#FactCheck - AI-Generated Video of Monkey Falsely Linked to Hanuman Devotion
A video is being widely shared on social media showing a monkey, with users claiming that the animal is immersed in devotion to Lord Hanuman. The clip is being circulated with assertions that the monkey was seen participating in Hanuman Aarti. Cyber Peace Foundation’s research found that the viral claim is fake. Our investigation revealed that the video is not real and has been generated using artificial intelligence tools.
Claim
On January 6, 2026, Facebook users shared the viral video claiming, “A monkey was seen immersed in devotion during Hanuman Aarti.”
- Post link: https://www.facebook.com/reel/1261813845766976
- Archived link: https://archive.ph/anid5
Screenshots of the post can be seen below.

FactCheck:
When we closely examined the viral video, we noticed several visual inconsistencies. These anomalies raised suspicion that the video might be AI-generated. To verify this, we scanned the video using the AI detection tool Hive Moderation. According to the results, the video was found to be 97 percent AI-generated.

Further, we analysed the video using another AI detection tool, Sightengine. The tool’s assessment indicated that the viral video is 98 percent AI-generated.

Conclusion
Our investigation confirms that the viral video claiming to show a monkey immersed in devotion to Lord Hanuman is AI-generated and not real. The claim circulating on social media is false and misleading.
Related Blogs

Risk Management
The ‘Information Security Profile’ prioritises and informs cybersecurity operations based on the company's risk administration procedures. It assists in choosing areas of focus for security operations that represent the desired results for producers by supporting periodic risk evaluations and validating company motivations. A thorough grasp of the business motivations and safety requirements unique to the Production system and its surroundings is necessary in order to manage cybersecurity threats. Because every organisation has different risks and uses ICS and IT in different ways, there will be variations in how the profile is implemented.
Companies are currently adopting industry principles and cybersecurity requirements, which the Manufacturing Information is intended to supplement, not replace. Manufacturers have the ability to identify crucial operations for key supply chains and can order expenditures in a way that will optimise their impact on each dollar. The Profile's primary objective is to lessen and manage dangers associated with cybersecurity more effectively. The Cybersecurity Framework and the Profile are not universally applicable methods for controlling security risks for essential infrastructure.
Producers will always face distinct risks due to their distinct dangers, weaknesses, and tolerances for danger. Consequently, the ways in which companies adopt security protocols will also change.
Key Cybersecurity Functions: Identify, Protect, Detect, Respond, and Recover
- Determine
Create the organisational knowledge necessary to control the potential hazards of cybersecurity to information, systems, resources, and competencies. The Identify Function's tasks are essential for using the Framework effectively. An organisation can concentrate its efforts in a way that aligns with its approach to risk mitigation and company needs by having a clear understanding of the business environment, the financial resources that assist with vital operations, and the associated cybersecurity threats. Among the outcome characteristics that fall under this function are risk evaluation, mitigation strategy, the administration of assets, leadership, and the business environment.
- Protect
Create and put into place the necessary measures to guarantee the provision of crucial infrastructure amenities. The Protect Function's operations enable the limitation or containment of the possible impact of a cybersecurity incident. Instances of results Access Management, Knowledge and Instruction, Data Safety and Security, Data Protection Processes and Instructions, Repair, and Defensive Systems are some of the classifications that fall under this role.
- Detect
Create and carry out the necessary actions to determine whether a cybersecurity event has occurred. The Detect Function's operations make it possible to find vulnerability occurrences in an efficient way. This function's result subcategories include things like abnormalities and incidents, constant security monitoring, and identification processes.
- React
Create and carry out the necessary plans to address a cybersecurity event that has been discovered. The Response Function's operations facilitate the capacity to mitigate the effects of a possible cybersecurity incident. Within this Scope, emergency planning, interactions, analysis, prevention, and enhancements are a few examples of result categories.
- Recover
Create and carry out the necessary actions to uphold resilience tactics and restore any services or competencies that were hampered by a cybersecurity incident. In order to lessen the effects of a vulnerability incident, the Recovery Function's efforts facilitate a prompt return to regular operations. The following are a few instances of outcome subcategories under this role: communications, enhancements, and recovery planning.
Conclusion
The Information Security Profile, when seen in the framework of risk mitigation, offers producers a tactical method to deal with the ever-changing cybersecurity danger scenario. The assessment directs safeguarding operations prioritisation by recognising specific business reasons and connecting with corporate goals. The Profile enhances the cybersecurity standards and established industry guidelines by taking into account the differences in vulnerabilities and organisational subtleties among producers. It highlights the significance of a customised strategy, acknowledging that every business has unique risks and weaknesses.
The fundamental tasks of the Framework, to Identify, Protect, Detect, Respond, and Recover, serve as a thorough roadmap, guaranteeing a proactive and flexible approach to cybersecurity. The Profile's ultimate goal is to increase the efficacy of risk mitigation techniques, understanding that cybersecurity is a constantly shifting and evolving subject for the manufacturing sector.
References
- https://csrc.nist.gov/news/2020/cybersecurity-framework-v1-1-manufacturing-profile
- https://nvlpubs.nist.gov/nistpubs/ir/2020/NIST.IR.8183r1.pdf
- https://mysecuritymarketplace.com/reports/cybersecurity-framework-version-1-1-manufacturing-profile/

