#FactCheck-AI-generated video falsely shared as Saudi airstrike on Yemen's Sanaa International Airport
Executive Summary
A video is being widely shared on social media claiming to show a Saudi Arabian F-15 fighter jet carrying out an airstrike on Sanaa International Airport in Yemen's capital. The footage shows several aircraft parked at what appears to be an airport before explosions erupt, followed by flames, thick smoke and people running in panic. The CyberPeace Research Wing found that the viral claim is false. Our research revealed that the circulating video is AI-generated and does not depict the actual airstrike. While it is true that Saudi Arabia carried out an airstrike at Sanaa International Airport, the viral footage is unrelated to that incident and is being shared with a misleading claim.
Claim
An Instagram post shared on July 15, 2026, claims that Saudi Arabia's F-15 fighter jets bombed Sanaa International Airport in Yemen. The post can be viewed here:
https://www.instagram.com/reel/DayBwufzn2N/?utm_source=ig_web_button_share_sheet

Fact Check
To verify the claim, we searched using relevant keywords but found no credible news reports or authentic footage matching the viral video. However, we found verified footage of the actual Saudi airstrike on The New York Post's YouTube channel. A comparison showed that the genuine footage is entirely different from the viral clip in terms of visuals, sequence and overall content.
https://www.instagram.com/reel/DawHCM_s_fn/?utm_source=ig_web_button_share_sheet

During our research, we also found the same viral video on an Instagram account named "warfarenextgen", which regularly publishes AI-generated war-related videos

We further examined the video using multiple AI detection tools: Hive Moderation assessed the video as 99.9% likely to be AI-generated.

DetectVideo AI found a 76% probability that the video was AI-generated.

Sightengine also concluded that the video was approximately 99% likely to be AI-generated.

Conclusion
Our research found that Saudi Arabia did carry out an airstrike on Sanaa International Airport to prevent an Iranian aircraft carrying a Houthi delegation from landing. However, the viral video does not show that attack. It is an AI-generated video that is being falsely circulated as footage of the real incident, making the viral claim misleading.
Related Blogs

Executive Summary:
A video showing a peacock allegedly trapped in ice has been going viral on social media. In the clip, the peacock appears to be frozen in a snow-covered area. Moments later, a man is seen approaching with a hammer and breaking the ice to rescue the bird. Social media users are sharing the video as a real-life incident, praising the peacock’s resilience and describing the scene as inspiring. However, CyberPeace research found the viral claim to be misleading. Our research revealed that the video was created using Artificial Intelligence (AI) and is being falsely circulated as a real incident.
Claim:
Facebook user ‘Ras Bihari Pathak’ shared the viral video on January 25, 2026, with the caption: “This peacock is not standing on ice, but on courage. It reminds us that no matter how harsh the circumstances are, hope always returns in colours.” The archived version of the post can be accessed here.

Fact Check:
To verify the claim, we first conducted a keyword search on Google to check whether any such real incident involving a peacock trapped in ice had been reported. However, no credible or verified media reports were found. Next, we closely examined the viral video. Upon observation, the peacock’s movements and reactions appeared unnatural and artificial. The motion lacked realistic physical behaviour, raising suspicion that the video might have been digitally generated. To confirm this, we analysed the clip using the AI video detection tool Hive Moderation, which indicated a 99 per cent or higher likelihood that the video was AI-generated.

Conclusion:
CyberPeace research confirms that the viral video showing a peacock allegedly trapped in ice is not real. The clip has been created using Artificial Intelligence and is being shared on social media with a false and misleading claim.

