#FactCheck - "Viral Video Misleadingly Claims Surrender to Indian Army, Actually Shows Bangladesh Army”
Executive Summary:
A viral video has circulated on social media, wrongly showing lawbreakers surrendering to the Indian Army. However, the verification performed shows that the video is of a group surrendering to the Bangladesh Army and is not related to India. The claim that it is related to the Indian Army is false and misleading.

Claims:
A viral video falsely claims that a group of lawbreakers is surrendering to the Indian Army, linking the footage to recent events in India.



Fact Check:
Upon receiving the viral posts, we analysed the keyframes of the video through Google Lens search. The search directed us to credible news sources in Bangladesh, which confirmed that the video was filmed during a surrender event involving criminals in Bangladesh, not India.

We further verified the video by cross-referencing it with official military and news reports from India. None of the sources supported the claim that the video involved the Indian Army. Instead, the video was linked to another similar Bangladesh Media covering the news.

No evidence was found in any credible Indian news media outlets that covered the video. The viral video was clearly taken out of context and misrepresented to mislead viewers.
Conclusion:
The viral video claiming to show lawbreakers surrendering to the Indian Army is footage from Bangladesh. The CyberPeace Research Team confirms that the video is falsely attributed to India, misleading the claim.
- Claim: The video shows miscreants surrendering to the Indian Army.
- Claimed on: Facebook, X, YouTube
- Fact Check: False & Misleading
Related Blogs

