‏إظهار الرسائل ذات التسميات Cyber Crime. إظهار كافة الرسائل
‏إظهار الرسائل ذات التسميات Cyber Crime. إظهار كافة الرسائل

FIU-IND and I4C Forge MoU to Bolster India’s Cyber Fraud and Financial Crime Defenses

FIU-IND and I4C Forge MoU to Bolster India’s Cyber Fraud and Financial Crime Defenses

On April 9, 2026, India’s Financial Intelligence Unit (FIU-IND) and the Indian Cyber Crime Coordination Centre (I4C) signed a landmark Memorandum of Understanding (MoU) to strengthen the country’s fight against cyber fraud and financial crimes, focusing on real-time intelligence sharing, fraud detection, and asset recovery.

Key Details of the MoU

  • Signed by Amit Mohan Govil (Director, FIU-IND) and Rajesh Kumar (CEO, I4C).
  • Focus on real-time intelligence sharing on cyber fraud and money laundering.
  • Development of red flag indicators for banks and financial institutions.
  • Strengthening asset recovery mechanisms for victims of online financial crimes.
  • Establishing feedback loops to refine national fraud detection protocols.

India’s Digital Payment Context

India’s digital payment ecosystem has witnessed exponential growth, with UPI transactions crossing 12 billion per month in early 2026. This rapid adoption has also led to a surge in cyber fraud cases, including phishing, mule accounts, and instant loan scams.
  • The MoU reflects a “whole-of-government” approach, aligning financial monitoring with cybercrime enforcement.
  • It aims to safeguard citizens and businesses by institutionalizing fraud detection protocols.
  • It complements national initiatives such as Digital India and the National Cyber Security Strategy.

Strategic Impact

  • For Citizens: Stronger safeguards against fraud in UPI, net banking, and fintech platforms.
  • For Financial Institutions: Clear guidelines and early-warning indicators to detect suspicious activity.
  • For Investigators: Faster access to intelligence, enabling quicker case resolution and recovery of stolen assets.
  • For Policy: Reinforces India’s commitment to secure digital transactions and global best practices.

Conclusion

This MoU is a milestone in India’s cybercrime policy, signaling a shift toward institutionalized fraud detection and coordinated asset recovery at a time when India’s digital economy is expanding globally.

Cyber Interference Hits Delhi Airport Navigation Systems; Probe Launched

Cyber Interference Hits Delhi Airport Navigation Systems; Probe Launched

Delhi Airport recently faced a cyberattack attempt involving GPS spoofing signals. Pilots reported false navigation data, but backup systems and contingency procedures ensured flight safety. The government has confirmed the incident and launched investigations.

The Indian government and aviation authorities have officially confirmed the GPS spoofing incident near Delhi Airport. Civil Aviation Minister Ram Mohan Naidu acknowledged it in Parliament, and the aviation regulator DGCA issued directives to airlines and pilots to report such cases promptly.

The Ministry of Civil Aviation told Parliament that flights near Delhi and other major airports faced GPS spoofing and GNSS interference over the past year. Minister Ram Mohan Naidu confirmed that pilots were forced to switch to backup landing modes when navigation data was compromised.  

What Happened at Delhi Airport

  • Type of attack: GPS spoofing — fake satellite signals were transmitted to mislead aircraft navigation systems about their actual position.
  • Impact: Pilots received incorrect data, including false aircraft positions and misleading terrain warnings.
  • Scope: Delhi’s Indira Gandhi International Airport was among several major airports (including Mumbai and Bengaluru) that detected such signals.
  • Government response: Civil Aviation Minister Ram Mohan Naidu confirmed in Parliament that GPS spoofing and GNSS interference attempts had occurred over the past year.
  • Safety measures: Conventional navigation systems (like Instrument Landing Systems and radar) were used to override spoofed signals, ensuring no accidents occurred.

What “Switching to Backup Landing Modes” Means

Cyber Interference Hits Delhi Airport Navigation Systems; Probe Launched
When GPS spoofing compromised the aircraft’s satellite navigation data, pilots could no longer trust the primary GNSS/GPS guidance for approach and landing. In such cases, they revert to backup landing modes, which are older but highly reliable systems:
  • Instrument Landing System (ILS): Uses radio beams from ground transmitters to guide aircraft precisely down to the runway. It’s the gold standard backup for low‑visibility landings.
  • VOR/DME (VHF Omnidirectional Range / Distance Measuring Equipment): Provides position and distance information using ground‑based radio signals. Pilots can navigate and align with the runway without GPS.
  • Radar Vectoring by Air Traffic Control (ATC): Controllers give pilots heading and altitude instructions to safely guide them to final approach.
  • Visual Flight Rules (VFR): If weather is clear, pilots may rely on direct visual cues to land safely.

After Effects 

  • GPS spoofing disrupted the “modern” navigation layer.
  • Pilots had to fall back on conventional radio‑based systems that are immune to satellite signal manipulation.
  • This ensured flight safety despite compromised GPS data.

Think of it like driving with a GPS app that suddenly shows you on the wrong road. Instead of following the faulty GPS, you switch to road signs and landmarks — older but trustworthy guidance — to reach your destination safely.