On 12 August 2026, President Donald Trump signed a National Security Presidential Memorandum titled Expanding Capabilities to Combat Transnational Cyber Enabled Crime. Stripped of its bureaucratic packaging, the document does something American law has resisted for three decades: it lets private companies, under close federal supervision, break into the systems of foreign criminal networks and, in some cases, disrupt or damage them.
That is a genuinely large policy shift, even if the memorandum itself is careful, almost defensive, about how it frames the shift. Understanding why requires separating what the text actually authorizes from the "hack back" headline that has attached itself to the story within days of signing.
The problem the memo says it is solving
The White House frames this as a response to scale, not ideology. Americans reported losing more than 20.8 billion dollars to cyber enabled crime in 2025, a sharp jump from the roughly 12.5 billion dollar figure cited when the administration's earlier March 2026 executive order on cybercrime, fraud, and predatory schemes was signed. Ransomware, phishing, financial fraud, sextortion, and impersonation scams sit at the center of that number, and the administration's own supporting material points to a grim detail buried in the numbers: one in seven young people who experienced sextortion as a minor reported harming themselves as a result.
Those crimes, the memorandum argues, are increasingly the work of organized, transnational groups operating from jurisdictions the FBI simply cannot reach. Domestic law enforcement, built for domestic crime, is structurally mismatched to a threat that lives across borders and inside encrypted infrastructure. The administration's answer is to formally recruit the resource it says is best positioned to close that gap: the American cybersecurity industry itself, which the memo describes as "the most innovative and technologically advanced in the world."
What the Program actually authorizes
The memorandum directs the National Coordination Center, a body first stood up under a 2025 executive order, to build a formal Program through which vetted Participating Companies can conduct two categories of activity against foreign Cyber Enabled Transnational Criminal Organizations, defined in the text as CE TCOs.
Cyber Surveillance Operations cover unauthorized access to a target's systems for the primary purpose of collecting information or intelligence, undertaken with the intent to remain undetected. Cyber Effects Operations go further: manipulating, disrupting, denying, degrading, or destroying information systems, the infrastructure those systems control, or the data resident on them.
Crucially, CE TCOs are defined narrowly. A foreign group only counts if it targets the US government, US persons, or US interests, and it must not be an institutional arm of a foreign state or wholly directed by one. The memo builds in a presumption of innocence at the state level too: a group is assumed not to be state controlled unless clear intelligence establishes otherwise. That distinction matters enormously, because it is the line meant to separate this Program from anything resembling private warfare against a nation state.
No operation happens unilaterally. Every proposed action must be approved in writing by two Program Executive Directors, one designated by the Attorney General and one by the Secretary of Homeland Security, coordinating with each other before signing off. Participating Companies must pass what the memo calls rigorous vetting, sign contractual agreements with DOJ or DHS, and in many cases post a bond or escrow of at least one million dollars, forfeited if they breach their agreement. Within 60 days of the memo's signing, the Program Executive Directors must publish detailed operating procedures covering everything from target adjudication to what happens if an operation accidentally hits a US person's system, in which case the company must stop, run minimization procedures, and immediately notify the Center.
There is also a hard ceiling built into the design. Operations expected to cause loss of life, serious injury, or conduct that would rise to the level of a use of force or armed attack under international law, termed Critical Outcomes in the text, cannot be approved by the Program Executive Directors at all. That ceiling is the memo's clearest attempt to keep this inside the bounds of law enforcement rather than sliding into something closer to conflict.
Multiple law firms tracking the rollout, including Wiley, have been explicit on one point worth repeating because so much coverage has blurred it: this is not a green light for companies to hack back on their own initiative. Every operation remains, on paper, an act of the federal government, merely executed through a contracted private hand.
Why experts are not popping champagne
Legal caution has not stopped a wave of professional anxiety. Cyber policy veterans interviewed by outlets like CyberScoop describe the memo as a genuine philosophical break in how Washington thinks about offense in cyberspace, and the debate that followed split fairly evenly between cautious optimism and open alarm.
The core worry, echoed across nearly every serious critique, is attribution. Cyber operations are hard to trace precisely because criminals exploit shared infrastructure, proxies, and compromised third party systems to hide, and that same fog does not lift just because a government contract sits behind the operator. A former senior CISA official, Michael Garcia, put the risk plainly: pressure to attribute quickly could push companies toward lower certainty judgments about who they are actually striking, with a realistic chance of hitting the wrong server, or worse, infrastructure tied to a foreign government rather than a criminal gang. A former Cyber Command official was blunter still, describing parts of the memo on social media as a structure that could reward companies for manufacturing billable threats rather than resolving them efficiently.
Paul Rosenzweig, a former DHS policy official, raised a separate and arguably more durable problem: jurisdiction. Whatever this memo authorizes under American law, the systems being accessed usually sit inside someone else's sovereign territory, governed by that country's own criminal statutes. Washington cannot legislate away a foreign hacking law simply by calling the American company that broke it a Participating Company.