Introduction
Recently the attackers employed the CVE-2017-0199 vulnerability in Microsoft Office to deliver a fileless form of the Remcos RAT. The Remcos RAT makes the attacker have full control of the systems that have been infected by this malware. This research will give a detailed technical description of the identified vulnerability, attack vector, and tactics together with the practical steps to counter the identified risks.
The Targeted Malware: Remcos RAT
Remcos RAT (Remote Control & Surveillance) is a commercially available remote access tool designed for legitimate administrative use. However, it has been widely adopted by cybercriminals for its stealth and extensive control capabilities, enabling:
- System control and monitoring
- Keylogging
- Data exfiltration
- Execution of arbitrary commands
The fileless variant utilised in this campaign makes detection even more challenging by running entirely in system memory, leaving minimal forensic traces.
Attack Vector: Phishing with Malicious Excel Attachments
The phishing email will be sent which appears as legitimate business communication, such as a purchase order or invoice. This email contains an Excel attachment that is weaponized to exploit the CVE-2017-0199 vulnerability.
Technical Analysis: CVE-2017-0199 Exploitation
Vulnerability Assessment
- CVE-2017-0199 is a Remote Code Execution (RCE) vulnerability in Microsoft Office which uses Object Linking and Embedding (OLE) objects.
- Affected Components:some text
- Microsoft Word
- Microsoft Excel
- WordPad
- CVSS Score: 7.8 (High Severity)
Mechanism of Exploitation
The vulnerability enables attackers to craft a malicious document when opened, it fetches and executes an external payload via an HTML Application (HTA) file. The execution process occurs without requiring user interaction beyond opening the document.
Detailed Exploitation Steps
- Phishing Email and Malicious Document some text
- The email contains an Excel file designed to make use of CVE-2017-0199.
- When the email gets opened, the document automatically connects to a remote server (e.g., 192.3.220[.]22) to download an HTA file (cookienetbookinetcache.hta).
- Execution via mshta.exe some text
- The downloaded HTA file is executed using mshta.exe, a legitimate Windows process for running HTML Applications.
- This execution is seamless and does not prompt the user, making the attack stealthy.
- Multi-Layer Obfuscation some text
- The HTA file is wrapped in several layers of scripting, including: some text
- JavaScript
- VBScript
- PowerShell
- This obfuscation helps evade static analysis by traditional antivirus solutions.
- The HTA file is wrapped in several layers of scripting, including: some text
- Fileless Payload Deployment some text
- The downloaded executable leverages process hollowing to inject malicious code into legitimate system processes.
- The Remcos RAT payload is loaded directly into memory, avoiding the creation of files on disk.
Fileless Malware Techniques
1. Process Hollowing
The attack replaces the memory of a legitimate process (e.g., explorer.exe) with the malicious Remcos RAT payload. This allows the malware to:
- Evade detection by blending into normal system activity.
- Run with the privileges of the hijacked process.
2. Anti-Analysis Techniques
- Anti-Debugging: Detects the presence of debugging tools and terminates malicious processes if found.
- Anti-VM and Sandbox Evasion: Ensures execution only on real systems to avoid detection during security analysis.
3. In-Memory Execution
- By running entirely in system memory, the malware avoids leaving artifacts on the disk, making forensic analysis and detection more challenging.
Capabilities of Remcos RAT
Once deployed, Remcos RAT provides attackers with a comprehensive suite of functionalities, including:
- Data Exfiltration: some text
- Stealing system information, files, and credentials.
- Remote Execution: some text
- Running arbitrary commands, scripts, and additional payloads.
- Surveillance: some text
- Enabling the camera and microphone.
- Capturing screen activity and clipboard contents.
- System Manipulation: some text
- Modifying Windows Registry entries.
- Controlling system services and processes.
- Disabling user input devices (keyboard and mouse).
Advanced Phishing Techniques in Parallel Campaigns
1. DocuSign Abuse
Attackers exploit legitimate DocuSign APIs to create authentic-looking phishing invoices. These invoices can trick users into authorising payments or signing malicious documents, bypassing traditional email security systems.
2. ZIP File Concatenation
By appending multiple ZIP archives into a single file, attackers exploit inconsistencies in how different tools handle these files. This allows them to embed malware that evades detection by certain archive managers.
Broader Implications of Fileless Malware
Fileless malware like Remcos RAT poses significant challenges:
- Detection Difficulties: Traditional signature-based antivirus systems struggle to detect fileless malware, as there are no static files to scan.
- Forensic Limitations: The lack of disk artifacts complicates post-incident analysis, making it harder to trace the attack's origin and scope.
- Increased Sophistication: These campaigns demonstrate the growing technical prowess of cybercriminals, leveraging legitimate tools and services for malicious purposes.
Mitigation Strategies
- Patch Management some text
- It is important to regularly update software to address known vulnerabilities like CVE-2017-0199. Microsoft released a patch for this vulnerability in April 2017.
- Advanced Email Security some text
- It is important to implement email filtering solutions that can detect phishing attempts, even those using legitimate services like DocuSign.
- Endpoint Detection and Response (EDR)some text
- Always use EDR solutions to monitor for suspicious behavior, such as unauthorized use of mshta.exe or process hollowing.
- User Awareness and Training some text
- Educate users about phishing techniques and the risks of opening unexpected attachments.
- Behavioral Analysis some text
- Deploy security solutions capable of detecting anomalous activity, even if no malicious files are present.
Conclusion
The attack via CVE-2017-0199 further led to the injection of a new fileless variant of Remcos RAT, proving how threats are getting more and more sophisticated. Thanks to the improved obfuscation and the lack of files, the attackers eliminate all traditional antiviral protection and gain full control over the infected computers. It is real and organisations have to make sure that they apply patches on time, that they build better technologies for detection and that the users themselves are more wary of the threats.
References
- Fortinet FortiGuard Labs: Analysis by Xiaopeng Zhang
- Perception Point: Research on ZIP File Concatenation
- Wallarm: DocuSign Phishing Analysis
- Microsoft Security Advisory: CVE-2017-0199

