Visualização normal
-
ASEC BLOG
-
July 2026 Dark Web Breach Incident Trend Report
Note The July 2026 Dark Web Breach Incident Trend Report was compiled based on data breach cases posted on deep web and dark web forums. Due to the nature of some posts, it is difficult to fully verify their accuracy; some posts related to South Korea included AI-generated false data or cases where it could […]
-
Firewall Daily – The Cyber Express

-
India Tightens Social Media Rules to Protect Children Online
India online safety rules are being strengthened as the government steps up measures to protect children and other users from harmful digital content, cyber risks and emerging threats linked to artificial intelligence. The government said its policies are aimed at ensuring an open, safe, trusted and accountable internet, with recent measures focusing on child safety, privacy protection, faster content removal and stronger platform responsibilities. The Information Technology Act, 2000, and the
India Tightens Social Media Rules to Protect Children Online
![]()
India online safety rules are being strengthened as the government steps up measures to protect children and other users from harmful digital content, cyber risks and emerging threats linked to artificial intelligence. The government said its policies are aimed at ensuring an open, safe, trusted and accountable internet, with recent measures focusing on child safety, privacy protection, faster content removal and stronger platform responsibilities.
The Information Technology Act, 2000, and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, form the core legal framework governing online safety and intermediary responsibilities in India. The government has also highlighted the Digital Personal Data Protection Act, 2023, and recent amendments to the IT Rules as part of its broader approach to digital safety.
India Online Safety Rules Tighten Platform Responsibilities
Under the IT Rules, intermediaries are required to observe due diligence and inform users that they must not host, display, upload, modify, publish, transmit, update or share content that is harmful to children or violates applicable laws.
Recent amendments require social media platforms and other intermediaries to remove unlawful content within three hours of receiving an order from a competent court or a reasoned intimation from the appropriate government or its agency.
The government has also outlined specific obligations related to content involving nudity, impersonation and other sensitive material. In cases involving certain complaints about content featuring full or partial nudity, exposed private areas or artificially morphed images, intermediaries must take reasonable and practicable measures to remove or disable access within two hours.
Government Targets Harmful Content and OTT Platforms
The government said it has taken action against online platforms and OTT services over unlawful and obscene content. In the last two years, 50 OTT platforms have been disabled for public access in India for displaying obscene content and violating provisions including Sections 67 and 67A of the IT Act, Section 294 of the Bharatiya Nyaya Sanhita and the Indecent Representation of Women (Prohibition) Act, 1986.
The government also said it has taken note of reports alleging the dissemination of advertisements linked to child sexual abuse material (CSAM) on social media platforms and sought a detailed report from the concerned intermediary. The National Commission for Protection of Child Rights has also issued notices to the concerned platforms.
India Strengthens AI-Generated Content Safeguards
The government has also expanded its regulatory focus to address risks associated with AI-generated content and synthetically generated information. Amendments to the IT Rules introduce requirements for clear labelling and traceable metadata for permissible AI-generated content, allowing users to identify synthetically generated material.
The framework also strengthens platform accountability and requires greater user awareness about the legal consequences of unlawful AI-generated content. The rules specifically cover harmful material including CSAM, non-consensual intimate imagery and impersonation.
Platforms are required to deploy reasonable and appropriate technical measures, including automated tools or other mechanisms, to prevent users from creating, modifying, publishing or sharing synthetically generated information that violates applicable laws.
Significant Social Media Intermediaries are also required to make reasonable efforts to deploy technical measures to proactively identify content depicting rape, child sexual abuse or conduct, as well as content identical to information previously removed.
Child Privacy and Digital Addiction Remain Key Concerns
The Digital Personal Data Protection Act, 2023, provides a framework for protecting children's privacy online. It mandates parental consent for processing children's personal data and prohibits practices considered detrimental to children's well-being, including tracking, behavioural monitoring and targeted advertising directed at children.
The government has also highlighted digital addiction as a serious challenge affecting children and young people. The Economic Survey 2025-26 noted potential impacts on cognitive development, academic performance, workplace productivity, social connectedness and mental health, alongside risks linked to cyberbullying, compulsive gaming, social media and online gambling.
Cyber Awareness Reaches 11.37 Lakh Participants
Alongside regulatory measures, the government is expanding cyber awareness initiatives through the Information Security Education and Awareness project. So far, 6,650 awareness workshops have been conducted nationwide, reaching more than 11.37 lakh participants, including students, teachers, law enforcement officials, government personnel and members of the public.
The government has also highlighted digital safety initiatives in education. The PRAGYATA Guidelines provide a framework for safe online learning and responsible use of social media and electronic devices. CBSE has introduced digital etiquette and cybersecurity training initiatives, while NCERT has incorporated cyber safety into its curriculum.
The measures were outlined by Union Minister for Electronics and Information Technology Ashwini Vaishnaw in the Lok Sabha on July 22, 2026, as the government continues to strengthen its approach to c child protection and accountability across India's digital ecosystem.
-
ASEC BLOG
-
June 2026 Security Issues in Korean & Global Financial Sector
Statistics on Malware Distributed to the Financial Sector In the June threat analysis for the financial sector, phishing was the most prevalent attack method in Attack Stage 1, while droppers/downloaders (distribution tools that download additional malware) were the most prevalent in Attack Stage 2. Infostealers were identified in the third attack stage, indicating that multi-stage […]
June 2026 Security Issues in Korean & Global Financial Sector
-
Graham Cluley
-
Smashing Security podcast #476: Remote-control rickshaws and rogue book marketers
An app has appeared in India that lets anyone with a smartphone stop a passing e-rickshaw dead in its tracks - no login, no passwords, no permissions needed. Meanwhile, Geoff - swimming in money and Lamborghinis, as all published authors are - has been on the receiving end of a slew of AI-generated scam pitches from fake book marketing experts. Rather than ignore them, he's been playing them at their own game... All this and more in this episode of the "Smashing Security" podcast with cyb
Smashing Security podcast #476: Remote-control rickshaws and rogue book marketers
-
SentinelLabs

