Home/Threat Actor/Bahamut
Threat Actor

Bahamut

bahamut · private_mercenary · active since 2014

Bahamut (EHDevel / URPAGE / G0166) is a private-sector cyber- espionage mercenary cluster active since 2014, widely characterized since BlackBerry / Cylance's seminal October 2020 report as a hack-for-hire operation serving multiple state and private clients , with strong circumstantial evidence of India-aligned tasking for Pakistani-military and Sikh-activist targeting and of UAE / Gulf- state-aligned tasking for Qatari and Iranian dissident targeting, though no client has been formally established, defined operationally by a signature fake-news watering-hole infrastructure spanning multiple regional topics, extensive trojanized-app distribution through the official Google Play Store, demonstrated iOS implant capability, and disciplined long-dwell collection tradecraft that consistently avoids burning zero-day exploits.

private_mercenary confidence: medium 15 aliases MITRE ATT&CK G0112 ↗

Profile

Bahamut (also tracked as EHDevel, URPAGE, "The White Company" historically, and MITRE ATT&CK G0166) is a private-sector cyber- espionage mercenary cluster active since at least 2014 and publicly characterized from 2017 onward. The cluster is widely assessed across vendor and academic research to operate as a "hack-for-hire" operation serving multiple clients rather than as the in-house cyber unit of any single state. BlackBerry / Cylance's October 2020 report "Bahamut: Hack-for-Hire Master Artisans of Cyberespionage" is the seminal public profile and the central source for the mercenary characterization that has shaped all subsequent reporting. Bahamut is one of the few publicly-tracked APT-tier clusters where attribution is not to a state but to a private commercial entity. Strong circumstantial evidence has been published associating different Bahamut campaigns with different suspected clients, including India-aligned tasking for operations against Pakistani military and Sikh-activist targets, and UAE / Gulf-state-aligned tasking for operations against Qatari and Iranian dissident targets. No state has been formally established as a Bahamut client.

the "private mercenary serving multiple state clients" framing should be treated as the dominant vendor assessment but not as definitively confirmed. The origin: private_mercenary value in this record is a deliberate departure from the nation- state origin values used for the other 35+ actors in this corpus, reflecting the cluster's defining mercenary characteristic. Operationally Bahamut is distinguished from peer clusters by three signature elements: First, the cluster operates an extensive network of fake-news watering-hole websites covering niche regional topics, Sikh- community news, Iranian-dissident commentary, Middle Eastern regional politics, Pakistani military commentary, and many others. These fake-news sites serve a dual purpose as both credential- harvesting and watering-hole infrastructure and as long-term access channels into target communities. Several Bahamut fake-news sites have published genuine-looking articles for months or years before being weaponized for delivery, establishing real audiences and legitimacy. Second, the cluster operates one of the most extensive publicly- documented Android implant operations of any tracked APT cluster, with repeated and persistent distribution of trojanized applications through the official Google Play Store and through third-party Android app marketplaces, disguised as VPN clients, security tools, messaging applications, and consumer chat applications. ESET, Lookout, ThreatFabric, and Cyble have published extensive documentation of these Android implants and the cluster's recurring tactic of slipping malicious applications past Google Play security review. Third, the cluster has demonstrated iOS implant capability, uncommon among publicly-tracked clusters at this tier, and consistent with the assessed mercenary business model where premium per-target client work justifies the higher development cost of iOS tooling. Initial-access tradecraft on Windows is overwhelmingly via spear- phishing with weaponized Office documents (CVE-2017-11882 Equation Editor, CVE-2018-0802, CVE-2017-0199, CVE-2017-8570) and via credential-phishing kits targeting Google, Microsoft, and Apple accounts. On mobile platforms initial access is via trojanized applications distributed through legitimate app stores. The cluster is famous for not burning zero-days, toolkit sophistication is moderate-high but technique sophistication is durable-and-disciplined rather than cutting-edge. A handful of operational notes: First, partial overlap with the "Windshift" / APT-C-23 cluster (suspected UAE / Gulf-aligned) and with "Dark Caracal" (Citizen Lab's 2018 disclosure of a Lebanese General Security Directorate- adjacent cluster) appears in some early reporting. Modern vendor consensus treats these as separate but adjacent clusters that may share contractor staff, infrastructure, or tooling at the margins. Second, the cluster's targeting against Sikh-activist and Khalistan-movement entities overlaps confusingly with separate India-aligned state surveillance activity against the same communities (notably the diplomatic incidents surrounding alleged Indian state involvement in Khalistan-related targeting in Canada in 2023-2024). Toolkit and tradecraft remain distinctively Bahamut. Third, the "private mercenary" framing, though dominant in vendor reporting, has not been confirmed by formal investigation or by client identification. Bahamut's underlying clients and the identity of the commercial entity operating the cluster remain open questions.