Pilots switched to ground‑based navigation aids and ATC guidance when GPS signals were spoofed, ensuring safe landings despite compromised satellite data.

Investigations Underway

  • NSA Ajit Doval’s office has launched a probe into the Delhi incident, treating it as a national security matter.
  • Civil Aviation Ministry acknowledged the cyberattack attempt and assured Parliament that contingency procedures are in place.
  • International parallels: Similar GPS spoofing incidents have been reported globally, especially near conflict zones, raising concerns about aviation cybersecurity.

Risks & Challenges

  • Operational disruption: Over 400 flights across India were reportedly disrupted last month due to navigation interference.
  • National security: GPS spoofing can be used to misdirect aircraft, posing risks not just to safety but also to defense operations.
  • Cyber resilience gap: India’s aviation systems rely heavily on satellite navigation, making them vulnerable to spoofing unless robust countermeasures are deployed.

Quick Comparison: GPS Spoofing vs. Traditional Cyberattacks

Feature GPS Spoofing (Delhi Case) Traditional Cyberattack (e.g., ransomware)
Target Aircraft navigation systems IT infrastructure, servers, data
Method Fake satellite signals Malware, phishing, unauthorized access
Impact Misleading flight paths, terrain warnings Data theft, system shutdown, ransom demands
Detection Pilot reports, backup system alerts Security software, forensic analysis
Countermeasures Conventional navigation systems, contingency procedures Firewalls, backups, patching

Key Takeaway

Delhi Airport’s navigation systems were indeed under attack via GPS spoofing. Flights remained safe thanks to backup systems, but the incident highlights growing cyber threats to aviation. India is now investigating the matter at the highest levels, signaling the seriousness of such interference.

Aadhaar (AePS) -Related Banking Scams on the Rise, 5 Key Things You Must Do

Aadhaar (AePS) -Related Banking Scams on the Rise, 5 Key Things You Must Do

The Aadhaar-enabled Payment System (AePS) in India has recently faced exploitation by cybercriminals, leading to depositors losing their hard-earned savings through these frauds. These scams often involve cloned or fraudulently obtained fingerprints to access victims' bank accounts.

In one instance, a gang of cybercriminals in Hyderabad fraudulently withdrew ₹14.64 lakh from 149 customers. In an another AEPS related scam in Bihar, cyber criminals exploited the victim's Aadhaar biometrics data obtained from government land records to make transactions using the AePS.

The civil society platform, Bank Bachao Desh Bachao Manch, has raised concerns about these scams and urged the Reserve Bank of India to take action.

To protect against AePS fraud, users are advised to lock their Aadhaar biometrics and regularly monitor their bank accounts for any suspicious activity.

To protect yourself and prevent misuse of Aadhaar data, consider the following steps:

1. Lock Your Biometrics: Use the m-Aadhar app or the Unique Identification Authority of India (UIDAI) website to lock your biometrics. This prevents unauthorized access to your Aadhaar data.
  • Use virtual IDs: Process online transactions using a virtual ID instead of Aadhaar.
2. Contact Your Bank: If you become a victim of AePS fraud, immediately contact your bank's helpline number and report the fraudulent transaction. Provide any relevant details, such as SMS or email notifications.

3. Block Your Account: Request your bank to temporarily block your account to prevent further unauthorized transactions. Change your PIN, internet banking password, and other relevant passwords associated with your account.

4. File a Police Complaint: Report the incident to the National Cyber Crime Reporting Portal. You have 90 days to raise a chargeback on the transaction by approaching your bank or calling their service helpline.

5. Know Transaction Limits: AePS has per-day and amount-specific limits. Currently, the maximum limit for a single transaction is ₹10,000, with a maximum of five transactions per day. Be vigilant and block your account immediately if you notice any suspicious activity.

The government has acknowledged the issue and is working on measures to enhance the security of the AePS to prevent such frauds in the future.

AePS Cyberfraud: Money from Bank A/C Stolen Using Aadhaar Biometrics Data from Victim’s Land Records Obtained from Govt Website

AePS Cyberfraud: Money from Bank A/C Stolen Using Aadhaar Biometrics Data from Victim’s Land Records Obtained from Govt Website

In a recent cyberfraud case that emerged in Bihar's Purnia district, criminals swindled a person's account without using the conventional methods of OTP or phone calls. Instead, they exploited the victim's Aadhaar biometrics data obtained from government land records to make transactions using the Aadhaar Enabled Payment System (AePS). The Bihar police have been actively investigating such cases and recently arrested 33 alleged cybercriminals operating from Nawada district.

Bihar police revealed the unique scam in a press conference, the video of which was shared by Haryana IPS officer Pankaj Jain on X (Twitter).



While in this case cyber thieves used biometric details from victim’s land record or commonly called land registry, in another instance of cyberfraud related to Aadhaar, criminals (in Bihar only) allegedly cloned fingerprints to steal money from victims' bank accounts without using OTP or phone calls. The accused hacked into the government's database to access the victim's land records dated June 25, 2024. The criminals then breached the victim's Aadhaar details and obtained their fingerprint. Using the victim's thumb impression extracted from the land records, the accused created a false thumb impression. They used this false thumb impression along with the victim's Aadhaar to withdraw money from the bank account.