Executive Summary
A video circulating on social media allegedly shows Uttar Pradesh Chief Minister Yogi Adityanath criticizing Bollywood actor Shah Rukh Khan and asking people not to watch his films. Users sharing the clip claim that these statements are recent. CyberPeace’s research has found the claim to be misleading. research revealed that the video is from 2015, long before Yogi Adityanath became the Chief Minister of Uttar Pradesh. At that time, he was serving as a Member of Parliament from Gorakhpur.
Claim
On January 13, 2026, a Facebook user shared the video with the caption: "A clear message from the Hon’ble Chief Minister of Uttar Pradesh, Param Pujya Mahant Yogi Adityanath, urging people not to watch Shah Rukh Khan’s movie. Share this message widely, send it to all groups you are part of, and inform the youth in your family."

Fact Check:
To verify the claim, keyframes from the viral video were extracted and reverse-searched using Google Lens. The same video was found in a Facebook post dated March 28, 2022, where it was shared with the caption: "Baba Ji’s message to not watch Shah Rukh Khan’s ‘Pathaan’ movie."

Further research traced the video to Aaj Tak’s website, which reported on November 4, 2015, that then-BJP MP Yogi Adityanath criticized Shah Rukh Khan, comparing his language to that of terrorist Hafiz Saeed, stating that there was no difference in their statements.

A Live Hindustan report from the same date confirmed that Yogi Adityanath had strongly reacted to Shah Rukh Khan’s comments on rising intolerance in India and Hafiz Saeed’s invitation for him to stay in Pakistan. The reports make it clear that Yogi Adityanath criticized Shah Rukh Khan in 2015 by highlighting the similarity between his statements and those of Hafiz Saeed. At the same time, Shah Rukh Khan had highlighted growing intolerance in the country, citing incidents where filmmakers, scientists, and authors were returning awards, describing it as a sign of “deep intolerance” in India.