-
One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforcement
Executive Summary SentinelLABS has been tracking sustained cyberespionage activity against several Pakistani law enforcement organizations, taking place from February 2024 to April 2026. All these actors converged on Balochistan Police over this period, bringing both a partner and an adversary of Pakistan to the same police force in a province shaped by a separatist insurgency and the regional tensions it has drawn in. At Balochistan Police, the compromised assets included servers hosting web a
One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforcement
Executive Summary
- SentinelLABS has been tracking sustained cyberespionage activity against several Pakistani law enforcement organizations, taking place from February 2024 to April 2026.
- All these actors converged on Balochistan Police over this period, bringing both a partner and an adversary of Pakistan to the same police force in a province shaped by a separatist insurgency and the regional tensions it has drawn in.
- At Balochistan Police, the compromised assets included servers hosting web applications that manage police and citizen data, such as criminal and biometric records.
- A suspected China-nexus actor planted implants in one of the web applications, which serves both police staff and citizens, weaponizing a tool of Pakistan’s police digitalization against its users.
- Pakistani law enforcement organizations attract cyber collection because they hold information on Pakistan’s internal security that regional powers have an incentive to pursue.
- For China, the likely primary concern is the safety of its nationals, the target of repeated deadly attacks Pakistan has failed to prevent, leading Beijing to assess that threat for itself rather than rely on its partner alone.
- For India, the strongest motive is probably its rivalry with Pakistan, with Balochistan Police offering insight into the security posture of a Pakistani province prominent in wider mutual accusations over cross-border support for militancy.
Overview
Suspected China- and India-nexus threat actors carried out intrusions into several Pakistani law enforcement organizations between 2024 and 2026. Our analysis of C2 netflow data revealed that suspected China- and India-nexus threat actors operating PlugX, ShadowPad, Cobalt Strike, and Remcos infrastructure have converged on this victim class.
All of these threat actors were active against Balochistan Police, the principal police force serving the Pakistani province of the same name, at various points between 2024 and 2026. The affected assets spanned network appliances and servers hosting web applications that manage biometric records, hotel and tenant registrations linked to national identity records, criminal case files, and personnel records. A suspected China-nexus threat actor also compromised one of these web applications, deploying custom implants masquerading as a portal update. The application is used by police staff and by citizens interacting with law enforcement through it, and the compromise put both user groups within the threat actor’s reach.
When multiple cyberespionage actors operate against law enforcement institutions of a single state, the convergence itself is a signal of target value. What draws them is a particular kind of institution: one that holds the government’s internal security picture, what it knows about the threats inside its borders, and how it acts against them. Each of the states suspected to be behind the activities covered in this post has its own stake in the threats monitored by Pakistani law enforcement.
Strategic Motives | Distrust and Accusations
The China-nexus activity is most likely motivated primarily by concern for the safety of Chinese nationals. Their presence across Pakistan is substantial, tied in large part to the China-Pakistan Economic Corridor (CPEC), Beijing’s flagship Belt and Road infrastructure program in the country. Chinese nationals have been the target of repeated deadly attacks, some of which were claimed by the Balochistan Liberation Army (BLA), a Baloch separatist group opposed to China’s presence in the Pakistani resource-rich southwest. Notable attacks include the October 2024 Karachi airport attack and the March 2024 suicide bombing in northwestern Pakistan.
The attacks have fueled explicit Chinese dissatisfaction with Pakistani counter-militancy performance. In October 2024, China’s Ambassador to Pakistan publicly called them “unacceptable”, warning that the security situation was the main obstacle to CPEC. The threat to Chinese nationals remains unresolved. As recently as January 2026, China’s Minister of Public Security and Pakistan’s Interior Minister agreed to expand counterterrorism coordination, deepen police training exchanges, and establish a special unit in Islamabad to protect Chinese nationals.
Pakistani law enforcement is a natural collection target for China. The data it holds would let China assess the security environment its nationals face independently, rather than relying on a partner whose protection has repeatedly fallen short.
For the India-nexus activity, which was focused on Balochistan, the strongest motive is probably the adversarial security relationship between India and Pakistan, in which the province is a recurring flashpoint. Pakistan has long accused India of backing the Baloch insurgency, describing the BLA as an “Indian proxy“, a charge it has not publicly substantiated and that India denies. India, in turn, accuses Pakistan of backing the militant groups behind attacks in Indian-administered Kashmir, which Pakistan denies.
The Baloch insurgency is a front in the antagonism between the two states, and Balochistan Police would hold the operational record of how Pakistan manages the province’s security. For India, that material could offer visibility into a conflict at the center of the accusations and counter-accusations between them.
Balochistan Police is the same law enforcement institution the China-nexus actors were active against, approached from the opposite direction. To China, it is the police force of a partner that cannot be trusted to protect Chinese nationals in Balochistan. To India, it is the police force of a rival, with deep insight into the security of a province central to the friction between the two states.
Intrusions Into Pakistani Law Enforcement Organizations
We observed the highest concentration of intrusions at Balochistan Police. They affected network appliances and web servers hosting several of its web applications, one of which, the Complaint Management System (CMS), drew particular attention. The next two sections discuss the impacted assets in greater detail.
We also identified compromised infrastructure associated with several other Pakistani law enforcement organizations:
- the Khyber Pakhtunkhwa Police, the police force of Khyber Pakhtunkhwa province;
- the Islamabad Police, which serves the Islamabad Capital Territory;
- the Punjab Safe Cities Authority (PSCA), an autonomous government body that operates the integrated command, control and communication system for the police in the major cities of Punjab province.

We group the C2 activity we observed against all these targets into four clusters, each associated with a single malware family or tool: PlugX, ShadowPad, Cobalt Strike, and Remcos.
Because we cluster based on tooling, not on actor attribution, the number of threat actors behind each C2 activity cluster differs. We associate the Remcos cluster with a single actor, while the PlugX, ShadowPad, and Cobalt Strike clusters are built on shared or commodity tooling and may each involve more than one operator.
The table below presents the constituent servers of each C2 activity cluster, along with the first and last dates on which any of its servers communicated with Pakistani law enforcement infrastructure. The figure that follows shows how each cluster’s activity was distributed across the targeted organizations over time.
| C2 activity cluster | C2 servers | First seen | Last seen |
| PlugX | 172.111.233[.]36, 172.111.233[.]96, 172.111.233[.]12, 172.111.233[.]105, 172.111.233[.]26, 172.94.9[.]49, 172.94.9[.]43, 172.94.9[.]19, 45.74.6[.]17 | 27 February 2024 | 28 September 2024 |
| ShadowPad | 45.125.32[.]218 | 5 November 2024 | 29 November 2024 |
| Cobalt Strike | 142.171.183[.]8, 193.42.25[.]65 | 12 October 2024 | 5 December 2025 |
| Remcos | 89.31.121[.]220 | 13 January 2026 | 9 April 2026 |

The sections below cover the basis for each cluster’s attribution and its broader victimology. The observation windows we present there are generally wider, spanning all per-cluster victims.
C2 Activity Cluster | PlugX and ShadowPad
PlugX and ShadowPad point to China-nexus cyberespionage groups on the basis of the tooling itself, since both are backdoors shared among multiple such groups. The victimology we observed for PlugX (between 27 February and 28 September 2024) and ShadowPad (between 3 August and 1 December 2024) reinforces this assessment.
Beyond Pakistani law enforcement, victimology for PlugX and ShadowPad includes government, foreign affairs, defense, nongovernmental, and research entities across South, Southeast, Central, and East Asia, the Arabian Peninsula, and Southeast Europe, consistent with China-aligned collection.
C2 Activity Cluster | Remcos
We attribute the Remcos C2 server 89.31.121[.]220 to a suspected India-nexus threat actor, which Recorded Future tracks as TAG-179. Its infrastructure, tooling, and TTPs overlap to varying degrees with those of the threat actors tracked by Kaspersky as Mysterious Elephant and by Qihoo 360 as APT-C-08 (a.k.a. Bitter).
Our data shows that TAG-179 has been intensifying its activities and diversifying its TTPs since early 2025. This trend aligns with the prior research from Kaspersky and Qihoo 360, which documents in detail the tooling and infection chains used across 2025 and 2026.
Notably, Qihoo 360 describes a chain that delivers a Remcos backdoor configured with the same server that constitutes our Remcos C2 activity cluster (89.31.121[.]220). The IOC table of this report lists several lure files and backdoor components that we associate with TAG-179.
Among the lures is one with direct relevance to Pakistani law enforcement: it displays a decoy document posing as an operational plan for the repatriation of illegal foreigners, including Afghan Citizen Card (ACC) holders. These are Afghan nationals who have been granted temporary registration in Pakistan and are targeted for deportation under Pakistan’s Illegal Foreigners’ Repatriation Plan.
The decoy document outlines coordination among district-level police forces, the National Database and Registration Authority (NADRA, an agency of the Pakistani Ministry of Interior), and Pakistani intelligence organizations. Its subject matter is consistent with the Pakistani law enforcement victimology of TAG-179, making it an example of a plausible lure against this target class.