The Bihar Police have detained eight individuals involved in this systematic fraud scheme. To prevent similar incidents, consider these precautions:
  • Mask your Aadhaar number: Download the masked Aadhaar from the UIDAI website.
  • Use virtual IDs: Process online transactions using a virtual ID instead of Aadhaar.
  • Link your number and email ID to Aadhaar: Ensure your contact details are linked to your Aadhaar for notifications about suspicious activity.
If you encounter AePS cyber fraud, report it on the National Cybercrime Reporting Portal. Stay vigilant and protect your hard-earned money.

1,800 Bitcoin Wallets Suspected of Engaging in Transactions Linked to Child Sexual Exploitation or Human Trafficking

1,800 Bitcoin Wallets Suspected of Engaging in Transactions Linked to Child Sexual Exploitation or Human Trafficking

According to a recent report by the wired, US senators have called for fresh scrutiny of cryptocurrencies' role in paying for child sexual abuse imagery online, a problem that they say has worsened.

"These are deeply troubling findings revealing the extent to which cryptocurrency is the payment of choice for perpetrators of child sexual abuse and exploitation," wrote US senators Elizabeth Warren and Bill Cassidy. They called for the United States' Department of Justice and Department of Homeland Security to redouble efforts to stop the use of cryptocurrency to pay for child sexual abuse material (CSAM) online.

Citing data from the US Treasury's Financial Crime Enforcement Network as well as research from Chainalysis, a company that specializes in tracing crypto transactions, and the Internet Watch Foundation, a CSAM-focused charity, the letter asserts that the "use of cryptocurrency in the illicit trade of CSAM appears to be increasing."

Between January 2020 and December 2021, the U.S. Treasury Department's Financial Crimes Enforcement Network (FinCEN) identified over 1,800 unique Bitcoin wallet addresses related to suspected online child sexual exploitation (OCSE) and human trafficking offenses. This alarming trend highlights the use of cryptocurrency, particularly Bitcoin, in criminal activities involving the exploitation of vulnerable individuals.

Child Sexual Exploitation (CSE) refers to victimizing minors for sexual gratification or other purposes. In this context, Bitcoin has been used to pay for child sexual abuse material (CSAM). The overlap between OCSE and human trafficking within the realm of cryptocurrency transactions underscores the need for vigilance and collaboration among financial institutions, law enforcement agencies, and nonprofit organizations to combat these heinous crimes.

It's essential to continue monitoring and addressing such illicit activities to protect the most vulnerable members of our society.

Catching perpetrators using crypto currencies for illegal transactions

While the use of cryptocurrencies can provide anonymity and challenges for law enforcement, there have been notable successes in catching perpetrators involved in criminal activities.

The Silk Road, an infamous dark web marketplace, facilitated illegal transactions using Bitcoin. In 2013, the FBI arrested Ross Ulbricht, the alleged founder of Silk Road, and seized approximately 144,000 Bitcoins (worth over $1 billion at today's prices). This case demonstrated that even pseudonymous transactions on the blockchain could be traced back to individuals.

Law enforcement agencies collaborated internationally to identify the site's operator, Alexandre Cazes. Cazes was arrested in Thailand, and authorities seized his assets, including cryptocurrencies.

In some cases, investigators have traced ransom payments to specific wallets and identified the perpetrators. For instance, the Colonial Pipeline ransomware attackers were tracked down, and part of the ransom was recovered.

Companies specializing in blockchain analytics provide tools to track transactions. These tools help law enforcement agencies follow the money trail and identify suspicious addresses.

Cryptocurrency exchanges cooperate with authorities by sharing information on suspicious transactions. This collaboration has led to the identification of criminals using exchanges for cashing out illicit gains.

Remember that while these success stories demonstrate progress, challenges remain. Criminals adapt, and privacy-focused cryptocurrencies continue to emerge. Law enforcement agencies must stay vigilant and adapt their strategies to combat crypto-related crimes effectively.

Infosys' CSR Arm Commits ₹33 Cr to Strengthen Cybercrime Investigation Capabilities of the Karnataka Police

Infosys' CSR Arm Commits ₹33 Cr to Strengthen Cybercrime Investigation Capabilities of the Karnataka Police

Renewal of 2018 grant for the setting up of the Centre for Cyber Crime Investigation Training & Research (CCITR)

Infosys Foundation, the philanthropic and CSR arm of Infosys, has announced that it has signed a Memorandum of Understanding (MoU) with the Criminal Investigation Department (C.I.D) of Karnataka and Data Security Council of India (DSCI), to renew the collaboration for the Centre for Cyber Crime Investigation Training & Research (CCITR) at C.I.D Headquarters, Bengaluru.

Infosys Foundation has committed a grant of over INR 33 crore to strengthen the cybercrime investigation capabilities of the Karnataka police, by extending its association with CCITR for four more years. Building on the collaboration established in 2018, the new MoU will bolster the state police force’s cybercrime prosecution capabilities through training and research in digital forensics and cybercrime investigation.

