ME is responsible for targeted attacks on human rights activists, human rights defenders, academics, and lawyers across India with the objective of planting incriminating digital evidence.
Targets and known victims include those involved in the Bhima Koregaon case, in which the evidence presented in the case was planted by the actor prior to arrests.
Heavy reliance on commercial and rather uninteresting malware like NetWire and DarkComet RATs. They also attempted to deliver keyloggers and Android trojans. Early efforts around 2012 included the keyloggers and DarkComet RATs.
Around 2014/2015 the actor potentially gained access to a new set of resources as the quality and persistence of their campaigns increased.
Many relationships to other actors and known threats exists. For example:
- Very early activity was part of the infrastructure included in the great Operation Hangover report from 2013.
- NSO Group’s Pegasus mobile spyware was found on one known victims iPhone.
- Overlapping SideWinder APT activity against the same targets.
"We observe that ModifiedElephant activity aligns sharply with Indian state interests and that there is an observable correlation between ModifiedElephant attacks and the arrests of individuals in controversial, politically-charged cases."