Within our observation window for the Remcos C2 activity (from 20 November 2025 to 21 April 2026), the victimology outside Pakistani law enforcement includes government, defense, foreign affairs, intelligence, research, and manufacturing entities across South and Southeast Asia, and the Middle East.
C2 Activity Cluster | Cobalt Strike
Although Cobalt Strike is a commodity tool that carries no inherent attribution, we attribute with medium confidence both servers in this C2 activity cluster to China-nexus threat actors.
The C2 traffic to 142.171.183[.]8, spanning 13 September 2024 to 5 December 2025, reveals victimology extending beyond Pakistani law enforcement to government, academic, telecommunications, and non-governmental entities across South, East, and Southeast Asia, the Middle East, and South America, in line with a China-aligned targeting profile. Among these entities are Tibetan Buddhist organizations in Taiwan, a long-standing Chinese cyberespionage interest.
For 193.42.25[.]65, we observed C2 communications only with Balochistan Police infrastructure, taking place between 7 November and 5 December 2024. 193.42.25[.]65 also served as next-stage infrastructure for one of two implants deployed on the Balochistan Police CMS web application. We trace these implants to a Chinese-speaking developer through related samples sharing the same development environment, a topic we discuss in greater detail in a later section.
Balochistan Police | Compromised Assets
Across the four C2 activity clusters, C2 communications involving the following Balochistan Police assets took place between 2 June 2024 and 9 April 2026:
- two network appliances;
- web servers hosting several Balochistan Police web applications;
- a Fortinet FortiMail appliance that had served as Balochistan Police’s primary inbound email gateway.
At the time of this activity, the FortiMail appliance was no longer the designated inbound email gateway, but it remained operational on the network and may have continued to process outbound or internal mail relay traffic. Its compromise may therefore have additionally exposed email traffic it processed.
Many of the web applications hosted on the affected servers are part of the Smart Police Station initiative, an EU-supported effort to modernize Balochistan policing and improve how it serves the public through digitalization. Throughout the threat actor activities, the web servers hosted a mix of public-facing applications through which citizens and businesses access policing services, alongside restricted police applications protected by firewalls against unauthorized external access.
The table below summarizes the application functions as described in publicly available documentation.
| Application | Function |
| First Information Report (FIR) | Application for FIR registration and management. FIRs are documents prepared by police upon receiving information about the commission of a cognisable offence. |
| Human Resource Management Information System (HRMIS) | Personnel database managing officer service records, transfers, postings, payroll, and performance evaluations. |
| Anti-Vehicle Lifting System (AVLS) | Database for tracking stolen vehicles, their recovery, and investigation. |
| HotelEye | System for hotel guest check-in logging, integrated with NADRA identity records to notify police when individuals with criminal records check in. |
| Criminal Record Management System (CRMS) | Criminal records database with fingerprint-based biometric matching. |
| Tenant Registration System (TRS) | Landlord-tenant registration platform integrated with criminal records. |
| Complaint Management System (CMS) | Platform for registering, tracking, and resolving citizen complaints, from reports of crime and loss of documents to complaints about police misconduct. |
If the threat actors could reach the data stores backing these applications from the compromised servers, the data they could obtain would span police personnel records, criminal case files, biometric records, stolen vehicle records, hotel guest check-in records, tenant registration records, and citizen complaints. Together, it would provide broad visibility into Balochistan Police’s operational posture, capabilities, and intelligence activities.
Balochistan Police | CMS Compromise
The CMS web application, accessible at cms.balochistanpolice[.]gov[.]pk and hosted on one of the affected Balochistan Police web servers, was also compromised. Based on shared infrastructure and a common focus on Balochistan Police, we associate this intrusion with the threat actor operating 193.42.25[.]65, a constituent of the Cobalt Strike C2 activity cluster.
The landing page at cms.balochistanpolice[.]gov[.]pk features a login interface and a separate search form.

Access behind the login interface is highly likely restricted to law enforcement personnel. Stolen login credentials for the portal, which we retrieved from information stealer logs published on the dark web, reveal a consistent naming convention across the recovered usernames: a ps- prefix (most probably denoting “police station”) followed by a district or city within Balochistan, such as ps-barkhan.
In contrast, the search form, which posts to /Complaint/PublicSearch and accepts a complaint reference number and mobile number, is evidently intended to allow citizens to check the status of a filed complaint.
We therefore assess with high confidence that the CMS application serves two distinct user groups: law enforcement personnel and citizens.
Based on VirusTotal data, two variants of an implant named cms_plugin.exe were uploaded to cms.balochistanpolice[.]gov[.]pk/client%20scripts/ in late 2024, one written in the Rust programming language, the other compiled as a .NET executable. The Rust executable is a malware stager that downloads a payload from 193.42.25[.]65 and executes it. We could not retrieve the next stage at the time of analysis.
The .NET executable masquerades as 360Safe.exe, a component of the endpoint security software 360 Safe Guard from the Chinese vendor Qihoo 360. It reflectively loads an assembly implementing an AsyncRAT client, which is configured to use 41.216.188[.]140 as its C2 server. The assembly has a PDB path of D:\codedome\case\six\Client\Client2\obj\Debug\Client2.pdb.
Pivoting on the D:\codedome prefix, we identified multiple additional samples highly likely built in the same development environment. Several are AsyncRAT clients that share implementation patterns with the one embedded in cms_plugin.exe, such as variable naming and string obfuscation, reinforcing a common origin beyond the shared PDB prefix. Some contain Chinese-language terms in pinyin in their PDB paths, such as xinshi (likely 新式, “new type” or “new variant”), and one includes log messages in simplified Chinese. These indicators point to a Chinese-speaking developer behind the samples linked by the D:\codedome prefix, including the one deployed on the Balochistan Police CMS application.