Aliases

15
bahamutbahamut aptbahamut_aptehdeveleh develeh_develurpagewhite companywhite_companythe white companywindshift overlapapt-c-23 overlapapt_c_23_overlapg0166desert_falcon_overlap

MITRE ATT&CK aliases

1
Additional names MITRE lists for G0112.
Windshift

Notable Campaigns

8
2024-2025Continued Operations Across Multiple Theaters (2024-2025)
2023-2025Sikh-Activist and Khalistan-Movement Targeting (2023-2025)
2022-2024Iranian and Qatari Dissident Targeting (2022-2024)
2021-2023Android Implant Distribution via Google Play (2021-2023)
2020BlackBerry / Cylance: Bahamut, Hack-for-Hire Master Artisans of Cyberespionage (October 2020)
2018-2019Bellingcat / Open-Source Attribution Discussion (2018-2019)
2018Trend Micro URPAGE Disclosure (August 2018)
2017EHDevel Disclosure (Cisco Talos, September 2017)

Attribution & Reporting

Attributed by
BlackBerry / Cylance Research and IntelligenceCisco TalosTrend MicroCitizen Lab (University of Toronto)ESETKasperskyBellingcat (open-source research)LookoutCyfirmaSentinelOneThreatFabricVolexityMicrosoftGroup-IBCluster25Recorded Future Insikt GroupCybleQiAnXin RedDrip
Key reporting
reportCisco Talos: The EHDEVEL Framework (September 2017)
reportTrend Micro: The URPAGE Connection to Bahamut, Confucius, and Patchwork (August 2018)
reportCitizen Lab: Dark Caracal, Cyber-Espionage at a Global Scale (January 2018), partial Bahamut adjacency
reportBellingcat: Bahamut Mercenary APT and UAE Discussion (October 2020)
reportBlackBerry / Cylance: Bahamut, Hack-for-Hire Master Artisans of Cyberespionage (October 2020), seminal report
reportESET: Bahamut Cybermercenary Group Targets Android Users with Fake VPN Apps (November 2022)
reportSentinelOne Labs: The Pegasus Android Stories, Bahamut Mobile Spyware (2022)
reportCyfirma: The Bahamut, Spear Phishing and Mobile Malware (multiple years)
reportThreatFabric: Bahamut Fake VPN and Chat Apps on Google Play Targeting Mobile Users (2022)
reportLookout: Bahamut Android Spyware (2022-2023)
reportCyble: Bahamut APT Group Targets Users via Trojanized Apps (June 2023)
reportRecorded Future Insikt Group: Bahamut Targeting Dissidents (multiple years)
reportCluster25: Bahamut APT, Mercenary Profile
reportMalpedia Actor Profile: Bahamut
reportMITRE ATT&CK Group G0166, Bahamut

Operational

State sponsor

Widely assessed by vendor research to operate as a private-sector "hack-for-hire" mercenary operation serving multiple state and private clients rather than as the in-house cyber unit of any single state. BlackBerry / Cylance's October 2020 report "Bahamut: Hack-for-Hire Master Artisans of Cyberespionage" is the seminal public characterization of the cluster's mercenary business model; this assessment has been widely accepted across subsequent vendor reporting (Cisco Talos, Trend Micro, Citizen Lab, ESET, Kaspersky, Cyfirma, ThreatFabric, SentinelOne, Volexity). Strong circumstantial evidence has been published associating various Bahamut campaigns with different suspected clients, including India-aligned tasking (campaigns against Pakistani military and Sikh separatist activists), UAE / Gulf-state tasking (campaigns against Qatari and Iranian dissidents in Europe), and possible additional Middle Eastern clients. No single state has been definitively confirmed as the cluster's principal sponsor.

no formal government attribution has been issued by any state. The "private mercenary" framing in this record reflects the dominant vendor and research-community assessment, with the explicit caveat that the underlying clients have not been formally established.

Motivations
mercenary_espionage, hack_for_hire, dissident_surveillance, journalist_surveillance, geopolitical_collection, private_sector_intelligence
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)49/60 · 81%
Analytics (MITRE CAR)23/60 · 38%
Runtime / container (Falco)6/60 · 10%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)15/60 · 25%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

1 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MOBILE SPYWARE SUITEMSHTA
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin