/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researcher details how hacker-for-hire group RocketHack infiltrated the email and Telegram accounts of ~3,500 individuals, including politicians and journalists

An unprecedented peek inside an underground hacker-for-hire operation reveals 3,500 targets, including Belarusian presidential candidates … Tweets: @rondeibert , @iblametom , and @martijn_grooten Tweets: Profdeibert / @rondeibert : NSO Group is a more polished version of the type of cyber mercenary firm operating in grey zones, like that reported on below. But the outcome is the same: dictators, kleptocrats, and even corrupt businesses are driving a new type of despotism-as-a-service. https://twitter.com/... Thomas Brewster / @iblametom : One of the domains owned by one of the apparent hackers here is inṣtagṛam[.]com. Pretty smart phishing domain. https://twitter.com/... Martijn Grooten / @martijn_grooten : Hacker-for-hire groups aren't getting the attention their actions deserve. Their targets often include civil society and this case is no exception. Important work by @FeikeHacquebord and good write-up by Tom. https://twitter.com/... Expand More For Next Unexpand More For Next

Forbes Thomas Brewster

Context & Ripple Effects

The mercenary-hacking beat has been building for years: Latin American governments bought Hacking Team exploits to spy on political opposition back in 2016, and India emerged as a hack-for-hire hub targeting politicians, companies, and activists in 2020. What makes this Forbes report different is access — an inside view of RocketHack's own operation rather than inference from victims or leaked customer lists.

The target list is the story: roughly 3,500 individuals, including Belarusian presidential candidates and journalists, had email and Telegram accounts infiltrated. Citizen Lab's Ron Deibert frames RocketHack alongside NSO Group as the same grey-zone business model at different price points — despotism-as-a-service available to any buyer.

First-order effects

  • Belarusian opposition figures, politicians, and journalists must treat email and Telegram as compromised channels, since account infiltration exposes sources, contacts, and private coordination.
  • Telegram faces a specific reputational problem: its accounts were among the attack surface for a mass-targeting operation, not just a bystander platform.

Second-order effects

  • Commercial spyware firms like NSO Group get pulled into the same scrutiny cycle — Deibert explicitly casts them as a more polished version of the same trade, so every new operator exposed raises questions about the whole supplier ecosystem.
  • Demand-side evidence accumulates for governments considering export controls or sanctions on spyware brokers, following the pattern where Hacking Team's client list became the basis for public accountability.

Third-order effects

  • If the pattern holds, state-aligned hacking keeps blurring into a contractor market — echoing how Russian hacking evolved from criminal schemes into joint criminal-government teams — with repression outsourced to firms whose customers are dictators, kleptocrats, and corrupt businesses.
  • Messaging platforms become structural targets: as political organizing consolidates on apps like Telegram, credential theft against those platforms becomes standard tradecraft, pushing platforms toward hardened authentication as a baseline expectation.

The trend: Hacker-for-hire operations are maturing into an off-the-shelf surveillance industry serving authoritarian buyers, with each exposed operator normalizing the model NSO Group made famous.

Discussion

  • @rondeibert Profdeibert on x
    NSO Group is a more polished version of the type of cyber mercenary firm operating in grey zones, like that reported on below. But the outcome is the same: dictators, kleptocrats, and even corrupt businesses are driving a new type of despotism-as-a-service. https://twitter.com/..…
  • @iblametom Thomas Brewster on x
    One of the domains owned by one of the apparent hackers here is inṣtagṛam[.]com. Pretty smart phishing domain. https://twitter.com/...
  • @martijn_grooten Martijn Grooten on x
    Hacker-for-hire groups aren't getting the attention their actions deserve. Their targets often include civil society and this case is no exception. Important work by @FeikeHacquebord and good write-up by Tom. https://twitter.com/...
  • @ericgarland Eric Garland on x
    “there's an underground industry of players like RocketHack, who will break into people's digital lives for the highest bidder, whether that's a government, a corporate espionage client, a stalker or an abusive spouse.” https://www.forbes.com/...
  • @campuscodi Catalin Cimpanu on x
    NEW: Trend Micro has published a 46-page report today about Void Balaur, a cyber-mercenary group that appears to be operating out of Russia and the CIS space https://therecord.media/... https://twitter.com/...
  • @iblametom Thomas Brewster on x
    Something to think about: RocketHack is far from the most sophisticated hacker-for-hire crew out there. Imagine what others are doing. https://twitter.com/...
  • @iblametom Thomas Brewster on x
    3,500 victims at the time of his research, but a dozen new victims a day. Other targets include as many as 70 (?!) IVF doctors and customers/employees at a major cryptocurrency exchange. https://twitter.com/...
  • @trendmicrorsrch @trendmicrorsrch on x
    Our research delves into the activities of the cybermercenary group known as #VoidBalaur (aka Rockethack). Learn more about the cyberattacks of this hacker-for-hire group against its prominent targets and their potential real-life consequences here 👇 👇 https://research.trendmicro…
  • @bobmcardle Robert McArdle on x
    For anyone interested in Cybercrime or CyberEspionage, this is genuinely an important one https://www.forbes.com/... + full details on https://www.trendmicro.com/... < @TrendMicro research into #VoidBalaur, a cyber mercenary group that blurs the lines between financial and state …
  • @campuscodi Catalin Cimpanu on x
    They also targeted activists and journalists, with their most notable campaign being in Uzbekistan in 2016. Trend Micro said this campaign predated the group's first ads on hacking forums. https://therecord.media/... https://twitter.com/...