Executive Summary
A shocking video showing a car hanging from a highway signboard is going viral on social media. The clip allegedly shows a black Mahindra Thar stuck on an overhead direction signboard on the Delhi–Jaipur Highway (NH-48). Social media users are widely sharing the video, claiming it shows a real road accident. However, a research by CyberPeace found the viral claim to be false. Our findings reveal that the circulating video is not real but AI-generated.
Claim
Social media users are sharing the clip as footage of an actual road accident. A viral post on X (formerly Twitter) claims that the incident took place on the Delhi–Jaipur Highway, showing a black Mahindra & Mahindra Thar lodged in a highway signboard.
- https://x.com/SenBaijnath/status/2024098520006029504
- https://archive.ph/cmr5e

Fact Check
On closely examining the viral video, several inconsistencies were observed that are commonly associated with AI-generated content. For instance, it appears highly improbable for a heavy vehicle to get stuck precisely at the center of a signboard at such a height. Despite the scale of the alleged incident, traffic on the highway below continues moving normally without any disruption. Additionally, the text visible on the right side of the signboard appears distorted and unusually written. To further verify the authenticity of the video, we analysed it using the AI detection tool Hive Moderation, which indicated a 99.9% probability that the video was AI-generated.

Another AI image detection tool, WasitAI, also found that the visuals in the viral clip were largely AI-generated.

