#FactCheck -Bangladesh protest video falsely shared as police firing incident in Bihar’s Siwan
Executive Summary
A video is being widely shared on social media with the claim that a youth was killed in police firing in Bihar’s Siwan. The viral 1-minute-22-second video shows a young man standing with a stick in his hand. Moments later, gunfire is heard, after which he appears to be injured and collapses. His associates are then seen carrying him away from the spot. CyberPeace Research Wing’s research found that the claim is false. The research revealed that the viral video is not from Bihar’s Siwan but dates back to the student protests in Bangladesh in July 2024.
Claim:
The video was shared on X with a caption claiming that it shows a police firing incident in Bihar’s Siwan, where a student was allegedly killed after police opened fire with AK-47 rifles.
The caption stated, “This video is going viral on social media. It is being claimed that this video is from Siwan, Bihar, where police fired AK-47s at students. During the firing, a youth was hit by two bullets and died.”
https://x.com/Deshmukh_0/status/2082053481993740701

Fact Check:
To verify the authenticity of the viral claim, we extracted keyframes from the video and conducted a reverse image search. During the research, we found a longer version of the same video uploaded on the YouTube channel of a Bangladeshi news portal on July 16, 2024.
According to the video description, the footage shows the death of student Abu Sayed during protests in Rangpur, Bangladesh, on July 16, 2024.
https://www.youtube.com/watch?v=iuf7H0MNIaI

Further research led us to a report published by bdnews24, which also carried visuals matching those seen in the viral video. The report stated that on July 16, 2024, Abu Sayed, an English Department student at Begum Rokeya University in Rangpur, Bangladesh, died after being shot during the protests.
https://bdnews24.com/bangladesh/87ef7e69c496#google_vignette

Conclusion:
The evidence gathered during the research confirms that the viral video claiming to show a youth being killed in police firing in Bihar’s Siwan is misleading. The video is actually from Bangladesh and shows the death of student Abu Sayed during the July 2024 protests in Rangpur. The old footage is being shared with a false claim linking it to a recent incident in Bihar.
Related Blogs

