Research Report on the Scams in Names of Indian Railway and Big Brands in India released

Date:

Trending

- Advertisement -

WhatsApp messages masquerading as the offers from various giant entities with links luring unsuspecting users with the promise of transport subsidy, medical subsidy, recharge offer, free travel tickets etc., have been making the rounds on the app recently. If you receive such messages try to stay away from these, as these can be a scam.

Images above show Fake WhatsApp Messages (Screenshots)

The Research Wing of CyberPeace Foundation, Autobot Infosec Private Limited along with CyberPeace Center of Excellence (CCoE) have conducted six different studies based on these WhatsApp messages that contained links pretending to be a free subsidy, recharge offer and travel tickets from Indian Railways, Apollo Hospitals, Haldiram, Emirates Airlines, Various Telecom giants and Tata Group which ask users to participate in various offers and survey in order to get a chance to win the prizes.

Warning Signs

CyberPeace Advisory

- Advertisement -

The campaigns are pretended to be the offer from various big brands but hosted on the third party domain instead of the official website of the respective brands which make it more suspicious

The domain names associated with the campaigns have been registered in very recent times.

Multiple redirections have been noticed between the links.

No reputed site would ask its users to share the campaign on WhatsApp.

- Advertisement -

The prizes are kept really attractive to lure the laymen.

Grammatical mistakes have been noticed.

CyberPeace Foundation recommends that people should avoid opening such messages sent via social platforms.

Falling for this trap could lead to whole system compromise such as access to microphone, Camera, Text Messages, Contacts, Pictures, Videos, Banking Applications etc as well as financial loss for the users.

Do not share confidential details like login credentials, banking information with such a type of scam.

Never share or forward fake messages containing links to any social platform without proper verification.

Never install an application from a third party source instead of the official app store.

There is a need for International Cyber Cooperation between countries to bust the criminal gangs running the fraud campaigns affecting individuals and organizations to make the Cyberspace resilient and peaceful.

On the landing page a Congratulations message appears with the attractive photo of the offers and ask users to participate in a quick survey or questionnaires in order to avail the said offers. All the links showcase the respective logos of the said entities and ask users to take the survey to win recharges and subsidies.

Also at the bottom of the page a section comes up which seems to be a comment section where many users have commented about how the offers are beneficial.

All the surveys start with some basic questions like Do you know the above mentioned companies How old are you What do you think of Emirates Airlines or Haldiram’s Are you male or female etc.

Once the user answers the questions a “congratulatory message” is displayed. After Clicking the OK button users are given three attempts to win the prizes.

After completing all the attempts it says that the user has won the respective offers.

Image 2: Fake congratulatory messages

Clicking on the ‘OK’ button, it instructs users to share the campaign on WhatsApp. Strangely enough the user has to keep clicking the Whatsapp button until the progress bar completes. After clicking on the green ‘WhatsApp’ button it shows a section where a “Congratulations” appears once again.

During the analysis the research team found a JavaScript code called hm.js was being executed in the background from the host hm[.]baidu[.]com which is a subdomain of Baidu and is used for Baidu Analytics, also known as Baidu Tongji. The important part is that Baidu is a Chinese multinational technology company specializing in Internet-related services, products and artificial intelligence, headquartered in China.

The campaign, pretending an offer from TATA, insists users to download an application from a third party app store.

To read the detailed reports, visit www.cyberpeace.org/publications

The detailed study helped CyberPeace and AutoBot Infosec Pvt Ltd to come to the following conclusions:

The whole research activity was performed in a secured sandbox environment where the WhatsApp application was not installed. If any user opens the link from a device like smartphones where WhatsApp application is installed, the sharing features on the site will open the WhatsApp application on the device to share the link.

The campaign collects browser and system information from the users.

Most of the domain names associated with the campaign have the registrant country as China whereas the campaign that offers free 30GB of internet data has the registrant country as Pakistan.

Cybercriminals used Cloudflare technologies to mask the real IP addresses of the front end domain names used in the campaigns. But during the phases of investigation, the research team has identified a domain name that was requested in the background and has been traced as belonging to China.

THE SNAPSHOTS

Sign up to get quick snaps of everyday happening, directly in your inbox.

We don’t spam! Read our privacy policy for more info.

- Advertisement -

More Latest Stories

More Articles

How Air Can Become Urban India’s New Water Source

India's cities are running dry. Chennai nearly ran out of groundwater in 2019. Bengaluru's lakes are shrinking. Delhi's borewells are drawing from depths unimaginable...

The Human Algorithm: Why the Future of Digital Marketing Belongs to Empathetic Strategists

The modern marketing department is quieter than it used to be. The frantic tapping of copywriters racing against deadlines and the loud debates of creative directors have largely been replaced by the hum of servers processing natural language. Today, an enterprise can generate ten...

How AI is Rewriting the Economics of India’s $300 Bn IT Services Sector

When Microsoft CEO Satya Nadella recently disclosed that artificial intelligence now generates nearly 30...