Pivoting on the cms_plugin.exe filename, we identified a third malware stager functionally similar to the Rust variant, also downloading the next stage from 193.42.25[.]65.
Both cms_plugin.exe samples downloading from 193.42.25[.]65 display the message Update Complete! Please refresh the page upon execution, mimicking an update for the CMS portal.
The fake update prompt, combined with the cms_plugin.exe filename and the hosting location in the portal’s /client scripts/ directory, indicates that the implants were targeted at users of the CMS platform: police staff, citizens checking complaint status, or both. Successful infection would grant the threat actor access to the victim’s device. In the case of police personnel, this could provide a foothold into internal police networks and access to operational data beyond the CMS platform. In the case of citizens, it would enable surveillance of those who have filed complaints through the platform.
Conclusion
The intrusions we cover in this post show how domestic security institutions can become high-value intelligence targets when the threats they monitor overlap with foreign intelligence requirements. Balochistan Police sits at such an intersection, attracting cyberespionage activity from both a partner and an adversary of Pakistan. For China-nexus actors, access to its systems could support independent assessment of threats to Chinese nationals and interests in the country. For India-nexus actors, such access provides visibility into how Pakistan manages security in a province central to its adversarial relationship with India.
The compromise of the Complaint Management System web application adds a second dimension to the activity against Balochistan Police, extending the threat actor’s reach beyond the initially compromised environment. By hosting implants in a portal used by both citizens and law enforcement personnel, the threat actor turned a tool built to make policing in Pakistan more accessible and accountable to the public into a malware delivery mechanism. This weaponization widened the collection surface from the application and its data to the users interacting with it.
The multi-actor convergence on Balochistan Police points to a structural consequence of digital policing. Systems built to centralize records, workflows, and public interaction can also centralize intelligence value by bringing together operational, institutional, and civilian data across connected environments. Law enforcement infrastructure in that setting is no longer just the digital backbone of policing but intelligence terrain, and it will be treated as such by any adversary who can reach it.
Indicators of Compromise
SHA-1 Hashes
| Value | Note |
| 000fad96a85dd6933c22d3dbec9aed47b7f1f066 | Backdoor launcher (TAG-179) |
| 08570471f39bb6725f07b8cddbea99ed48c22686 | Backdoor launcher (TAG-179) |
| 23f4766c011d193f076dfc735dc460e2a41ead79 | Backdoor launcher (TAG-179) |
| 23f6781919a50b118d8d4e6a7e9ae63b71ecc885 | cms_plugin.exe |
| 2bab40c55637398f0497cff9c8cbea564d595c7f | Lure file (TAG-179) |
| 4039454c9189e64285e93fc075a30b93f814b5b5 | cms_plugin.exe |
| 47f8cb0c2dcf62702f58cfc1603d6325755f6820 | Backdoor launcher (TAG-179) |
| 539bd79fbb684edea94eb37518134b97e94b9dd8 | Lure file (TAG-179) |
| 58cb2d95063b9df807b7aa8dc106b74ce988a491 | cms_plugin.exe |
| 5d60ff36ff519c2e13e7f66cfa0bb46be79592a7 | Backdoor (TAG-179) |
| 63b88d00331de88af696dfb7a896935d830e485f | Backdoor (TAG-179) |
| 6fe2e74d009abbd56de01fd7404a1245e9b47c79 | Lure file (TAG-179) |
| 71757adba833b46f961e840d0f055bcce0b529c4 | Lure file (TAG-179) |
| 8c329db96e093fa25268e078405a33c518dbb5c9 | Backdoor (TAG-179) |
| c6c197e61079a0a33108c2c87b5e3c7056a138ec | Lure file (TAG-179) |
| d66ab0cd2e44dc8389c111b7ed34c7bcb0b35311 | Backdoor (TAG-179) |
IP Addresses
| Value | Note |
| 142.171.183[.]8 | Cobalt Strike C2 server |
| 172.111.233[.]105 | PlugX C2 server |
| 172.111.233[.]12 | PlugX C2 server |
| 172.111.233[.]26 | PlugX C2 server |
| 172.111.233[.]36 | PlugX C2 server |
| 172.111.233[.]96 | PlugX C2 server |
| 172.94.9[.]19 | PlugX C2 server |
| 172.94.9[.]43 | PlugX C2 server |
| 172.94.9[.]49 | PlugX C2 server |
| 193.42.25[.]65 | Cobalt Strike C2 server |
| 41.216.188[.]140 | AsyncRAT C2 server |
| 45.125.32[.]218 | ShadowPad C2 server |
| 45.74.6[.]17 | PlugX C2 server |
| 89.31.121[.]220 | Remcos C2 server |
URLs
| Value | Note |
| https[://]cms.balochistanpolice[.]gov[.]pk/client%20scripts/cms_plugin.exe | Implant-hosting URL on the Balochistan Police CMS portal |

-
DCiber
-
Megavazamento de 24 bilhões de credenciais e bloqueio do Telegram na Índia expõem nova fase do crime digital
Dois acontecimentos recentes acenderam um alerta global sobre a evolução das fraudes digitais e a profissionalização do crime cibernético. De um lado, pesquisadores da Cybernews identificaram uma base exposta contendo aproximadamente 24 bilhões de registros de credenciais, incluindo e-mails, nomes de usuário, senhas em texto claro e URLs de acesso. De outro, o governo da Índia bloqueou temporariamente o Telegram após suspeitas de que grupos organizados estariam utilizando a plataforma para tenta
Megavazamento de 24 bilhões de credenciais e bloqueio do Telegram na Índia expõem nova fase do crime digital
Dois acontecimentos recentes acenderam um alerta global sobre a evolução das fraudes digitais e a profissionalização do crime cibernético. De um lado, pesquisadores da Cybernews identificaram uma base exposta contendo aproximadamente 24 bilhões de registros de credenciais, incluindo e-mails, nomes de usuário, senhas em texto claro e URLs de acesso. De outro, o governo da Índia bloqueou temporariamente o Telegram após suspeitas de que grupos organizados estariam utilizando a plataforma para tentar fraudar candidatos do NEET 2026, principal exame nacional de admissão para cursos de medicina do país. Para a LC SEC, consultoria especializada em cibersegurança e compliance, os dois episódios evidenciam a crescente profissionalização do crime digital.
Segundo informações divulgadas pela Cybernews, a base reúne dados provenientes de diferentes fontes, incluindo infostealers, compilações de vazamentos anteriores e outras exposições digitais acumuladas ao longo dos anos. Embora ainda não seja possível determinar quantos registros são duplicados ou quantas pessoas únicas foram afetadas, a consolidação desse volume de informações em um único conjunto amplia significativamente o potencial para ataques de tomada de contas, fraudes financeiras e invasões corporativas.
Na Índia, o caso envolvendo o Telegram também chamou a atenção pela escala da operação, pois, segundo informações divulgadas pela Reuters, o bloqueio temporário da plataforma ocorreu após autoridades apontarem que grupos organizados teriam utilizado o aplicativo para coordenar tentativas de fraude relacionadas ao exame NEET 2026. O episódio ganhou repercussão nacional após o cancelamento dos resultados de cerca de 2,3 milhões de estudantes em meio a investigações sobre possível vazamento de questões e irregularidades no processo seletivo.
Embora distintos, os dois casos compartilham um elemento importante: a utilização de plataformas digitais como parte da infraestrutura que sustenta operações criminosas. Ao rastrear a origem dos dados presentes na base identificada pela Cybernews, os pesquisadores encontraram 36 fontes distintas de informação. Segundo a investigação, grande parte delas estaria associada a canais do Telegram utilizados para compartilhamento de credenciais roubadas, dados obtidos em violações de segurança e materiais relacionados a atividades ilícitas.
“O aspecto mais relevante desses casos é que eles mostram como o crime digital funciona atualmente. Não estamos falando apenas de vazamentos ou de uma plataforma específica, mas de um ecossistema onde dados roubados são coletados, organizados, compartilhados e utilizados por diferentes grupos criminosos. O Telegram aparece nesse contexto como um dos canais identificados para circulação dessas informações, evidenciando como plataformas digitais podem ser incorporadas à cadeia operacional das fraudes”, afirma Luiz Cláudio, CEO e fundador da LC SEC.
O cenário acompanha uma tendência observada globalmente pelo relatório Microsoft Digital Defense de 2025, que aponta que mais de 97% dos ataques contra identidade são baseados em senhas e que esse tipo de ameaça cresceu 32% no primeiro semestre de 2025. O relatório também destaca que mecanismos de autenticação multifator resistentes a phishing são capazes de bloquear mais de 99% desses ataques.
Na avaliação do especialista, o foco das organizações não deve estar apenas na proteção de sistemas, mas também na gestão da identidade digital. “Quando credenciais comprometidas passam a circular livremente, os criminosos conseguem assumir contas legítimas, acessar ambientes corporativos e utilizar essas informações para ataques mais sofisticados. A identidade digital se tornou um dos ativos mais valiosos e mais visados do ambiente corporativo”, explica Luiz Claudio.
Diante desse cenário, a LC SEC recomenda que empresas revisem suas políticas de autenticação, ampliem o uso de autenticação multifator (MFA), fortaleçam processos de validação de identidade e monitorem continuamente credenciais expostas. A adoção de estratégias de Threat Intelligence, avaliações periódicas de acessos privilegiados e programas permanentes de conscientização também são medidas importantes para reduzir riscos e antecipar movimentos de grupos criminosos.
-
Security | TechRepublic
-
Tata Electronics Leak Exposes 200,000 Files, Including Apple and Tesla Documents
Tata Electronics is investigating a cyber incident after leaked files reportedly included manufacturing documents for Apple and Tesla. The post Tata Electronics Leak Exposes 200,000 Files, Including Apple and Tesla Documents appeared first on TechRepublic.
Tata Electronics Leak Exposes 200,000 Files, Including Apple and Tesla Documents
Tata Electronics is investigating a cyber incident after leaked files reportedly included manufacturing documents for Apple and Tesla.
The post Tata Electronics Leak Exposes 200,000 Files, Including Apple and Tesla Documents appeared first on TechRepublic.
-
Security | TechRepublic
-
Mukesh Ambani’s Reliance AI Roadmap Puts Jio CallAgent Inside the Network
Reliance’s AI roadmap puts Jio CallAgent inside the telecom network while tying India-scale AI ambitions to Jamnagar compute, local-language services, and enterprise compliance questions. The post Mukesh Ambani’s Reliance AI Roadmap Puts Jio CallAgent Inside the Network appeared first on TechRepublic.
Mukesh Ambani’s Reliance AI Roadmap Puts Jio CallAgent Inside the Network
Reliance’s AI roadmap puts Jio CallAgent inside the telecom network while tying India-scale AI ambitions to Jamnagar compute, local-language services, and enterprise compliance questions.
The post Mukesh Ambani’s Reliance AI Roadmap Puts Jio CallAgent Inside the Network appeared first on TechRepublic.
-
Firewall Daily – The Cyber Express