Introduction
For more than 10 years, WhatsApp has been designed around one seemingly trivial but impactful idea: your phone number is your digital identity. This concept offered simplicity in terms of contact discovery and onboard- ing but inevitably exposed users to fraud, spam and the everyday necessity of sharing personal phone numbers with complete strangers in group chats and conversations. On June 29th Meta finally revealed a major move: you’ll now be able to choose and reservate a WhatsApp username and communicate without sharing your phone number.
This shift to a username based identity marks the company catching up to platforms like Telegram and Signal, which have utilized this functionality for years.
However, while presented as a push towards greater privacy for the millions using its platform, this new change has already created some alarm around impersonation, cybersquatting, and identity theft. The issues became amplified when, according to reports, the Indian Ministry of Electronics and Information Technology advised WhatsApp to halt the implementation of the new features while it clarifies details, shifting a mundane app update into a high-stakes discussion on digital privacy, platform responsibility, and government regulation.
How does the mechanism work?
“WhatsApp’s username is an added pseudonym layer on its current phone number architecture, not a replacement,” Meta said in a statement on Thursday, as reported by TechCrunch. A WhatsApp username is a three to 35-character name containing lower case letters, numbers, periods and underscores that must contain at least one letter and “should not look like a website address.” The feature will allow you to “reserve a unique identifier that you can share as an alternative to your phone number in WhatsApp Settings - Accounts - Username.”
It said the usernames will work in parallel with a username key which can serve as a passphrase to initiate conversation “with a recipient before sending a message for the first time.”
“The change - which will have some additional, protective measures like reserving usernames for people of public interest or those that would cause impersonation, and rate limits on claiming names - can help maintain phone number protection, while offering people more choices,” Meta said. WhatsApp said usernames will replace phone numbers as the primary way to initiate new chats, but will not be publicly searchable: “Anyone you message would need your exact username, and would still need you to respond.”
The Genuine Privacy Case
The upside is real. Phone numbers double as keys to two-factor authentication, banking apps and SIM-swap fraud, so handing one to a new acquaintance, a group chat of strangers or a customer-support bot has always carried quiet risk. Numbers harvested from public groups already fuel spam and scam campaigns, and a username-first model narrows that exposure considerably.
For journalists, small business owners and anyone who fields messages from people they've never met, decoupling identity from a number that also unlocks their bank account is a meaningful, overdue shift – and one that WhatsApp's closest competitors adopted years ago without major incident.
The Scammer's Paradise Scenario
The trouble lies in what a username removes. A phone number was never just an identifier; it was also a rough verification signal and, for law enforcement, a traceable data point. Security reporters testing the reservation system found that lookalike handles mimicking prominent Indian politicians, film stars and the Reserve Bank of India remained available to claim. Crypto executive Changpeng Zhao's own failed bid to capture his desired handle highlighted the first-come, first-served danger of the rollout and led researchers to advise people to manually activate the optional username key that Meta leaves disabled by default.
The Mozilla Foundation was unvarnished about the tradeoff, noting that impersonation from fake accounts and scams are an “inevitable consequence” of a design that abandons the “implicit signal of authenticity” that comes from owning a phone number.
Indian entrepreneur Ankur Warikoo called the rollout a potential “disaster” if robust enforcement against fraud isn’t immediately applied because scammers could register handles a few characters removed from a popular brand or public figure to launch investment and payment schemes, a concern mirrored by cyber security researchers who observed that many users neglect to check verification badges before trusting an account.
India's Regulatory Scrutiny of WhatsApp's Username Feature
So far the strongest reaction comes from New Delhi. The Ministry of Electronics and Information Technology (MeitY) issued an official notice to Meta's compliance office that it should “temporarily suspend the feature” in the country pending further consultations and “provided an explanation in three days”. The cited concerns involve “digital arrest” fraud, a rapid boom category that involves crooks impersonating investigators like those with India's CBI, judges or customs agents to extort victims, in addition to standard concerns around phishing and bank or government impersonation.
A subtler concern, for India’s government anyway, is “traceability.”
At present, say officials, an Indian mobile number is a launching pad to determine whether a given suspect is a domestic or international actor, while a username and foreign SIM would leave authorities nowhere to begin. The Department of Telecommunications independently voiced concerns over how the change intersects with its SIM-binding regulations and over WhatsApp's lag time for such requests. The MeitY notice, the legal basis for which, incidentally, is in contention with some digital rights groups, specifically invokes Section 79 of the IT Act and various IT Rules from 2021 and provisions on identity theft and impersonation that target individual criminals rather than the tech tools. Not everyone, however, shares MeitY’s reading of the legal ground: the Internet Freedom Foundation says that Section 79 “deal with liability of intermediary” and “does not confer on the government power to license the features of a product,” while arguing the relevant criminal statutes were designed to criminalize impersonators, not tech platforms whose services are misused, echoing concerns that killed a similar government advisement about AI models last spring.
In the meantime, Meta says usernames are unavailable in the country for now and the multilayered safeguards it designed were always intended for exactly this level of risk.
Conclusion
WhatsApp's username feature is neither a total privacy upgrade nor a major security problem; instead, it reallocates risk, reducing phone number exposure while adding a risk of identity spoofing and misuse. Whether it pays off will hinge on the strength of Meta's crackdown on fraudulent usernames, the uptake of extra security features like the username key and whether the company can adequately satisfy regulatory concerns about traceability and user safety. Until all those questions are fully settled, users may want to use the feature tentatively, secure a desired username, enable any other protections and be watchful about new contacts.
References
- https://blog.whatsapp.com/its-time-to-reserve-your-whatsapp-username
- https://www.businesstoday.in/technology/news/story/whatsapp-usernames-why-indias-top-creators-fear-scams-impersonation-and-identity-theft-540359-2026-07-02
- https://www.outlookindia.com/national/outlook-explains-why-is-the-indian-government-worried-about-whatsapp-usernames
- https://techcrunch.com/2026/06/29/whatsapp-now-lets-you-reserve-usernames/
- https://bestmediainfo.com/mediainfo/mediainfo-digital/whatsapp-says-username-feature-not-live-yet-after-meity-asks-meta-to-pause-rollout-12124813

Executive Summary
A video showing a group of Hindu ascetics (sadhus) allegedly performing intense penance while their bodies appear to be covered in ice is being widely shared on social media. Users are circulating the video as real and claiming that it represents an ancient tradition of Sanatan Dharma. CyberPeace research found the viral claim to be false.The research revealed that the video circulating on social media is not real but has been generated using artificial intelligence (AI).
Claim
On social media platform Facebook, a user shared the viral video on January 16, 2026. The video shows several ascetics engaged in penance, with their bodies seemingly covered in ice. Users shared the video while claiming that it depicts an authentic spiritual practice rooted in Sanatan Dharma.
Links to the post, archive link, and screenshots can be seen below.

Fact Check:
To verify the authenticity of the viral claim, CyberPeace searched relevant keywords on Google. However, no credible or reliable media reports supporting the claim were found. A close examination of the viral video raised suspicion that it may have been AI-generated. To verify this, the video was analysed using the AI detection tool Hive Moderation. According to the results, the video was found to be 99 percent AI-generated.

In the next step of the research, the same video was analysed using another AI detection tool, Sightengine. The results again indicated that the video was 99 percent AI-generated.