Conclusion:
Our research found that the statement attributed to Chief Minister Yogi Adityanath circulating on social media is not recent. The video dates back to 2015, a time when Yogi Adityanath was not yet the Chief Minister of Uttar Pradesh.
.webp)
Introduction
The advent of frontier AI has significantly widened the range of actors who can launch cyberattacks, extending beyond state actors with immense capabilities or organized professional cybercriminal rings. In its most critical advisory, CIAD-2026-0020, titled "Defending against frontier AI-driven cyber risks," which was released on April 26, 2026, the Indian Computer Emergency Response Team (CERT-In) officially stated that AI can now carry out autonomous cyber activities of unprecedented scale and speed. The advisory highlights that these frontier AI models can perform automated reconnaissance, phishing, malware creation, vulnerability identification, and social engineering with minimal human involvement, thus "lowering the barrier to orchestrating complex cyber attacks." The risks that such AI models pose are not restricted to state actors and corporate entities anymore and also extend to MSMEs, public organizations, and individuals.
India’s Escalating Cybercrisis
The Indian digital economy has been developing at a very fast pace, but the same cannot be said about its cybersecurity. Having a base of over 850 million internet users and a digital payment sector that records a massive 22,495 crore in monthly transaction volumes, coupled with the fastest-growing cloud sector in the world, India continues to remain a lucrative prey for cybercriminals. There were over 265 million attempts reported in the last year, 2025, alone, where close to 46% of all incidents detected were in enterprises with fewer than 1,000 employees, a very grave reality for MSMEs. MHA confirmed there were 28.15 lakh reported cybercrime complaints in 2025 as compared to 2024, with a jump of 24%. In this worsening environment the advisory is a breakthrough in Indian cyber governance. Where previously advisories covered only conventional threats like phishing and malware, the new warning names frontier agentic AI systems as autonomous multipliers of threats, capable of conducting operations at scale and speed with significantly reduced human oversight.
What is “Frontier AI” and why does it matter?
CERT-In’s decision to adopt the term "Frontier AI" is deliberate and meaningful. The advisory’s scope is a new category of agentic AI, which moves well beyond traditional chatbot-style AI, having the capacity to reason, plan, perform multiple actions in a single task autonomously, and carry out complicated tasks with minimal or no human guidance. CERT-In highlights that these tools now possess the capabilities that were "previously carried out by a coordinated team of skilled cybersecurity professionals." The advisory clearly flags the risk that these advanced models have the capability to generate malicious code, conduct network scans, probe systems for vulnerabilities, and even orchestrate intricate multi-stage cyberattacks in a single session. Their capacity to analyse a vast number of source code libraries to identify vulnerabilities, even unknown zero-day ones, and then develop proof-of-concept exploits at high speed. This means that the historical lead time to turn a vulnerability discovery into an exploit tool has reduced from weeks to just hours.
Six Core Threat Vectors identified by CERT-In
- AI-driven Automatic Zero-Day Discovery: AI-based solutions discover zero-day vulnerabilities and automatically create exploits in minutes, reducing the time taken by defenders.
- AI-driven Autonomous Reconnaissance: AI-driven agents scan cloud infra, APIs, and enterprise networks and outline attack vectors.
- AI-driven phishing & deepfakes: Multilingual, highly targeted phishing emails, deepfake audio, and deepfake voice/video calls bring sophistication to social engineering.
- Deepfake Financial Fraud: AI creates deepfake executives for high-value money transfers. For example, reports have indicated crore-level fund loss cases in India.
- AI-powered Autonomous Attack Chains: Advanced AI models are able to automatically perform multiple malicious stages like privilege escalation, lateral movement, data exfiltration, and data extraction.
- Cascading failures of interconnected systems: A single AI-supported security breach can have catastrophic domino effects on connected digital systems and critical infrastructures.
Why are MSMEs a target?
CERT-In’s warning is specifically targeted toward the weakness of the Indian MSMEs. Contributing almost 30% to India's GDP and employing over 110 million individuals, most MSMEs have failed to adequately prepare themselves against contemporary cyber threats. While a large corporation would have a full-time cybersecurity team, a security operation centre, and frequent vulnerability assessments, the majority of MSMEs lack such infrastructure due to budget constraints, out-of-date software, etc. This lack of security has proved to be quite disadvantageous for smaller businesses, as India was identified as one of the top global targets for cyberattacks, where approximately 46% of the total breaches worldwide targeted organizations having fewer than 1000 employees. The advisory claims that frontier AI systems have significantly increased the threats, for the skills necessary to carry out advanced cyberattacks have dramatically decreased. Ransomware, phishing and data exfiltration can be executed by even unsophisticated attackers. The aftermath could result in critical financial, operational, and compliance impact on these MSMEs.