-
Why India Temporarily Blocked Telegram Ahead of NEET UG 2026
India has temporarily enforced a Telegram Ban in India ahead of the NEET UG 2026 Re-examination, citing concerns that the platform could be used by organized cheating networks to target candidates. The restriction, recommended by the National Testing Agency (NTA) and implemented through directions issued by the Ministry of Electronics and Information Technology (MeitY), will remain in effect until June 22, 2026. According to the NTA, the measure is intended to support the safe and secure cond
Why India Temporarily Blocked Telegram Ahead of NEET UG 2026
![]()
Telegram Ban in India Limited to Examination Period
The temporary Telegram Ban in India has been imposed under Section 69A of the Information Technology Act, 2000. The restriction is limited to a defined period covering the examination day and its immediate aftermath. In addition to restricting access to the platform, authorities have directed Telegram to disable its Telegram Message Editing Feature in India until June 30, 2026. The NTA stated that the feature has been misused in the past to create misleading claims of Paper Leak incidents after examinations had already taken place. The agency noted that the temporary measures were adopted after other enforcement actions had already been pursued and were intended to address concerns during the examination window with the minimum restriction considered necessary.Coordinated Action Against NEET UG 2026 Exam Fraud Networks
The NTA credited the Indian Cyber Crime Coordination Centre (I4C), operating under the Ministry of Home Affairs, for coordinating action against channels and groups allegedly involved in Exam Fraud targeting NEET candidates. According to the agency, I4C worked with state law enforcement agencies and MeitY to identify and remove numerous Telegram channels, groups, and bots that openly advertised access to examination papers or related services. Authorities said several channels used names such as "PAPER LEAKED NEET," "Re-NEET 2026," and similar variations while demanding payments from candidates and their families in exchange for purported access to examination material. The NTA reiterated that no examination paper was available outside the secured examination process and described such offers as fraudulent.Why the Message Editing Feature Was Restricted
The direction related to the Telegram Message Editing Feature addresses concerns about fabricated evidence of examination leaks. According to the NTA, Telegram administrators can edit previously published messages while retaining the original posting timestamp. Authorities stated that this capability has been used in multiple examinations to replace earlier content with actual question papers after an exam had concluded, creating the appearance that the material had been shared before the test. The temporary restriction on editing existing messages is intended to prevent the creation and circulation of such misleading content during the post-examination period.Law Enforcement Investigations Continue
Authorities also pointed to ongoing enforcement actions in several states. The Bihar Police Economic Offences Unit issued a public advisory on June 9, warning candidates against fraudulent claims of pre-examination paper access circulating through Telegram and other online platforms. Separately, the Ahmedabad City Cyber Crime Branch arrested members of an alleged inter-state cyber fraud network accused of operating multiple Telegram channels linked to the same scheme. Investigators reported documented transactions worth approximately ₹1.5 crore and outreach to nearly 1,000 mobile numbers within a month.NTA Reassures Candidates
The NTA acknowledged that the restriction affects users who rely on Telegram for educational, professional, and personal communication. However, the agency emphasized that the measure is temporary and focused on protecting the integrity of the NEET UG 2026 Re-examination. The examination will proceed as scheduled on June 21. The agency urged candidates to ignore unverified information circulating online and rely only on official NTA communication channels for updates. Officials also encouraged students and parents to report suspicious activities through the national cybercrime reporting mechanisms and remain cautious of claims related to examination papers circulating on any platform.-
Firewall Daily – The Cyber Express

-
UIDAI, NFSU Sign 5-Year Pact to Boost Cybersecurity and Digital Forensics
The collaboration between the Unique Identification Authority of India and the National Forensic Sciences University marks a significant development in India's security landscape and digital forensics. In a move aimed at strengthening the country’s digital infrastructure, UIDAI and NFSU have formalized a five-year partnership to advance research, training, and operational capabilities in cybersecurity and digital forensics. According to an official statement, UIDAI and NFSU have established a
UIDAI, NFSU Sign 5-Year Pact to Boost Cybersecurity and Digital Forensics
![]()
According to an official statement, UIDAI and NFSU have established a structured collaboration designed to address emerging challenges in cybersecurity and digital forensics.
UIDAI and NFSU Join Forces on Cybersecurity and Digital Forensics
The agreement, announced on May 5 in Ahmedabad, provides a comprehensive framework to bring together expertise from both institutions. It is intended to reinforce cyber resilience across UIDAI’s systems, which form the backbone of India’s digital identity ecosystem. The Ministry of Electronics and Information Technology highlighted that this partnership creates an umbrella structure for coordinated efforts in research, technical development, and capacity building. The initiative underscores the growing importance of cybersecurity and digital forensics as critical components of national digital infrastructure.Six Strategic Pillars Driving UIDAI and NFSU Collaboration
The UIDAI and NFSU partnership is structured around six key pillars, each targeting specific aspects of cybersecurity and digital forensics. These include academic and professional development, aimed at building skilled talent in the field, as well as strengthening information security and system integrity within UIDAI’s ecosystem. Another major focus area is the development of advanced forensic infrastructure and laboratory capabilities. This will support deeper investigation and analysis of cyber incidents. Additionally, the agreement outlines provisions for technical support in cybersecurity operations, ensuring that UIDAI benefits from NFSU’s specialized expertise. The collaboration also emphasizes joint research and technical advisory in emerging technologies. Areas such as artificial intelligence, blockchain, cryptography, and deepfake detection are expected to play a central role. The sixth pillar focuses on strategic placement and outreach, creating pathways for NFSU students to gain hands-on experience and career opportunities within UIDAI-related projects.Strengthening India’s Digital Backbone
India’s digital identity framework, powered by UIDAI, requires continuous upgrades to counter evolving cyber threats. The UIDAI and NFSU partnership aims to address this need by integrating advanced cybersecurity and digital forensics practices into the system’s core operations. UIDAI Chief Executive Officer Vivek Chandra Verma described the agreement as a crucial step toward enhancing the security architecture of India’s digital public infrastructure. He stated that the collaboration will significantly improve forensic readiness and resilience, ensuring stronger protection against cyber risks. The signing ceremony was attended by senior officials from both institutions, including Deputy Director General Abhishek Kumar Singh and NFSU Gujarat Campus Director S. O. Junare. Their presence highlighted the institutional commitment to advancing cybersecurity and digital forensics through sustained collaboration.Expanding Access While Enhancing Security
Alongside this partnership, UIDAI has also taken steps to improve accessibility to its services. Collaborations with digital platforms like MapmyIndia and Google now allow users to locate authorized Aadhaar centers more easily. These platforms provide information on available services, operating hours, and accessibility features. While these initiatives focus on user convenience, they also align with the broader objective of strengthening the integrity of India’s digital identity system. By combining improved accessibility with robust cybersecurity and digital forensics measures, UIDAI aims to maintain trust in its infrastructure.-
Hackread – Latest Cybersecurity, Tech, Crypto & Hacking News
-
Harvester APT Expands Spying Operations with New GoGra Linux Malware
New GoGra Linux malware linked to Harvester APT targets systems in South Asia, using fake PDFs and Microsoft APIs for covert command and control.
Harvester APT Expands Spying Operations with New GoGra Linux Malware
-
Hackread – Latest Cybersecurity, Tech, Crypto & Hacking News
-
Mustang Panda Hits India and S. Korea with Updated LOTUSLITE Backdoor
Acronis reveals Mustang Panda is using an updated version of LOTUSLITE backdoor to target Indian banks and Korean diplomats. Learn how this DLL sideloading attack works.
Mustang Panda Hits India and S. Korea with Updated LOTUSLITE Backdoor
-
bellingcat

