#FactCheck -Scripted Video of Pre-Wedding Roka at Metro Station Misleads Users
Executive Summary
A video is going viral on social media showing a woman performing a pre-wedding ritual called “Roka” for a couple at a metro station. Many users are sharing the clip believing it to be a real incident. CyberPeace found in its research that the viral claim is false. The video is actually scripted.
Claim:
An Instagram user posted the video on February 7, 2026, with the caption, “A mother performed her son’s Roka with his girlfriend at a metro station.”

Fact Check:
To verify the claim, we conducted a reverse image search using Google Lens on screenshots from the viral video. We found the same video was first uploaded on February 5, 2026, by an Instagram account named “chalte_phirte098.” The profile belongs to digital content creator Aarav Mavi, who regularly posts relationship and breakup-related videos.

Although the viral clip does not include any disclaimer stating that it is scripted, an older video posted by the creator on December 16, 2025, clarifies that his content is based on real-life stories shared by people but is filmed using professional actors. Several similar staged videos are also available on his profile on Instagram.

Conclusion:
Our research clearly shows that the viral video claiming to show a pre-wedding Roka ceremony at a metro station is not real. It was created by a content creator for entertainment purposes. Therefore, the claim circulating on social media is misleading.
Related Blogs

Overview:
A recent addition to the list of cybercrime is SharpRhino, a RAT (Remote Access Trojan) actively used by Hunters International ransomware group. SharpRhino is highly developed and penetrates into the network mask of IT specialists, primarily due to the belief in the tools’ legitimacy. Going under the genuine software installer, SharpRhino started functioning in mid-June 2024. However, Quorum Cyber discovered it in early August 2024 while investigating ransomware.
About Hunters International Group:
Hunters International emerged as one of the most notorious groups focused on ransomware attacks, having compromised over 134 targets worldwide in the first seven months of 2024. It is believed that the group is the rebranding of Hive ransomware group that was previously active, and there are considerable similarities in the code. Its focus on IT employees in particular demonstrates the fact that they move tactically in gaining access to the organizations’ networks.
Modus Operandi:
1. Typosquatting Technique
SharpRhino is mainly distributed by a domain that looks like the genuine Angry IP Scanner, which is a popular network discovery tool. The malware installer, labeled as ipscan-3.9.1-setup. It is a 32-bit Nullsoft installer which embeds a password protected 7z archive in it.
2. Installation Process
- Execution of Installer: When the victim downloads and executes the installer and changes the windows registry in order to attain persistence. This is done by generating a registry entry that starts a harmful file, Microsoft. AnyKey. exe, are fakes originating from fake versions of true legitimate Microsoft Visual Studio tools.
- Creation of Batch File: This drops a batch file qualified as LogUpdate at the installer.bat, that runs the PowerShell scripts on the device. These scripts are to compile C# code into memory to serve as a means of making the malware covert in its operation.
- Directory Creation: The installer establishes two directories that allow the C2 communication – C:\ProgramData\Microsoft: WindowsUpdater24 and LogUpdateWindows.
3. Execution and Functionality:
- Command Execution: The malware can execute PowerShell commands on the infected system, these actions may involve privilege escalation and other extended actions such as lateral movement.
- C2 Communication: SharpRhino interacts with command and control servers located on domains from platforms such as Cloudflare. This communication is necessary for receiving commands from the attackers and for returning any data of interest to the attackers.
- Data Exfiltration and Ransomware Deployment: Once SharpRhino has gained control, it can steal information and then proceed to encrypt it with a .locked extension. The procedure generally concludes with a ransom message, which informs users on how to purchase the decryption key.
4. Propagation Techniques:
Also, SharpRhino can spread through the self-copying method, this is the virus may copy itself to other computers using the network account of the victim and pretending to be trustworthy senders such as emails or network-shared files. Moreover, the victim’s machine may then proceed to propagate the malware to other systems like sharing in the company with other employees.
Indicators of Compromise (IOCs):
- LogUpdate.bat
- Wiaphoh7um.t
- ipscan-3.9.1-setup.exe
- kautix2aeX.t
- WindowsUpdate.bat
Command and Control Servers:
- cdn-server-1.xiren77418.workers.dev
- cdn-server-2.wesoc40288.workers.dev
- Angryipo.org
- Angryipsca.com
Analysis:

Graph:

Precautionary measures to be taken:
To mitigate the risks posed by SharpRhino and similar malware, organizations should implement the following measures:
- Implement Security Best Practices: It is important only to download software from official sites and avoid similar sites to confuse the user by changing a few letters.
- Enhance Detection Capabilities: Use technology in detection that can detect the IOCs linked to Sharp Rhino.
- Educate Employees: Educate IT people and employees on phishing scams and the requirement to check the origin of the application.
- Regular Backups: It is also important to back up important files from systems and networks in order to minimize the effects of ransomware attacks on a business.
Conclusion:
SharpRhino could be deemed as the evolution of the strategies used by organizations like Hunters International and others involved in the distribution of ransomware. SharpRhino primarily focuses on the audience of IT professionals and employs complex delivery and execution schemes, which makes it an extremely serious threat for corporate networks. To do so it is imperative that organizations have an understanding of its inner workings in order to fortify their security measures against this relatively new threat. Through the enforcement of proper security measures and constant enlightenment of organizations on the importance of cybersecurity, firms can prevent the various risks associated with SharpRhino and related malware. Be safe, be knowledgeable, and most importantly, be secure when it comes to cyber security for your investments.
Reference:
https://cybersecuritynews.com/sharprhino-ransomware-alert/
https://cybersecsentinel.com/sharprhino-explained-key-facts-and-how-to-protect-your-data/
https://www.dataprivacyandsecurityinsider.com/2024/08/sharprhino-malware-targeting-it-professionals/