In addition, the joint initiative will bring together innovators, large enterprises, user enterprises, academia, and the government to fulfil the following objectives:
  • Capacity building of the police, prosecution, and judiciary in handling investigations, and development of SOPs in cybercrime investigations.
  • Performing research in digital forensics and cybercrime investigation that would improve the prosecution of cybercrime cases investigated by Karnataka Police.
  • Fostering entrepreneurship for development of indigenous cyber forensics products and solutions.T
  • raining and certification for police staff in their core areas like cybercrimes and digital forensics.
  • Collaboration with national and international organizations working in digital forensics domains.


Dr. M A Saleem IPS, Director General of Police, CID, Economic Offences & Special Units, Karnataka, said, “The strategic initiatives for capacity enhancement undertaken by the Criminal Investigation Department of Karnataka have been substantially bolstered by the collaborative efforts with the Infosys Foundation and the Data Security Council of India. In addition to training police officers, CCITR has also extended its activities to other stakeholders in the criminal justice delivery system, viz., the prosecution and judiciary. With the renewal of the collaboration, we expect more thought leadership in digital forensics that would improve the investigation and prosecution of cybercrime cases. At this juncture, I take this opportunity to thank the Infosys Foundation and Data Security Council of India for partnering with us in our efforts to combat the growing menace of cybercrimes.”

Mr. Vinayak Godse, Chief Executive Officer, Data Security Council of India, said, “On this special occasion of renewing our commitment, I would like to acknowledge and express our profound gratitude towards the Infosys Foundation and the Criminal Investigation Department of Karnataka for their pivotal partnership through CCITR. This collaboration has set an excellent example of how public-private partnerships can effectively contribute to handling cybercrime threats. Looking ahead, this renewed collaboration will enable us to develop even more advanced training programs, workshops, and knowledge-sharing initiatives.”

Sunil Kumar Dhareshwar, Trustee, Infosys Foundation, said, “We are very happy with the work DSCI and CCITR have collaboratively achieved. With the digital landscape evolving every day, this renewed engagement will bring in newer dimensions to Karnataka Police’s cybercrime handling capabilities through innovative solutions. This initiative signals a pivotal step towards safeguarding our digital future.”

KTR Inaugurated ‘Telangana Police CoE for Cyber Safety’, a 1st-of-its-Kind Initiative in India to Secure the Cyber Ecosystem for the State

Newly inaugurated Centre of Excellence for Cyber Safety, a first of its kind in India to secure Cyber Ecosystem for the State
Newly inaugurated Centre of Excellence for Cyber Safety, a first of its kind in India to secure Cyber Ecosystem for the State

Institutions outlast individuals says, KT Rama Rao

Awareness about Cyber Security needs to be promoted: KTR

A custom built Investigation tool ‘Crime OS’, another first, built by the city’s Start-up CyberEye launched, www.tspcc.org website unveiled, SoPs book authored by ground police launched

Mr K. T. Rama Rao, Minister of IT E&C, MA & UD, Govt of Telangana inaugurates TS Police Centre of Excellence for Cyber Safety in the city at Cyberabad Police Commissionerate at Gachibowli on Saturday

TS Police ‘Centre of Excellence for Cyber Safety’ is an initiative of Telangana Police and the Society For Cyberabad Security Council (SCSC) curated by Cyberabad Police Commissionerate. It was inaugurated by KTR in the presence of Shri Mohd Mahboob Ali, Minister of Home, Govt of Telangana; Mr M. Mahender Reddy, Director General of Police, Telangana.

It is the first of its kind initiat​ive​​ by any state in India. It is a proactive initiative. It is a process-driven initiative rather than a people-oriented unique initiative in which Telangana Police take pride. It is a productised approach.

The vision of this ambitious initiative is to secure the cyber ecosystem for the state of Telangana.

A book of SOPs authored by ground level police unveiled
A book of SOPs authored by ground level police unveiled

CP Stephen Ravindra seen interacing with KT Rama Rao at newly inaugurated TSPCC
CP Stephen Ravindra seen interacing with KT Rama Rao at newly inaugurated TSPCC

KTR, Mahmood Ali, DGP Mahender Reddy seen inspecting Telangana State Police Centre of Excellence for Cyber Safety
KTR, Mahmood Ali, DGP Mahender Reddy seen inspecting Telangana State Police Centre of Excellence for Cyber Safety

It is an industry-led initiative taken up in partnership with the Police (PPP), as a trusted partner to citizens, industry and academia, for mitigating cyber security incidents and frauds, by leveraging technology, setting up processes, building capacity, spreading awareness, to strengthen the legal framework by complementing cyber security initiatives of Government and to serve as a collaborative and continuous innovation platform for—Field Practitioners, Industry Experts, Thought Leaders, Researchers etc.

The who-is-who industry partners of the initiative include Microsoft, CyberEye, Google, EY, ISB, NALSAR, IIT-Hyderabad; RBI, NPCI (National Payments Corporation of India), IDRBT, Dept of Telecommunication, Govt of India; TAFCOP(Telecom Analytics for Fraud Management and Consumer Protection; HDFC Bank, ICICI Bank, RBL Bank, PayTM, TrueCaller, Intl Centre for Missing & Exploited Children.