-
Painkiller Pipeline: 300 Million Tapentadol Pills Sent from India to West Africa
This article is the result of a collaboration with Indian media outlet Newslaundry. You can find Newslaundry’s editorially independent coverage here. Collage illustration by Klawe Rzeczy. Elements from Unsplash. Indian companies have shipped more than 320 million synthetic opioid pills to West Africa – where they have not been approved by regulators – over the past three years, a Bellingcat investigation has found. Export records from trade data provider 52wmb show that more than 1,400
Painkiller Pipeline: 300 Million Tapentadol Pills Sent from India to West Africa
This article is the result of a collaboration with Indian media outlet Newslaundry. You can find Newslaundry’s editorially independent coverage here.

Indian companies have shipped more than 320 million synthetic opioid pills to West Africa – where they have not been approved by regulators – over the past three years, a Bellingcat investigation has found.
Export records from trade data provider 52wmb show that more than 1,400 consignments of tapentadol worth almost USD $130 million were sent from India to West Africa between January 2023 and December 2025.
Tapentadol, a painkiller two to three times more potent than tramadol, has not been approved for use in most West African countries, where some nations are grappling with an escalating opioid abuse epidemic.
However, this investigation shows that dozens of Indian suppliers have flooded the region with tapentadol over the past three years. Where dosages were listed, more than half the pills were in powerful strengths of 200mg or more – dosages that are not even approved in India.
The exports, cross-checked against records provided by trade data aggregator ImportGenius, show most tapentadol pills sent between 2023 and 2025 had the coastal nations of Sierra Leone and Ghana listed as their declared destinations.
The two West African countries were collectively marked as the destination for more than 80 per cent of the total value of tapentadol sent to the region.
Experts have documented how drug traffickers adapt quickly to international regulations and law enforcement efforts. In 2018, India tightened export controls around the opioid tramadol, one of the most trafficked synthetic drugs to West Africa.
In 2021, the International Narcotics Control Board (INCB) said large-scale tapentadol trafficking had been identified, particularly in consignments destined for Africa. It had previously noted that India’s strengthened tramadol controls could lead traffickers to substitute the drug with other potent synthetic opioids.
A BBC investigation last year revealed that Indian company Aveo Pharmaceuticals was illegally exporting tablets containing a mix of tapentadol and the muscle relaxant carisoprodol to West Africa. This led India’s drug regulator, the Central Drugs Standard Control Organisation (CDSCO), to ban the manufacture and export of all combinations of the two drugs.
Bellingcat’s investigation, in collaboration with Indian publishing partner Newslaundry, reveals that the supply of tapentadol pills from India to West Africa has surged in recent years.
Export data from 52wmb shows the value of tapentadol sent to the region has risen from about USD $27 million in the three year period from 2020 to 2022, to almost USD $130 million from 2023 to 2025.
Julius Maada Bio, Sierra Leone’s president, in 2024 declared a national emergency over rampant drug abuse and branded kush – a toxic blend of psychoactive substances including cannabis and synthetic opioids – a “death trap”.
Authorities in Sierra Leone have intercepted illegal tapentadol, including last July when the National Revenue Authority (NRA) said it thwarted a smuggling operation near its north-west border with Guinea.
The NRA and other agencies including the Transnational Organised Crime Unit, National Drug Law Enforcement Agency, and the Pharmacy Board of Sierra Leone did not respond to Bellingcat’s requests for comment.

Ghana’s Narcotics Control Commission (NACOC) said the illegal importation of tapentadol was first recorded in 2022 after international efforts to curb the tramadol crisis resulted in criminal networks shifting production to other pharmaceutical opioids including tapentadol, tafrodol and carisoprodol.
The agency has recorded a “steady rise” in tapentadol trafficking over the past three years, with authorities seizing more than 3.7 million tablets (250mg strength). Most were traced back to India, it said.
“NACOC investigations confirm that the bulk of tapentadol is trafficked into Ghana through seaports and by air, via express courier services,” a spokesperson said. “At the ports, the drug is concealed in containerized cargo falsely declared as pharmaceuticals, electrical materials or household goods. Express courier services are used for smaller, high-value quantities, often packed alongside legitimate consignments to avoid detection.”
NACOC said Ghana had emerged as both a destination and transit hub for tapentadol, with the majority of intercepted consignments bound for Niger, Mali, Burkina Faso and Nigeria. When sold domestically, it said the street drug was promoted as a tramadol substitute.
Ghana’s Food and Drugs Authority (FDA) said last year that the abuse of pharmaceutical opioids such as tapentadol — commonly known on the street as “Red” — was on the rise.
The FDA told Bellingcat it had “never issued any permit” for the manufacture or importation of tapentadol, in any strength, to any importer or to any country. It said any tapentadol shipments to Ghana were for “trans-shipment to neighbouring country”.
Import data for Ghana shows that no tapentadol entered the country between 2023 and 2025, which supports NACOC’s position that the drugs are being concealed and falsely declared. Import data for Sierra Leone was not available through 52wmb.

