WHERE a.name =~ $pattern OR any(x IN a.aliases WHERE x =~ $pattern)
RETURN a.id AS id, a.name AS name, a.aliases AS aliases, a.description AS description,
a.references AS references, a.campaigns AS campaigns
LIMIT 25Run yourself →Techniques this actor uses, grouped by the tactic each one serves.
MATCH (a:ACTOR {name: $name})-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN)
OPTIONAL MATCH (t)-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN t.id AS techniqueId, t.name AS techniqueName, tac.id AS tacticId, tac.name AS tacticName
LIMIT 1000Run yourself →Infrastructure publicly attributed to this actor.
MATCH (n)-[:ATTRIBUTED_TO]->(a:ACTOR {name: $name})
RETURN labels(n)[0] AS kind, n.name AS name
LIMIT 25Run yourself →Or query Whisper from your own LLM workflow via the Whisper MCP server.