Executive Summary:
A video clip featuring Prime Minister Narendra Modi and the newly elected Bharatiya Janata Party (BJP) national president, Nitin Nabin, is going viral on social media. In the clip, PM Modi is seen apparently pushing Nitin Nabin, prompting claims that Nabin had accidentally stepped between the Prime Minister and the camera, after which Modi allegedly pushed him out of the frame. CyberPeace’s research found that the viral clip is misleading and cropped. The original, unedited video shows Prime Minister Modi gesturing for Nitin Nabin to move ahead and offer floral tributes to the statues of Bharatiya Jana Sangh founder Syama Prasad Mukherjee and Pandit Deendayal Upadhyaya at the BJP headquarters in Delhi. It is pertinent to note that on 20 January 2026, BJP leader Nitin Nabin was elected as the party’s national president. Several senior BJP leaders, including Prime Minister Narendra Modi, were present at the event. During his address, PM Modi remarked, “Nitin Nabin ji is my boss, and I am a party worker.” The statement received widespread attention, following which multiple videos linking to the remark began circulating on social media. A Facebook user shared the viral clip with a Hindi caption alleging that despite calling himself a “party worker,” PM Modi pushed his “boss” out of the camera frame. The post further mocked the position of BJP president, claiming it to be merely ceremonial. (Archived link)
To verify the claim, we conducted a reverse image and video search, which led us to a longer version of the video uploaded on news agency INS’s official X handle on 20 January 2026. The caption stated that PM Modi, BJP president Nitin Nabin, Defence Minister Rajnath Singh, Home Minister Amit Shah, Union Minister Nitin Gadkari and senior leader J.P. Nadda paid tributes to Syama Prasad Mukherjee and Pandit Deendayal Upadhyaya at the BJP headquarters.

In the full video, PM Modi and Nitin Nabin are seen walking together. PM Modi then requests Nitin Nabin to proceed first for the floral tribute, placing his hand on Nabin’s back as a gesture to move forward. The viral clip selectively cuts this moment out of context and loops it to create a misleading impression. The complete footage clearly shows that PM Modi asked Nitin Nabin to offer tributes first, after which other leaders followed. There is no indication whatsoever that Nitin Nabin was pushed out of the camera frame, as claimed in the viral posts. We also found the live broadcast of the ‘Bharatiya Janata Party Sangathan Parv’ on BJP’s official YouTube channel. The same visuals appear at the end of the live stream, further confirming that PM Modi was merely gesturing for Nitin Nabin to proceed first.
Additionally, photographs available on Nitin Nabin’s official X handle show him offering floral tributes ahead of PM Modi, who is seen standing behind and waiting.

Conclusion:
CyberPeace research confirms that the viral clip has been cropped and shared with a false narrative. In the original context, Prime Minister Narendra Modi was respectfully inviting BJP national president Nitin Nabin to move ahead and pay tributes, not pushing him out of the camera frame.

Executive Summary:
A photo is being circulated on social media with the claim that it shows Ram Prakash, an official from the Indian High Commission in the United Kingdom (UK), participating in a protest organised over issues related to PoK. CyberPeace Research Wing’s research found the claim associated with the image to be false. The research confirmed that the image was digitally modified using OpenAI’s AI tools.
Claim:
A user on social media platform X (formerly Twitter) shared the viral image on August 4, 2026, claiming that Shri Ram Prakash, an official from the Indian High Commission in London, was seen formally participating in a protest organised by the banned Joint Awami Action Committee (JAAC). The post link, archive link, and screenshot are provided below:
https://x.com/i/birdwatch/t/2084551118189904105?source=6

Fact Check:
During the research, we conducted a Google search using relevant keywords. We traced the original source of the viral visual to a social media post shared by Pakistani media outlet GEO News’ UK Bureau Chief Murtaza Ali Shah on August 2, 2024.
The post featured a video of a protest held in Luton, United Kingdom, where a large number of British Kashmiris were seen marching to express concerns over the situation in Pakistan-occupied Kashmir (PoK). At the time, the Joint Awami Action Committee (JAAC) was leading a prolonged protest in the region.
https://www.facebook.com/reel/1383400640416385

At the 1:23 mark of the video shared by the Pakistani journalist, we found the same scene that appears in the viral image. However, the individual seen in the viral image does not appear in the original footage. Instead, the video shows a different person participating in the protest.

To further verify the authenticity of the image, we analysed it using multiple AI detection tools, including OpenAI’s image detection tool. The analysis detected provenance signals associated with OpenAI tools such as ChatGPT, OpenAI API, or Codex. These signals indicate that the image was created or modified using OpenAI’s AI tools.

Conclusion:
The research established that the viral image has been manipulated to falsely portray Indian High Commission official Ram Prakash as a participant in the protest. The original footage shows a different individual, while AI analysis confirmed that the image was modified using OpenAI tools. Therefore, the claim circulating with the image is misleading.