Bounce House Rental vs Inflatable Slides: Which Option Delivers More Excitement?

Planning a family gathering or a children's party often involves finding the perfect entertainment...

How Hiring a Qualified Plumber Solves Major Household Issues

For many homeowners, maintaining a functional and safe home is a top priority. Plumbing...

Why India Must Own Its Education Intelligence Stack

India has rapidly digitised large parts of its education ecosystem over the last decade....

Why Micro Learning at 3 Minutes Works Better Than Lectures at 3 Hours

In the fast-moving world of digital education, there is one myth that continues to...

More Than Just a Scratch: The Importance of Windshield Care

Maintaining your vehicle’s windshield often appears as a seemingly minor task that can easily...

How Choosing A Licensed Plumber Ensures Quality Repairs

When it comes to maintaining a safe and comfortable home, the quality of plumbing repairs can significantly impact your daily life. From leaky faucets...

The world’s largest crypto market is building in the dark

India remains one of the few significant economies without a comprehensive crypto and stablecoin...

How Location Data Storage Technology is Making City Travel Smoother

India’s mobility ecosystem is undergoing a quiet but powerful transformation, driven not just by...

India Is Building Cities Without Building the Systems That Make Them Work

India is in the middle of the largest urban expansion in its history. By 2050,...

Why Cyber Resilience Is Replacing Cybersecurity as a Boardroom Priority

Traditionally, cybersecurity was hard-wired to be a technology concern that was only taken care...

Infrastructure 4.0: How AI & Predictive Analytics Are Transforming Real Estate

The new era of technology and innovation has changed operations in many industries. The integration of artificial intelligence in different industries is making processes...

The Rise of Integrated Solar Tech Ecosystems in India

India’s clean energy is all about building an ecosystem that is interconnected with various elements and goes beyond just installing solar panels at scale. Renewable energy generation, storage, digital intelligence, manufacturing, financing, and grid infrastructure work together within the said ecosystem in a coordinated...

Beyond Nvidia: The Hidden Winners of the AI Stock Rally

Nvidia stock (NASDAQ:NVDA) has returned roughly 1,200% since ChatGPT launched in late 2022. Most...

What PM Modi’s Appeal to Avoid Gold Buying Could Mean for India’s Jewellery Economy

When Prime Minister Narendra Modi recently urged citizens to avoid purchasing gold for a...

How Agentic AI Is Personalising the End to End Salon Experience

Walk into a salon today, and more often than not, the experience still depends...

From Black Box to Trusted AI: Why Defence Needs Constitutional AI Models

For decades, the defence and intelligence agencies have followed one non-negotiable rule: trust nothing...

Apple Reports $111.18 Billion Revenue in Q2 FY26, Net Profit Rises to $29.6 Bn

Apple Inc. (NASDAQ:APPL) has reported its financial results for the quarter ended March 28,...

Hermès vs MetaBirkin: The NFT Case That Redefined Ownership on Ethereum

The NFT boom of 2021 and early 2022 pushed digital assets into the mainstream,...

Bihar Police, Vehant Technologies Partners to Deploy Screening Systems Across 40 Courts

In a bid to enhance safety and security across court premises for judges, lawyers,...

Rethinking Hospital Security: TrioTree Technologies CEO Surjeet Thakur on Securing Fragmented Hospital IT Environments

In an interaction with TechGraph, Surjeet Thakur, Founder and CEO of TrioTree Technologies, outlined...

What the Next Phase of Growth Looks Like for Indian and Global E-commerce Players

For close to a decade, metrics for evaluating the growth of e-commerce included customer...

India Is Building Cities Without Building the Systems That Make Them Work

India is in the middle of the largest urban expansion in its history. By 2050,...

“Budget should focus on reducing taxes on capital gains,” Says Abhishek Gupta of Hex N Bit

Speaking in the upcoming Union Budget 2021, Abhishek Gupta, Founder, and CEO, Hex N...

“China is a Global thief” Rep. Tom Rice on Uyghur Forced Labor Prevention Act

Speaking at the House on Uyghur Forced Labor Prevention Act, Rep. Tom Rice (R-SC)...

Borade AI Founder Shiv Kumar Borade on Building an AI Growth Engine for Small Businesses

Speaking with TechGraph, Shiv Kumar Borade, Founder & CMD of Borade.AI, discussed how many...

When AI-Generated Documentation Hurts More Than Helps

AI-generated documentation has quickly become a selling point for modern SaaS and developer platforms,...

Why Cyber Resilience Is Replacing Cybersecurity as a Boardroom Priority

Traditionally, cybersecurity was hard-wired to be a technology concern that was only taken care...

Alphabet Discloses $2.14 Billion in Public Equity Holdings as of June 30

Alphabet Inc. disclosed $2.14 billion in equity securities held across 39 positions as of...

Gaming for Good: Boosting the Indian Gaming Community through Technology

The Indian gaming industry is transforming remarkably, driven by technological advancement and a growing...

India to generate $100 bn from telephonic investments

India expects to attract $100 billion in investments in the telecom sector, a union...