Conclusion
Based on our research and available evidence, it is clear that the viral video showing a Mahindra Thar hanging from a highway signboard is not real but AI-generated.
.webp)
Introduction
As AI becomes more deeply integrated into everyday life and industries, Google Cloud is increasing its investment in AI-ready data centres worldwide, with India emerging as a key part of its expansion plans. Thomas Kurian’s latest India visit highlighted Google Cloud’s expanding ambitions in the country. Beyond the $15 billion, 1GW Visakhapatnam data centre announced in October 2025, Google is planning a larger multi-year AI infrastructure push, backed by partnerships with major enterprises across banking, healthcare, and digital services. This reflects a shift where countries are not only competing to create advanced AI technologies but also to build the infrastructure needed to support and lead the future AI economy. But it's worth being precise about what "building infrastructure" actually means here because it is private, foreign-headquartered capital constructing facilities on Indian soil, under terms that remain largely opaque to the public that will depend on them. That distinction matters more than the investment headline suggests.
The Promise and Pressure of Google’s Full-Stack AI Strategy
For decades, data centres were mainly built to store information, host websites, and support cloud applications. The rise of generative AI has completely changed that role. Today's systems need massive computing power both to train models on huge datasets and to run them every time someone generates content or automates a task. It is distinguished from traditional workloads mainly due to relying on proprietary technologies like GPU or TPU, alongside advanced networking and dynamic storage systems that complement each other and work in unison. The efforts of Google to create its own TPUs are understandable as they played a vital role in a number of achievements made by Google DeepMind. Today, the companies, government entities, and people turning to AI solutions put enormous pressure on the processing of data.
The companies that are building this infrastructure are shaping ecosystems on which others will depend on. Google’s “full stack” approach that infers controlling everything from chips and AI models to cloud platforms and applications which may improve efficiency and reduce costs, but it also creates deeper dependence on a single provider. Like a hospital adopting an AI platform is not just purchasing software; over time, its data systems, workflows, and operations can become closely tied to the underlying cloud ecosystem.
This concern when viewed against the concentration of the global cloud market: Amazon Web Services, Microsoft Azure, and Google Cloud together control roughly two-thirds of global cloud infrastructure, making them the dominant gatekeepers of enterprise computing. As these same companies move upward into AI models and applications while controlling the compute layer beneath them, the debate is no longer only about market share, it is about control over the entire AI value chain.
Why Location Matters and Why It Isn't Enough
In traditional internet services, a delay of a few milliseconds rarely mattered. However, future AI applications like autonomous vehicles, AI-assisted diagnostics, automated factory robotics will demand near-instant decision-making and cannot always depend on servers thousands of kilometres away. Regional data centres reduce that latency, which matters especially for India, where hundreds of millions are expected to interact with AI-powered services in the coming years. There is also the question of data sovereignty, and this is where the infrastructure narrative gets ahead of the regulatory reality. Governments worldwide are increasingly concerned about where citizens' and companies' data is stored and processed and local data centres are presented as the answer, but physical proximity does not automatically translate into legal accountability. Google has acknowledged that it bills cloud revenue through whichever global entity corresponds to the data centre being accessed which means an Indian client's spending on Google Cloud infrastructure inside India may still not be booked, taxed, or contractually governed as an Indian transaction. Google Cloud India Pvt. Ltd reported just ₹2,065.4 crore in FY25 revenue, strikingly disconnected from the scale of a $15 billion facility and its roster of major Indian clients. Servers on Indian soil do not by themselves guarantee that India captures the tax base, the leverage, or the oversight that "data sovereignty" implies.
This gap is widened by where India's own data protection framework stands. The Digital Personal Data Protection (DPDP) Act, 2023 leaves retention periods and purpose limitation loosely specified under Sections 8(7) and 12, and its enforcement rules are still being finalised. When hospitals or banks process data through a foundation-model platform like Gemini Enterprise, questions like where processing occurs and what audit trail exists for cross-border flows are not resolved by a local data centre's presence. At present, they rely mostly on vendor assurance rather than independent verification.
Economic Opportunities: More Than Just Servers
AI data centres are often imagined as buildings filled with computers, but their economic impact extends further, into energy systems, construction, engineering, semiconductor supply chains, and skilled technical work. Countries hosting these facilities can benefit from investment and job creation, while local businesses gain access to AI tools without building expensive infrastructure of their own.
For India, expanded AI infrastructure could support ambitions to become a global technology hub, and could narrow the gap in access to high-performance computing that has historically disadvantaged smaller companies and researchers. That potential is real. But it should be weighed against the terms on which it arrives, whether the economic value generated is captured domestically through tax revenue and enforceable local accountability, or whether India functions primarily as a hosting site while value accrues elsewhere. The current revenue-booking structure suggests the latter is, at minimum, a live risk rather than a settled question.
The Environmental Challenge of AI Expansion
However, what remains less discussed is the environmental cost behind this expansion from its impact on the power grid and water required for cooling to clearing use of renewable energy. A 1GW facility, the scale for the Visakhapatnam project is comparable to the output of a mid-sized power plant dedicated entirely to compute demand. As models grow larger and adoption accelerates, this level of energy and water consumption has become one of the central concerns of the global AI infra. As much attention as the investment figures receive, the sustainability issue behind such large-scale infrastructure deserves equal visibility.
The Future: AI Infrastructure as National Infrastructure
The expansion of Google Cloud's AI data centres show a change in how the world views computing. Data centres are no longer invisible facilities operating in the background; they are becoming strategic infrastructure comparable to power grids and telecom networks. That comparison should prompt that infrastructure this consequential is usually made subject to public oversight, licensing conditions, and accountability mechanisms proportionate to its importance which is missing so far. Google Cloud's investment and the compute capacity it brings will lower barriers for Indian enterprises and researchers who have long lacked access to frontier-scale infrastructure. Against this backdrop, India needs to develop the regulatory, tax, and competition frameworks to ensure that the foundation serves the country hosting it, rather than the company that owns it.
Beyond Compute: The Emerging Question of AI Sovereignty
The next phase of the AI race may not be defined only by who builds the most capable models, but by who governs the infrastructure, standards, and decision making systems that those models depend upon. As advances in artificial general intelligence and discussions around superintelligence move from research laboratories into policy circles, control over compute resources is becoming a matter of strategic importance comparable to control over energy reserves or communication networks. Nations that rely entirely on external providers for advanced AI infrastructure may eventually find themselves dependent not merely for technology services, but for economic productivity, public administration, healthcare delivery, and national security capabilities. For India, the challenge is therefore larger than attracting investment. It is about ensuring meaningful domestic participation in ownership, governance, talent development, and oversight so that the intelligence systems shaping the future remain aligned with national priorities and public interest.
References