Conclusion
CyberPeace concludes that the video circulating on social media is not real. The viral video showing ascetics covered in ice was generated using artificial intelligence and does not depict an actual religious or spiritual practice.

Overview:
A recent addition to the list of cybercrime is SharpRhino, a RAT (Remote Access Trojan) actively used by Hunters International ransomware group. SharpRhino is highly developed and penetrates into the network mask of IT specialists, primarily due to the belief in the tools’ legitimacy. Going under the genuine software installer, SharpRhino started functioning in mid-June 2024. However, Quorum Cyber discovered it in early August 2024 while investigating ransomware.
About Hunters International Group:
Hunters International emerged as one of the most notorious groups focused on ransomware attacks, having compromised over 134 targets worldwide in the first seven months of 2024. It is believed that the group is the rebranding of Hive ransomware group that was previously active, and there are considerable similarities in the code. Its focus on IT employees in particular demonstrates the fact that they move tactically in gaining access to the organizations’ networks.
Modus Operandi:
1. Typosquatting Technique
SharpRhino is mainly distributed by a domain that looks like the genuine Angry IP Scanner, which is a popular network discovery tool. The malware installer, labeled as ipscan-3.9.1-setup. It is a 32-bit Nullsoft installer which embeds a password protected 7z archive in it.
2. Installation Process
- Execution of Installer: When the victim downloads and executes the installer and changes the windows registry in order to attain persistence. This is done by generating a registry entry that starts a harmful file, Microsoft. AnyKey. exe, are fakes originating from fake versions of true legitimate Microsoft Visual Studio tools.
- Creation of Batch File: This drops a batch file qualified as LogUpdate at the installer.bat, that runs the PowerShell scripts on the device. These scripts are to compile C# code into memory to serve as a means of making the malware covert in its operation.
- Directory Creation: The installer establishes two directories that allow the C2 communication – C:\ProgramData\Microsoft: WindowsUpdater24 and LogUpdateWindows.
3. Execution and Functionality:
- Command Execution: The malware can execute PowerShell commands on the infected system, these actions may involve privilege escalation and other extended actions such as lateral movement.
- C2 Communication: SharpRhino interacts with command and control servers located on domains from platforms such as Cloudflare. This communication is necessary for receiving commands from the attackers and for returning any data of interest to the attackers.
- Data Exfiltration and Ransomware Deployment: Once SharpRhino has gained control, it can steal information and then proceed to encrypt it with a .locked extension. The procedure generally concludes with a ransom message, which informs users on how to purchase the decryption key.
4. Propagation Techniques:
Also, SharpRhino can spread through the self-copying method, this is the virus may copy itself to other computers using the network account of the victim and pretending to be trustworthy senders such as emails or network-shared files. Moreover, the victim’s machine may then proceed to propagate the malware to other systems like sharing in the company with other employees.
Indicators of Compromise (IOCs):
- LogUpdate.bat
- Wiaphoh7um.t
- ipscan-3.9.1-setup.exe
- kautix2aeX.t
- WindowsUpdate.bat
Command and Control Servers:
- cdn-server-1.xiren77418.workers.dev
- cdn-server-2.wesoc40288.workers.dev
- Angryipo.org
- Angryipsca.com
Analysis:

Graph:

Precautionary measures to be taken:
To mitigate the risks posed by SharpRhino and similar malware, organizations should implement the following measures:
- Implement Security Best Practices: It is important only to download software from official sites and avoid similar sites to confuse the user by changing a few letters.
- Enhance Detection Capabilities: Use technology in detection that can detect the IOCs linked to Sharp Rhino.
- Educate Employees: Educate IT people and employees on phishing scams and the requirement to check the origin of the application.
- Regular Backups: It is also important to back up important files from systems and networks in order to minimize the effects of ransomware attacks on a business.
Conclusion:
SharpRhino could be deemed as the evolution of the strategies used by organizations like Hunters International and others involved in the distribution of ransomware. SharpRhino primarily focuses on the audience of IT professionals and employs complex delivery and execution schemes, which makes it an extremely serious threat for corporate networks. To do so it is imperative that organizations have an understanding of its inner workings in order to fortify their security measures against this relatively new threat. Through the enforcement of proper security measures and constant enlightenment of organizations on the importance of cybersecurity, firms can prevent the various risks associated with SharpRhino and related malware. Be safe, be knowledgeable, and most importantly, be secure when it comes to cyber security for your investments.
Reference:
https://cybersecuritynews.com/sharprhino-ransomware-alert/
https://cybersecsentinel.com/sharprhino-explained-key-facts-and-how-to-protect-your-data/
https://www.dataprivacyandsecurityinsider.com/2024/08/sharprhino-malware-targeting-it-professionals/