Speaking on the occasion Mr KT Rama Rao said new-age crimes need new-age solutions. During Munugodu by-elections we realised that voters were lured with money transferred through digital payments. The Election Commission also needs to be sensitised on this matter. We live in a world where technology is everywhere. The devices outnumber the population. We are living in a connected world where devices talk between themselves. Under these circumstances, Cyber Security becomes a huge challenge he observed.

Speaking further he added that the sense of cyber crimes are not just confined to big cities but they are there and even spread to small and remote places. So we need to promote awareness. We need to promote 1930, an all-India toll-free number against cyber crimes. We need to build institutions like this Centre of Excellence rather than individuals. Processes are more important than people, he said.

He urged the industry to be part of this initiative. He appealed everyone to come forward. More than a million people work in the IT sector in the city. All must become cyber warriors. We are working on the first draft piece of legislation on Cyber Crimes. The work is under process. When it was ready and announced Telangana will be the first state to do so, he claimed with pride.

Newly inaugurated Centre of Excellence for Cyber Safety, a first of its kind in India to secure Cyber Ecosystem for the State
Newly inaugurated Centre of Excellence for Cyber Safety, a first of its kind in India to secure Cyber Ecosystem for the State

KTR urged the home minister and the top police leadership to work on the Registry of Sexual offenders. Sunitha Krishnan, a prominent social activist suggested it some time ago. Once those listed in the registry, will be prohibited from jobs and prohibited from using any facilities from the government.

Also, a participant in a Hackathon in the past suggested implementing a First Respondent Drone which can swiftly move to a crime scene much before the police arrive. He urged the home minister to start the work on these initiatives at the earliest possible time.

KTR launched ‘Crime OS’ a custom built Operating System on Microsoft Cloud, another first, built by city’s Start-up CyberEye
KTR launched ‘Crime OS’ a custom built Operating System on Microsoft Cloud, another first, built by city’s Start-up CyberEye

A customised Crime Operating System(Crime OS)  developed exclusively for this initiative by Hyderabad based Startup ‘CyberEye’ founded by a former DRDO expert, Ram Ganesh, who is also Director, Technical for the newly inaugurated Centre of Excellence(CoE) is launched by KTR. It is built on Microsoft Cloud.

www.tspcc.org, the website was launched. An SoP Book (Standard Operating Protocols) authored by ground police personnel was also unveiled

Mohd Mahmood Ali, Home Minister said the state has 64% of total CCTVs in India. Though there are not many crimes happening in this part,, most of our citizens are becoming victims of the cyber crimes done elsewhere, he said.

DGP Mr M. Mahender Reddy said today there are no crimes without digital components. And there are no individuals who are not impacted. So Police need to be relevant, and effective and must serve.

So we need to evolve from a physical force to a tech-savvy force. We must be the tech-based force which works with ease, he said.

Telangana Police is the best in the country. We have ten lakh CCTVs. Every citizen must be reassured that they are safe and that the police ensure their safety. Safety and Security are pre-requisite for the development of Telangana. Our goal is to keep Telangana safe in terms of the cyber ecosystem. The command control which was inaugurated some time ago will have dozens of Centres of Excellence, said Mr Mahender Reddy.

The Principal Secretary Jayesh Ranjan said the TS Police Centre of Excellence for Cyber Safety is yet another feather in the cap of Telangana Police, who already have stellar respect and are known for their pioneering efforts in utilising technology. He urged Mr Stephen Ravindra, Commissioner of Cyberabad to collaborate with other government CoEs. And he assured his help in facilitating the same.

Rajiv Kumar, MD of Microsoft India said post covid the nature of crimes used to be 80% conventional and 20% digital. Now it is reversed. And even that 20% has a digital component to it. TS Police Centre of Excellence for Cyber Safety is probably unique in the world.

Mr BVR Mohan Reddy, Founder Chairman Cyient said 5G which is around the corner is going to revolutionise the way we engage in future. It makes remote telesurgery possible. It is one of the many wonders we can expect in the future. At the same time, cyber crimes are galloping. There is a 150% increase in Cyber Crimes in the recent past. Hyderabad is the Happening City in the country. 50% of Tech Companies have their development centres in Hyderabad. He gave three suggestions for better policing. One is to develop a level of awareness so that reporting of crimes will go up. Two, the police must do capacity building in terms of expertise in Cyber Security. The third is to provide subject matter expertise to the police. He assured that his company will come forward to extend that help for the next two years.

Mr Stephen Ravindra, Commissioner of Police, Cyberabad said it is a dream come true to the Cyberabad Police in particular and Telangana Police in general. We need new-age policing which is in tune with the aspiration of the citizen and adoption of technology, work process. Policing has to be predictive, preventive and proactive.

Police must use technology as a force multiplier. Two lakh crore rupees worth of IT products and services are being exported from this state.

The Centre of Excellence is the new way of tackling the security challenges of the 21st century.