The Global Context
These developments seem to validate CERT-In's warning about threats posed by frontier AI. In its 2026 State of Cybersecurity Report, ISACA listed AI-related threats as the top concern of cybersecurity professionals; 61% of those surveyed reported generative AI/large language models as the top technology trend impacting cyber risk. Worryingly, in 2026 only 7% were confident in their organizations' defenses against ransomware. Check Point Software's Cyber Security Report 2026 corroborates this; in 2025 the report stated that in a single year, the trend of combined social engineering-based campaigns with automated operational execution has risen considerably. In all phases of the lifecycle of a cyberattack reconnaissance, social engineering, and tactical decision-making AI is being applied. KPMG is warning of deepfake-enabled fraud now "spreading at a faster rate than that experienced at the beginning of the phishing era, which is currently still the leading type of attack in the world."
CERT-In Recommendations
For Large Organisations:
- The use of security monitoring, threat detection, and log analysis should be increased.
- DDoS protection systems and multi-factor authentication (MFA) should be implemented on all internet-facing devices and assets.
- Critical security patches should be installed within 24 hours of release.
- Old VPN and remote-access infrastructure should be updated or replaced.
- AI-driven cyber drills and incident response simulations should be regularly performed.
For MSMEs:
- Software and security updates should be automatically enabled on all devices and systems.
- MFA should be enabled on organisational accounts and sensitive platforms.
- MSMEs should utilize MSSPs for specialized support and monitoring.
- Detailed inventories of IT assets and system logs should be kept for fast incident response.
- Staff should be educated about identifying AI-generated phishing, deepfakes, and scams.
For Individuals:
- Independent communication channels should be used to verify any dubious message or money request.
- Software from unverified sources or unauthorised channels should not be downloaded.
- The use of strong and unique passwords along with MFA wherever possible should be enforced.
From Advisory to Action
The May 2026 cybersecurity road map released by CERT-In signals a departure from identification of threats to enabling operations against frontier AI-led cyber threat landscapes. This initiative builds on their April advice and delineates a clearly articulated three-phase roadmap comprising immediate cyber readiness, AI governance controls, and deep integration of AI-driven defenses. It also provides for the establishment of a focused AI Cyber Defense Center and various multisector governance provisions. A prominent area is the increased threat of impersonation via deepfakes, and companies are encouraged to institute executive verification procedures prior to approving high-value transactions. The framework also emphasizes the establishment of an AI asset register requiring formal accounting and governance of all AI systems utilized in an enterprise. Meanwhile, CERT-In also recognizes the twin-use nature of frontier AI: for every threat, the same technology can bolster security with automated threat detection, phishing, and log analysis in real time. However, the deployment of state-of-the-art defenses is uneven, especially with MSMEs, where there isn’t the requisite domain expertise and funding for this infrastructure. Accordingly, the road map puts the emphasis on immediate and stronger cyber hygiene, compulsory incident reporting, enhancing AI literacy, and proper implementation of the Digital Personal Data Protection Act for long-term security investment and resilience.
Conclusion
The CERT-In advisory CIAD-2026-0020 signifies a vital acknowledgment of AI's transformational impact on the cybersecurity ecosystem. Capabilities formerly exclusive to elite state actors are being deployed by low-skilled users, leveraging state-of-the-art frontier AI tools. India’s MSMEs, enterprises, and digital citizens are experiencing a rapidly accelerating threat milieu. In this context, the CERT-In advisory and the ensuing blueprint can no longer be dismissed as ordinary government pronouncements but as critical operational imperatives. It is the country’s ability over the next few years to shore up its collective cyber resilience to the ever-increasing scale and sophistication of AI-powered attacks that will prove crucial.
References:
- https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES02&VLCODE=CIAD-2026-0020
- https://www.zeebiz.com/technology/news-cert-in-flags-high-severity-ai-cyber-risks-amid-claude-mythos-concerns-394448
- https://www.business-standard.com/technology/tech-news/cert-in-warning-ai-scams-frontier-models-mythos-gpt-5-5-what-it-means-126042800988_1.html
- https://www.businesswire.com/news/home/20251020612551/en/
- https://corporate.indiamart.com/2025/07/29/staying-ahead-of-cyber-threats/
- https://kpmg.com/kpmg-us/content/dam/kpmg/pdf/2025/deepfakes-real-threat.pdf