India’s drug and pharmaceutical exports have grown to more than $30 billion a year, according to the Pharmaceuticals Export Promotion Council of India (Pharmexcil), a division of the ministry of commerce and industry.
While tapentadol is available in India on prescription in strengths of up to 100mg (immediate release) and 200mg (extended release), authorities are aware of its risk of misuse. Last year, the Indian drug regulator’s Technical Advisory Board said the Department of Revenue may be requested to schedule the painkiller under the Narcotic Drugs and Psychotropic Substances Act, which would tighten rules around its export.
To export pharmaceutical products at strengths that are not approved in India, exporters are required to obtain an export “no objection certificate” (NOC) from the CDSCO, for which they have to submit proof of the drug’s approval in the importing country. Publicly available information shows tapentadol is not approved for use in any of the West African nations identified as part of this investigation.
The CDSCO did not respond to questions from Bellingcat or our publishing partner, Newslaundry.
In response to “Right to Information” requests submitted by Newslaundry, the CDSCO said only two companies had been granted authorisation to manufacture tapentadol for export between 2019 and 2024. However, the trade data analysed by Bellingcat did not list either company as an exporter of tapentadol to West Africa.
The CDSCO also said it had issued export NOCs for tapentadol to 51 companies since 2024, but that these were not for export to West African countries.
Meanwhile, Bellingcat’s analysis of trade data shows that more than 60 Indian suppliers have exported tapentadol to West Africa since 2023. The exporters are mostly pharmaceutical companies but also include smaller operations, such as one company owned by a Nigerian man who sent more than US $4 million of tapentadol to Niger and Ghana.

Dinesh Thakur, co-author of the book Truth Pill, told Newslaundry there were gaps in India’s drug regulatory framework that made it possible for potentially unsafe medicines to be manufactured and exported without proper oversight.
“There is no regulatory framework which checks a genuine importer and counterfeit importer between countries,” said Thakur, a former pharmaceutical executive who now works as a public health activist.
Mohammed Adinoyi Usman, a consultant anaesthetist at Rasheed Shekoni Federal University Teaching Hospital in Nigeria, said tackling Africa’s opioid crisis was complicated by a lack of resources across the region, weak government responses, and inaction by law enforcement agencies.
He said more collaboration and intelligence sharing was needed, especially across West African countries, to combat the problem. “We see so many opioids coming into our region because of a range of factors including under-funded institutions like customs and drug agencies, weak border controls and corruption,” he said.
“Africa is different. Even southern Africa is different from western Africa – each region has its peculiarities. In Nigeria, we don’t have well-functioning institutions to help control it. But our government is trying.”
Dr Usman said access to prescription opioids in Africa was inadequate, and pointed to research showing the disparity in distribution of legal opioids to low-income countries compared to high-income nations that consume the bulk of the world’s pain relief medication. He said opioid abuse was linked to crime and negative health outcomes.
“Sadly, access to prescription opioids is very limited in Africa,” Dr Usman said, “but the costs of illegal use are high.”
Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.
The post Painkiller Pipeline: 300 Million Tapentadol Pills Sent from India to West Africa appeared first on bellingcat.
-
bellingcat

-
How India’s Ruling Party is Using AI to Boost Hate Speech in States Near Bangladesh
The video posted by a state branch of India’s ruling Bharatiya Janata Party (BJP) showed Assam chief minister Himanta Biswa Sarma shooting an image of two men in Muslim skull caps. “Foreigner-free Assam”, read one caption across the video. “Why did you not go to Pakistan?” said another. Screenshots of the now-deleted video shared by BJP on Feb. 7 showing Assam Chief Minister Himanta Biswa Sarma shooting an AI-generated version of INC leader Gaurav Gogoi (in a white skull cap) and another uni
How India’s Ruling Party is Using AI to Boost Hate Speech in States Near Bangladesh
The video posted by a state branch of India’s ruling Bharatiya Janata Party (BJP) showed Assam chief minister Himanta Biswa Sarma shooting an image of two men in Muslim skull caps. “Foreigner-free Assam”, read one caption across the video. “Why did you not go to Pakistan?” said another.

One of the men in the photo that Sarma was portrayed as shooting was Gaurav Gogoi, a leader of the Indian National Congress (INC), the BJP’s main competitor in Assam for the state’s upcoming legislative elections next month.
Gogoi has stated that he is Hindu but enjoys visiting different religious sites and observing their norms. He has been photographed wearing traditional Muslim attire during religious occasions such as Eid.
But the image of him in the video shared by BJP Assam, wearing a casual singlet with a skull cap, was not one of those occasions.
Bellingcat has seen several dozen videos posted by the BJP that use generative artificial intelligence (AI) alongside anti-Muslim and anti-Bangladeshi messaging in the border states of Assam and West Bengal in December last year, ahead of legislative elections scheduled in both states for April.

Bellingcat analysed 499 social media posts containing photos and videos shared on Facebook, Instagram and X by the BJP’s official accounts in the two states for this time period, finding 194 posts that appeared to meet the United Nations’ definition of hate speech: discriminating against persons or communities based on inherent characteristics such as religion and national origin. Of these, 31 (about one in six of the hateful posts) contained the obvious use of AI-generated imagery.
Chart: Galen Reich
These appear to be part of a larger pattern of politicians and parties globally using generative AI to amplify hateful or divisive content, particularly ahead of major political events such as elections.
Ahead of the New York City mayoral race last year, Andrew Cuomo’s official X account shared, then deleted, an AI-generated video depicting Mamdani eating rice with his hands and a Black man in a keffiyeh shoplifting. In Italy, several opposition parties complained to a communications watchdog after deputy prime minister Matteo Salvini’s League party published a series of AI-generated images depicting men of colour attacking women or police officers. And in the UK, videos by an AI-generated rapper funded by the far-right Advance UK party, with lyrics targeting Muslims, were viewed millions of times.
A Campaign of Hate
Both Assam and West Bengal share a border with Bangladesh. BJP, the world’s largest political party, is currently in power in Assam, where legislative elections are scheduled on Apr. 9. West Bengal, which goes to the polls on Apr. 23, is governed by the Trinamool Congress (TMC).

Tensions between India and Bangladesh worsened after former Bangladeshi Prime Minister Sheikh Hasina, who enjoys close ties with Delhi, was ousted in 2024 and fled to India.
US-based international affairs expert Mohammed Zeeshan told Bellingcat that the “dehumanising and debasing” terminology used in India to refer to alleged illegal Bangladeshi immigrants, including by senior ministers, has caused resentment towards India in Bangladesh.
“The situation, in fact, was so bad that Hasina herself had subtly warned the Modi government in public statements that Indian domestic rhetoric was endangering Bangladeshi Hindus, who bore the brunt of that resentment,” Zeeshan said.
Related articles by Bellingcat
The Fall of Sheikh Hasina: Footage from the Streets of Bangladesh
Zobaida Nasreen, a professor of anthropology at Dhaka University, said that anti-Muslim rhetoric intensified by BJP leaders reinforces the belief in Bangladesh that Muslims and Bengalis are being collectively targeted in India.
“Viral videos containing this message tend to spread quickly across Bangladeshi media and social platforms especially on Facebook, enhancing perceptions of hostility and triggering anti-India sentiment or nationalist backlash,” she added.
In December, the month our dataset was collected, Dipu Das, a Hindu garment worker, was beaten to death at an anti-India protest in Bangladesh over allegations that he had made derogatory remarks about Islam.
And while the administration led by Bangladesh’s newly elected leader Tarique Rahman has sought to reset strained ties, most of the hateful social media posts we saw posted by the BJP in December attacked Bangladeshi Muslims and/or Bengali-origin Muslims in India, showing how tensions between the two countries continue to influence political messaging in India’s border states.
Bellingcat’s analysis included a total of 202 posts by BJP Assam and 297 by BJP’s West Bengal branch on their official accounts. We also looked at posts shared by BJP’s main opponent parties – 194 from INC in Assam and 357 from the TMC in West Bengal – during the same time period in December.
This included all visual social media posts (containing photos or videos) by each party in December, except those that did not appear to contain any overt political messaging, such as those simply commemorating public holidays. We only counted each photo or video once, regardless of how many platforms it was shared across.
Although all of the major parties contesting in the Assam and West Bengal state elections appeared to use AI-generated imagery in some of their posts, there appeared to be a particularly high concentration of hateful messaging in the ones posted by the BJP’s accounts.
In Assam, we identified 28 posts by BJP using apparently AI-generated imagery, of which 24 carried hateful messaging. Of the 194 INC posts we looked at from December, 41 appeared to feature AI-generated imagery, but none of these appeared to carry hateful messaging.
In West Bengal, we found 14 BJP posts that contained clear indicators of AI-generated imagery, seven of which were hateful. We also identified 15 posts by the incumbent TMC that appeared to feature AI imagery, but none of these appeared to meet the definition of hate speech.

