CSIDB logo
Threat actor

R3dr0x

Attribution profile

Type
Activist
Location
India
Known incidents
1 incident
First seen
2020-05-25
Last seen
2020-05-25
Updated
2026-08-01 20:33
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor known by the alias R3dr0x has been linked to a data breach involving the Indian defence contractor Bharat Earth Movers Limited (BEML). According to open‑source reporting, the actor’s location is noted as India, although the source material also mentions that analysts described the actor as appearing to be Pakistan‑based. The incident came to public attention in May 2020 when internal documents from BEML were posted on a dark‑web forum. The leaked material comprised email correspondence, customer records, freight invoices, interoffice memos and credential sets from seven employee accounts.

Researchers characterised the breach as politically motivated and described the actor as a hacktivist rather than a financially driven criminal. The specific focus of the leak was the section of BEML’s website dealing with indigenisation levels, which the actor framed as a warning against the policies of the Indian government. No technical evidence was presented to link the operation to a nation‑state sponsor, and the attribution remained based on circumstantial clues such as the actor’s message and password patterns. The disclosure was intended to highlight perceived vulnerabilities in the contractor’s web infrastructure.

The initial access vector reported in the case was the exploitation of vulnerabilities present in BEML’s web‑facing applications, allowing the actor to retrieve internal files. The disclosed sources do not reference any specific malware families, custom tools, or advanced payloads used during the operation. The actor’s activity was limited to data exfiltration and the subsequent posting of the stolen information on a dark‑web marketplace.

Attribution to any state sponsor or criminal consortium has not been established in public reports, with analysts noting only the speculative observation that the actor might be Pakistan‑based. The BEML incident remains the sole publicly documented operation associated with R3dr0x, and no further campaigns or recurring patterns have been attributed to the alias. No additional leaks or attributions have been tied to R3dr0x in subsequent threat intelligence feeds. Consequently, the profile of this threat actor is limited to the single politically motivated data leak described above.

Incidents

Attributed incidents are available to members.

1 incident
CSIDB