There is a compelling need to secure our digital ecosystem. It is the most sought-after initiative, an initiative of exceptional nature, said Mr Krishna Yedula, Secretary, SCSC in his welcome address.

Several top Police Officers, Government Officials, and Industry Captains, MP Ranjith Reddy, MLA A. Gandhi, MLC Naveen graced the launch.


ESET Research Uncovers New Cyberespionage Group Worok Targeting Companies, Govts Mostly in Asia

ESET Research Uncovers New Cyberespionage Group Worok Targeting Companies, Govts Mostly in Asia
  • ESET researchers have discovered a previously unknown cyberespionage group that they named Worok.
  • Worok has attacked various high-profile companies from the telecommunications, banking, maritime, energy, military, government, and public sectors. The targets are located mostly in Asia, but also in the Middle East and Africa.
  • Worok develops its own tools and leverages existing tools to compromise its targets. The group has used the infamous ProxyShell vulnerabilities to gain initial access in some cases. Its PowerShell backdoor PowHeartBeat has various capabilities, including command/process execution and uploading and downloading files.
yESET researchers recently discovered targeted attacks that used undocumented tools against various high-profile companies and local governments mostly in Asia, but also in the Middle East and Africa. These attacks were conducted by a previously unknown cyberespionage group that ESET has named Worok. According to ESET telemetry, Worok has been active since at least 2020 and continues to be active today. Among the targets were companies from the telecommunications, banking, maritime, energy, military, government, and public sectors. Worok used the infamous ProxyShell vulnerabilities to gain initial access in some cases.

"We believe the malware operators are after information from their victims because they focus on high-profile entities in Asia and Africa, targeting various sectors, both private and public, but with a specific emphasis on government entities,” says ESET researcher Thibaut Passilly who discovered Worok.

Back in late 2020, Worok was targeting governments and companies in multiple countries, specifically:
  • A telecommunications company in East Asia
  • A bank in Central Asia
  • A maritime industry company in Southeast Asia
  • A government entity in the Middle East
  • A private company in southern Africa
There was a significant break in observed operations from May 2021 to January 2022, but Worok activity returned in February 2022, targeting:
  • An energy company in Central Asia
  • A public sector entity in Southeast Asia
Worok is a cyberespionage group that develops its own tools and leverages existing tools to compromise its targets. The group’s custom toolset includes two loaders, CLRLoad and PNGLoad, and a backdoor, PowHeartBeat.

Technical Analysis

While the majority of initial accesses are unknown, in some cases through 2021 and 2022 we have seen exploits used against the ProxyShell vulnerabilities. In such cases, typically webshells have been uploaded after exploiting these vulnerabilities, in order to provide persistence in the victim’s network. Then the operators used various implants to gain further capabilities.

Once access had been acquired, the operators deployed multiple, publicly available tools for reconnaissance, including MimikatzEarthWormReGeorg, and NBTscan, and then deployed their custom implants: a first-stage loader, followed by a second stage .NET loader (PNGLoad).

Unfortunately, the ESET team have not able to retrieve any of the final payloads. In 2021, the first-stage loader was a CLR assembly (CLRLoad), while in 2022 it has been replaced, in most cases, by a full-featured PowerShell backdoor (PowHeartBeat) – both execution chains are depicted in Figure 2. These three tools are described in detail in the following subsections.

Worok compromise chains
Worok compromise chains

CLRLoad is a first-stage loader that was used in 2021, but in 2022 was replaced, in most cases, by PowHeartBeat. PNGLoad is a second-stage loader that uses steganography to reconstruct malicious payloads hidden in PNG images.

PowHeartBeat is a full-featured backdoor written in PowerShell, obfuscated using various techniques such as compression, encoding, and encryption. This backdoor has various capabilities, including command/process execution and file manipulation. For example, it is capable of uploading files to and downloading files from compromised machines; returning file information such as the path, length, creation time, access times, and content to the command and control server; and deleting, renaming, and moving files.

“While our visibility at this stage is limited, we hope that putting the spotlight on this group will encourage other researchers to share information about this group,” adds Passilly.
For more technical information about Worok, check out the blogpost “Worok: the big picture” on WeLiveSecurity. Make sure to follow ESET Research on Twitter for the latest news from ESET Research.

Visual heatmap of the targeted regions and verticals 

Cyberespionage Group Worok Targeting Companies, Govts Mostly in Asia
Map of the targeted regions and verticals




For more than 30 years, ESET® has been developing industry-leading IT security software and services to protect businesses, critical infrastructure and consumers worldwide from increasingly sophisticated digital threats. From endpoint and mobile security to endpoint detection and response, as well as encryption and multifactor authentication, ESET’s high-performing, easy-to-use solutions unobtrusively protect and monitor 24/7, updating defenses in real time to keep users safe and businesses
running without interruption. Evolving threats require an evolving IT security company that enables the safe use of technology. This is backed by ESET’s R&D centers worldwide, working in support of our shared future. 