None of this makes the memo indefensible. Supporters point out, correctly, that the private sector already does enormous amounts of active defense and threat disruption work informally, through botnet takedown litigation and coordinated infrastructure seizures, and that formalizing federal oversight over that activity is arguably safer than the current improvisation. The honest position, and probably the fair one, is that the memo trades one set of risks for another, and which set turns out worse will depend entirely on the operating procedures due inside sixty days, procedures the public has not yet seen.
CyberPeace Insights: what this means beyond America's borders
A significant share of the CE-TCO activity this memo is built to target, the ransomware crews, romance investment fraud operations, and sextortion rings running out of Southeast Asia, does not victimize Americans in isolation. The scam compounds clustered along the Myanmar, Cambodia, and Laos borders, repeatedly raided over the past two years, have held thousands of trafficked workers of dozens of nationalities, Indians consistently among the largest groups rescued, alongside Chinese, Filipino, and Malaysian nationals. India has run its own repatriation efforts out of Mae Sot in Thailand, bringing citizens home several hundred at a time, and has built its own institutional response to this threat through the Indian Cyber Crime Coordination Centre, which coordinates cybercrime enforcement across states and increasingly across borders.
That shared exposure gives India and the United States real common ground here. The criminal infrastructure this American Program is designed to disrupt is, in significant part, the same infrastructure that has trafficked and defrauded Indian citizens, which gives New Delhi genuine reason to watch this experiment closely and constructively. At the same time, the Program's underlying model, private companies conducting cross-border operations under one nation's legal authorization, is a genuinely new template in international cyber governance, and how it performs over its first year will likely shape how other major digital economies, India included, think about calibrating their own frameworks for public-private cooperation against transnational cybercrime. India and other nations should closely watch whether this becomes a template worth adapting or a cautionary tale worth avoiding.
It is pertinent to note that Justice and Homeland Security departments have 60 days to write detailed operating procedures covering everything from a target-vetting rubric to a classified operational workflow and 180 days to deliver the first status report to the White House.
References
- The White House. "Expanding Capabilities to Combat Transnational Cyber Enabled Crime." 12 August 2026. https://www.whitehouse.gov/presidential-actions/2026/08/expanding-capabilities-to-combat-transnational-cyber-enabled-crime/
- Wiley Rein LLP. "Navigating the New Presidential Memorandum on Transnational Cyber Enabled Crime." August 2026. https://www.wiley.law/alert-Navigating-the-New-Presidential-Memorandum-on-Transnational-Cyber-Enabled-Crime
- SecureWorld. "Trump Memo Lets Private Firms Hack Back at Cybercriminals." August 2026. https://www.secureworld.io/industry-news/trump-authorizes-private-firms-offensive-cyber-operations
- CyberScoop. "A bold new strategy or a dangerous precedent? Experts are divided on Trump's memo." August 2026. https://cyberscoop.com/private-sector-hacking-presidential-memo-cybersecurity/
- CyberScoop. "Trump turns to private sector in offensive hacking operations memo." August 2026. https://cyberscoop.com/trump-memo-private-sector-offensive-hacking/
- CNN Politics. "Cyber privateers: Trump issues order allowing US companies to hack overseas groups under certain conditions." August 2026. https://www.cnn.com/2026/08/13/politics/cyber-privateers-trump-order-overseas-groups-hacking
- NPR. "Trump administration wants to allow companies to hack foreign cybercriminals." August 2026. https://www.npr.org/2026/08/15/nx-s1-5930311/trump-companies-hack-foreign-cybercriminals
- The Next Web. "President Donald Trump signs memo letting US agencies hack transnational crime groups abroad." August 2026. https://thenextweb.com/news/trump-cyber-memo-transnational-crime
- Machine News. "Security firms hit back at Trump's call to hack back against international crime gangs." August 2026. https://www.machine.news/security-firms-hit-back-at-trumps-call-to-hack-back-against-international-crime-gangs/
- Lawfare. "Trump Admin Cyber Strategy Centers Private Sector in Offensive Cyber Operations." March 2026. https://www.lawfaremedia.org/article/trump-admin-cyber-strategy-centers-private-sector-in-offensive-cyber-operations
- Lawfare. "Partners or Provocateurs? Private Sector Involvement in Offensive Cyber Operations." July 2025. https://www.lawfaremedia.org/article/partners-or-provocateurs--private-sector-involvement-in-offensive-cyber-operations
- Global Indian Network. "Pig Butchering Scams in India: The Dark Intersection of Social Media, AI, and Emotional Manipulation." January 2026. https://globalindiannetwork.com/pig-butchering-scams-in-india/
- The Tribune. "India brings home scammed 549 nationals from Myanmar in 2 days." 2025. https://www.tribuneindia.com/news/india/india-brings-home-scammed-549-nationals-from-myanmar-in-2-days
- Malay Mail. "India to repatriate 500 nationals fleeing Myanmar's cyber scam hub, says Thai PM." October 2025. https://www.malaymail.com/amp/news/world/2025/10/29/india-to-repatriate-500-nationals-fleeing-myanmars-cyber-scam-hub-says-thai-pm/196399
- NBC News. "260 foreigners rescued from virtual slavery in Myanmar's online scam centers are being repatriated." 2025. https://www.nbcnews.com/news/world/260-foreigners-rescued-virtual-slavery-myanmars-online-scam-centers-ar-rcna192180
- CyberPeace Foundation. "About Us." https://cyberpeace.org/about-us
Contributors
- Maj. Vineet Kumar, Founder & Global President, CyberPeace
- Mr. Neeraj Soni, Senior Research Analyst, Policy & Advocacy, CyberPeace
List of Abbreviations
- CE‑TCO — Cyber Enabled Transnational Criminal Organization
- DOJ — Department of Justice
- DHS — Department of Homeland Security
- FBI — Federal Bureau of Investigation
- CISA — Cybersecurity and Infrastructure Security Agency
- I4C — Indian Cyber Crime Coordination Centre
- US — United States
- IT — Information Technology