Support Bellingcat
Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.
When contacted for comment, BJP Assam spokesperson Rupam Goswami did not directly respond to questions on the party’s general use of AI but said they did not post any AI-generated photos of Gogoi. “BJP does not stoop so low,” he told Bellingcat.
As for the “point blank” shooting video, Goswami initially said the person responsible had been punished and removed from the party. However, when asked about Sarma saying that he would re-post the video with those he was depicted shooting labelled as “Bangladeshis”, Goswami said, “[Bangladeshis] need to be completely suppressed.”
BJP West Bengal did not respond to multiple requests for comment by Bellingcat via phone and email.
It is important to note that as generative AI technology improves, it can be increasingly difficult to detect AI-generated imagery. Our manual count of AI-generated imagery only included posts that had obvious signs of generative AI such as unnaturally smooth textures and multiple people with the same faces. It is therefore possible that there were other images in our dataset where generative AI was used more subtly.
However, Joyojeet Pal, Professor of Information at the University of Michigan, told Bellingcat that the quality of these visuals, or whether they looked real, was not the priority.
“What politicians in India have understood is that the sociocultural drivers of misinformation are most important for elections, so they harp on about things to the extent that they have started to not care about form over substance. It looks bad? It doesn’t matter,” he said.
More important to voters, according to Pal, was whether they already believed in the narrative contained in the videos, which generative AI could help create more quickly: “AI is helping cement polarised opinions by giving you the kind of content you have already decided you want to engage with.”
When asked about INC’s use of AI, party spokesperson Aman Wadud said that it was obvious that some of the videos they posted were made with AI and that there was no intention to mislead.
“AI can be both destructive and creative. We are using it in a creative manner, we are not using it in a destructive manner. We don’t violate people’s dignity, we don’t falsely accuse people,” he said.
TMC did not respond to Bellingcat’s multiple requests for comment via phone and email by publication time.
Portraying Bengali Muslims as ‘Foreigners’
The largest category of hateful messaging Bellingcat observed in the BJP’s posts targeted Bangladeshi or Bengali-origin Muslims, referring to them as “infiltrators” or “foreigners”. We counted 66 such posts by the BJP’s Assam and West Bengal branches from December, of which eight appeared to contain obvious AI-generated imagery.
Bengali-origin Muslims are often stereotyped as “illegal immigrants” in the state, although members of the community have lived in India since the late 1800s.
Last year, the BJP deported thousands of alleged undocumented migrants – reportedly including Indian Muslim citizens – to Bangladesh. Human rights groups have called the deportations unlawful and discriminatory, as well as lacking in due process.
One video referencing this theme shows AI-generated visuals of protests against “illegal infiltration” in Assam, with the caption urging people to “wake up” or the country would “turn into Bangladesh”.
A different one uses real footage from past violence in Assam mixed in with images of Muslim men. A song playing in the background accuses them of taking over “Assamese land” and shows AI images of “Assamese” people, i.e. those not in stereotypical Muslim clothing, crying.

Both videos use religious markers to draw a distinction between “infiltrators” – men in skull caps or lungis associated with Bengal-origin Muslims – and “citizens” in non-Muslim attire.
Clothing is often used by the Hindu far-right as a visual shorthand for identity and a deepening religious divide. In 2019, Prime Minister Narendra Modi said of protests against a controversial citizenship law that those responsible for violence could be “identified by their clothes”.
In the hateful posts seen by Bellingcat, both real and AI-generated images of opposition figures – particularly Gogoi – were shown alongside messaging that suggested that they supported “foreigners” or “infiltrators”.
The Center for the Study of Organized Hate (CSOH) also noted, in a 2025 report on AI-generated imagery and Islomophobia in India, that Hindu far-right politicians and media outlets have invoked and reinforced the trope of Muslims as “infiltrators” for years.
“AI-generated images on these themes reinforce associations between Muslim identity and illegality, reinforcing xenophobic and Islamophobic stereotypes. In doing so, they play a powerful role in justifying exclusionary policies and normalising discrimination against Muslims,” the report said.
‘Save Hindus’
Zenith Khan, a data analyst who worked on the CSOH report, noted that AI-generated propaganda was often tightly knit with current political moments, and its impact depended on “timing it right” especially when “people are emotionally charged”.
The violence against the minority Hindu community in Bangladesh has been used by the BJP to raise concerns over the safety of Hindus in India.
Days after Das’ lynching, the Assam state branch of BJP posted a video with an image of his face – except that it was manipulated with AI to show tears streaming from his eyes. “Save Hindus”, said the text accompanying the video.
Posts by BJP’s West Bengal unit also seemed to frame Muslims as criminals or threats. A video, styled after the TV show “Stranger Things”, raised alarms over an “upside down” version of the state under the current government.
A man is depicted being chased by men in skull caps. Arrows label them as “Ralib,” “Galib,” and “Chalib” – a play on Muslim names ending in “-lib” – in case the skull caps left any ambiguity about their Muslim portrayal.

INC filed a police complaint in September last year against the BJP for sharing AI videos targeting Gogoi and the Muslim community, as well as another complaint in relation to the video of Sarma portrayed as shooting two men “point blank” in February.
INC Assam spokesperson Wadud said that no action had been taken on the party’s police complaints as far as he knew.
Disinformation researcher Bharat Nayak told Bellingcat that it has always been tech platforms’ responsibility to control new types of content.
“The goal post can’t shift. This has always been a tech problem,” he said.
When this responsibility is shrugged off, Nayak added, the result is a lack of accountability. “If you’re using old videos from other countries as new, you will have people countering you. But AI-generated videos can be shared without context just to spread hate – like showing people in skull caps – and the ‘when, where, how’ questions vanish.”
Both Meta – which owns Facebook and Instagram – and X have policies against hateful conduct.
Meta also announced in 2024 that it would start adding “AI info” labels to more content detected as AI-generated, while some X users spotted a similar feature introduced on the platform last month. Only five of INC’s AI visuals that we identified – and none of those by TMC or the BJP – had a disclaimer that said “AI-generated”.
Bellingcat reached out to Meta and X for comment on whether the posts we identified breached their terms of use regarding hateful conduct or labelling AI-generated posts. A Meta spokesperson said they were reviewing the flagged content and “will take appropriate action on any violations of our policies”. As of publication, X had not responded.
Kalim Ahmed from Bellingcat’s Discord Community contributed research to this piece.
Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.
The post How India’s Ruling Party is Using AI to Boost Hate Speech in States Near Bangladesh appeared first on bellingcat.