Trust Lacking Within the Cybercriminal Underground - Trend Micro Research

Report details changing tactics and global demand for new malicious services like Deepfake ransomware and AI bots


Trend Micro Incorporated, a global leader in cybersecurity solutions, today released new data on cybercriminal operations and patterns for buying and selling goods and services in the underground. Trust has eroded among criminal interactions, causing a switch to e-commerce platforms and communication using Discord, which both increase user anonymization.

"This report highlights the threat intelligence we collect and analyze from global cybercriminal networks that enables us to alert, prepare and protect our corporate customers and partners," said Ed Cabrera, chief cybersecurity officer for Trend Micro. "This research helps us inform businesses early about emerging threats, such as Deepfake ransomware, AI bots, Access-as-a-Service and highly targeted SIM-swapping. A layered, risk-based response is vital for mitigating the risk posed by these and other increasingly popular threats."

The report reveals that determined efforts by law enforcement appear to be having an impact on the cybercrime underground. Several forums have been taken down by global police entities, and remaining forums experience persistent DDoS attacks and log-in problems impacting their usefulness.

Loss of trust led to the creation of a new site, called DarkNet Trust, which was created to verify vendors’ and increase user anonymity. Other underground markets have launched new security measures, such as direct buyer-to-vendor payments, multi-signatures for cryptocurrency transactions, encrypted messaging, and a ban on JavaScript.

The report also reveals the changing market trends for cybercrime products and services since 2015. Commoditization has driven prices down for many items. For example, crypting services fell from US$1,000 to just $20 per month, while the price of generic botnets dropped from $200 to $5 per day. Pricing for other items, including ransomware, Remote Access Trojans (RATs), online account credentials and spam services, remained stable, which indicates continued demand.

However, Trend Micro Research has seen high demand for other services, such as IoT botnets, with new undetected malware variants selling for as much as $5,000. Also popular are fake news and cyber-propaganda services, with voter databases selling for hundreds of dollars, and gaming accounts for games like Fortnite can fetch around $1,000 on average.

Other notable findings include the emergence of markets for:

  • Deepfake services for sextortion or to bypass photo verification requirements on some sites.

  • AI-based gambling bots designed to predict dice roll patterns and crack complex Roblox CAPTCHA.

  • Access-as-a-Service to hacked devices and corporate networks. Prices for Fortune 500 companies can reach up to US$10,000 and some services include access with read and write privileges.

  • Wearable device accounts where access could enable cybercriminals to run warranty scams by requesting replacement devices.


Trends in underground marketplaces will likely shift further in the months following the global COVID-19 pandemic, as attack opportunities continue to evolve. To protect against the ever-changing threat landscape, Trend Micro recommends a multi-layered defense approach to protect against the latest threats and mitigate corporate security risk.

To find out more and read the full report, please visit: https://www.trendmicro.com/vinfo/in/security/news/cybercrime-and-digital-threats/trading-in-the-dark

Cyber-criminals Mostly Targeted India's Banking, Govt, Critical Infrastructure in 2018-19

Banking and finance, government and critical infrastructure were among the most targeted sectors in India by cybercriminals in 2018-19, according to tech major Cisco.

Also, about 26 per cent of these overall attacks cost organisations in the country upwards of USD 5 million each.

"The hackers are persistent, and their campaigns are very targeted. We have found that sectors like banking and finance (20.1 per cent), government (19.6 per cent) and critical infrastructure (15.1 per cent) were among those that continue to face the highest threat of cyberattacks," Cisco India and SAARC Director (Security Business) Vishak Raman told PTI.

He added that cybercriminals are also increasingly targeting sectors like defence (15.1 per cent), IT, telecom and healthcare.

"They are using a host of mechanisms like point of sale attacks to target sectors like retail, hospitality, entertainment and e-commerce. Ransomware are used to attack public sector entities, transportation as well as banking and finance verticals," he said.

Raman cited an Asia-Pacific Security Capabilities Benchmark Study conducted by Cisco that found 21 per cent respondents saying cost of breach for them was between USD 5-9.9 million, while another 5 per cent said it was more than USD 10 million for them.

The cost of breach included loss of revenue, customers, and other costs related to the event. About 27 per cent said the cost of less than USD 100,000 -- an indication that while the amount involved may be small but the volume of such attacks is growing.

"Companies are now spending on not just protection but also increasingly on proactive threat hunting, more forensics," he said. PTI SR

Despite Talent, Tools India Can't Handle Big Cyber Attacks - Report

India is a land of abundant talent. We all know that by now, but despite of having such talented workforce, the country is still unprepared to protect itself if a cyberattack to the scale of ‘WannaCrypt’ or ‘Petya’ ever hits home turf.

According to a recent IBM study conducted by Ponemon Institute, while the average cost of a data breach in 2017 decreased by 10 per cent globally when compared to the 2016 figure, but for the Indian enterprises, it grew by 12.3 percent from Rs 97.3 million in 2016 to Rs 110 million in 2017.

Elaborating on the findings of the report, John Shier, Senior Security Expert at the Abingdon, UK-headquartered Sophos, did an interview with IANS and said, “India has well-trained, well-educated and capable IT people. The country has got access to all the tools it needs to secure its systems. Yet, in the case of a big cyber attack, India is still unprepared.”