Introduction
A famous quote, “Half knowledge is always dangerous”, but “Too much knowledge of anything can lead to destruction”. Recently very infamous spyware and malware named WyrmSpy and Dragon Egg were invented by a Chinese group of hackers APT41. The APT41 is a state-endorsed Clandstein active group based in the People’s Republic of China that has been active since 2012. In contrast to numerous countries-government supported, APT has a footprint record jeopardising both government organisations for clandestine activities as well as different private organisations or enterprises for their financial gain. APT41 group aims at Android devices through spyware wyrmspy and dragon egg, which masquerades as a legitimate application. According to the U.S. jury legal accusation from 2019 to 2020, the group was entangled in threatening over more than 100 public and private individuals and organisations in the United States and around the world.Moreover, a detailed analysis report was shared by the Lookout Threat Researchers, that has been actively monitoring and tracking both spyware and malware.
Briefing about how spyware attacks on Android devices take place
To begin with, this malware imitates a real source Android application to show some sort of notification. Once it is successfully installed on the user’s machine, proclaims multiple device’s permission to enable data filtration.
Wyrmspy complies with log files, photos, device locations, SMS(read and write), and audio recordings. It has also authenticated that there are no detection malware activities found on google play even after running multiple security levels. These malicious things are made with the intent to obtain rooting access privileges to the device and monitor activities to the specified commands received from the C2 servers.
Similarly, Dragon Egg can collect data files, contacts, locations, and audio recordings, and it also accesses camera photos once it successfully trade-off the device. Dragon egg receives a payload that is also known as “smallmload.jar”, which is either from APK(Android Packet Kit).
WyrmSpy initially masquerades as a default operation system application, and Dragon Egg simulates a third-party keyboard/ messaging application.
Overview of APT41 Chinese group background
APT41 is a Chinese-based stealth activity-carrying group that is said to be active since mid-2006. Rumours about APT41 that it was also a part of the 2nd Bureau of the People’s Liberation Army (PLA) General Staff Department’s (GSD) 3rd Department. Owning to that fact, 2006 has seen 140+ organisations’ security getting compromised, ranging from 20 strategically crucial companies.APT is also recognised for rationally plundering hundreds of terabytes of data from at least 141 organisations between 2006 and 2013. It typically begins with spear-phishing emails to the targeted victims. These sent emails contain official templates along with language pretending to be from a legitimate real source, carrying a malicious attachment. As the victim opens the attached file, the backdoor bestows the control of the targeted machine to the APT groups machine. Once there is an unauthorised gain of access, the attacker visits and revisits the victim’s machine. The group remains dormant for lengthy durations, more likely for months or even for years.
Advisory points need to adhere to while using Android devices
- The security patch update is necessary at least once a week
- Clearing up unwanted junk files.
- Cache files of every frequently used application need to clear out.
- Install only required applications from
Google play store. - Download only necessary APK files only it comes from trusted resources.
- Before giving device permission, it is advisable to run your files or URLs on VirusTotal.com this website will give a good closure to the malicious intent.
- Install good antivirus software.
- Individuals need to check the source of the email before opening an attachment to it.
- Never collect or add any randomly found device to your system
- Moreover, the user needs to keep track of their device activity. Rather than using devices just for entertainment purposes, it is more important to look for data protection on that device.
Conclusion
Network Crack Program Hacker Group (NCPH), which grew as an APT41 group with malicious intent, earlier performed the role of grey hat hacker, this group somehow grew up greedy to enhance more money laundering by hacking networks, devices, etc. As this group conducts a supply chain of attacks to gain unauthorised access to the network throughout the world, targeting hundreds of companies, including an extensive selection of industries such as social media, telecommunications, government, defence, education, and manufacturing. Last but not least, many more fraud-making groups with malicious intent will be forming and implementing in the future. It is on individuals and organisations to secure themselves but practise basic security levels to safeguard themselves against such threats and attacks.