Giving solution to the problem he mentions, Shier said that the country needs to do just three simple things to fix the issue to a certain extent, he said, “It is the time to look at the procedures and make sure they are implemented to secure the data. Firstly, it is needed to see that the things are done. Secondly, it needs to be checked if the things are done correctly and thirdly, test it repeatedly to make sure what has been done is done right.”

Sher believes that by doing the basics right, the companies can helps cybersecurity firms in staying one step ahead of the criminals.

The survey conducted by Ponemon Institute found out that at 41 per cent, malicious or criminal attacks were the main cause of data breach for the companies surveyed. The report also revealed that almost 33 per cent of the companies surveyed that experienced a data breach were a result of a system glitch and 26 per cent breaches were caused due to contractor or employee negligence.

It is important to understand that eliminating cyber risks completely is not possible as of yet, but one can still reduce these risks to a minuscule level by having well-configured security measures at place that keep an eye on illegal intrusion. The security measures being referred here are up-to-date softwares and firewalls.

However, often it is not the software or hardware that fails us, it is the human factor. In a majority of cyberattack cases, they enter the system by sending malicious emails to employees who out of curiosity end up taking the bait making the whole company system vulnerable.

This development was first reported by IANS’ Sourabh Kulesh.

[Image: Shutterstock]

Cyber crimes cost India $4 billion in 2013

cybercrime cost India

India might be having the slowest internet speed in Asia but the cyber criminals in the country are for sure having a ball. According to a recently released Delhi High Court-commissioned report, Cyber Crimes have cost India losses worth Rs. 24,630 crore i.e. around USD $4 billion, in the last year alone.

According to the report, the cyber criminals have become much more advanced and used sophisticated means like spear-phishing and ransomware to carry out these internet frauds.

Surinder S Rathi, additional district judge and OSD to Delhi Legal Service Authority (DLSA), submitted the facts and figures in a report before the court in the demand that a direction should be released for a comprehensive study to be done on various issues including the cost incurred in operating the criminal justice system.

JR Midha and Gita Mittal, who constitute the bench of justices, are yet to announce the punishment to the three convicts in the Nitish Katara 2002 murder case.  The bench of justices had also instructed the DLSA to calculate the cost incurred in the trial of this particular case.

The report gives no more details about cyber crime stalking in India. According to the National Crime Records Bureau data, in 2013, 66.40 lakh criminal complaints were filed across the nation. Out of these, Delhi, the national capital accounted for around 86,800 complaints.

According to the report, globally, most of the countries have realized the extravagant financial cost of operating the criminal justice system but our own country has still not seen the light. All the wings of the system are utterly confused and overburdened due to unscientific and mindless planning.

India has not been able to control incidents of crime even after having some odd 12,700 police stations and 15.70 lakh policemen working in them. The police, which is the first ring of criminal justice system, is itself in a very bad state across the nation.

The report also said that there is an immediate need to form a comprehensive methodology for computing the costs incurred by the nation on the account of various criminal acts. Till now, no empirical study has been carried out to know how much does a criminal case cost to the exchequer at the tax payer right from the filling of the First Information Report to its conclusion post the trail in sentencing.

Cyber crimes cost India $4 billion in 2013

cybercrime cost India

India might be having the slowest internet speed in Asia but the cyber criminals in the country are for sure having a ball. According to a recently released Delhi High Court-commissioned report, Cyber Crimes have cost India losses worth Rs. 24,630 crore i.e. around USD $4 billion, in the last year alone.

According to the report, the cyber criminals have become much more advanced and used sophisticated means like spear-phishing and ransomware to carry out these internet frauds.

Surinder S Rathi, additional district judge and OSD to Delhi Legal Service Authority (DLSA), submitted the facts and figures in a report before the court in the demand that a direction should be released for a comprehensive study to be done on various issues including the cost incurred in operating the criminal justice system.

JR Midha and Gita Mittal, who constitute the bench of justices, are yet to announce the punishment to the three convicts in the Nitish Katara 2002 murder case.  The bench of justices had also instructed the DLSA to calculate the cost incurred in the trial of this particular case.

The report gives no more details about cyber crime stalking in India. According to the National Crime Records Bureau data, in 2013, 66.40 lakh criminal complaints were filed across the nation. Out of these, Delhi, the national capital accounted for around 86,800 complaints.

According to the report, globally, most of the countries have realized the extravagant financial cost of operating the criminal justice system but our own country has still not seen the light. All the wings of the system are utterly confused and overburdened due to unscientific and mindless planning.

India has not been able to control incidents of crime even after having some odd 12,700 police stations and 15.70 lakh policemen working in them. The police, which is the first ring of criminal justice system, is itself in a very bad state across the nation.

The report also said that there is an immediate need to form a comprehensive methodology for computing the costs incurred by the nation on the account of various criminal acts. Till now, no empirical study has been carried out to know how much does a criminal case cost to the exchequer at the tax payer right from the filling of the First Information Report to its conclusion post the trail in sentencing.

Market Reports

Market Report & Surveys
IndianWeb2.com © all rights reserved