#FactCheck: Old Protest Video Misleadingly Shared as Police Action During BRICS Summit
Executive Summary
A video is being shared on social media with the claim that youths have announced sit-ins and protests in Delhi during the 18th BRICS Summit. The video is being shared with allegations that the Modi government attempted to suppress the protests and subjected the youth to severe oppression. It also claims that a large-scale protest would be held in Delhi on September 16. The video shows a large gathering of people, with police personnel seen taking action against them.
Research by CyberPeace found that the video is old and has been available online since at least July 20, 2026. According to earlier sources, the video shows police action against CJP protesters who were marching towards Parliament on July 20, 2026. Meanwhile, the 18th BRICS Summit is being held in New Delhi on September 12 and 13, 2026. Therefore, the old video is being misleadingly linked to police action during the BRICS Summit.
Claim:
A video is being shared on social media with the claim that youths have announced sit-ins and protests in Delhi during the 18th BRICS Summit and that the Modi government subjected them to severe oppression while attempting to suppress the protests.
https://x.com/indiantiwari01/status/2098058633825411110?s=20

FactCheck:
To verify the authenticity of the viral claim, we conducted a reverse image search of the keyframes from the video. During the search, we found the same video on the YouTube channel ANKIT'S PEACEFUL MIND, where it was published on July 20, 2026.
https://www.youtube.com/watch?v=uPsm9jueugY

According to the video description, a tense situation unfolded at Jantar Mantar in Delhi, where police took action against people holding a peaceful protest and resorted to a lathi charge. The post claimed that thousands of youths, students and others had gathered in Delhi in support of environmental activist Sonam Wangchuk and the ongoing Ladakh movement. The situation reportedly escalated, leading to clashes between the protesters and the large number of security personnel deployed at the site.
As part of the next step in our research, we found the same video on a Facebook page, where it was published on July 20. The video was also shared with the claim that security forces had resorted to a lathi charge against protesters during a CJP demonstration at Jantar Mantar in Delhi.
https://www.facebook.com/watch/?v=1583508539869113

Conclusion:
Our research found that the video being shared on social media is not related to any incident during the BRICS Summit. The video is old and has been available online since at least July 20, 2026. According to earlier sources, the video shows police action against CJP protesters who were marching towards Parliament on July 20. Meanwhile, the 18th BRICS Summit is being held in New Delhi on September 12 and 13, 2026. Therefore, sharing the old video as footage of police action against protesters during the BRICS Summit is misleading.
Related Blogs

A war in the twenty-first century does not start when the first bullet or missile is fired. It begins much earlier, covertly, and without any official announcement. Cyberspace is this new battlefield. States now use a variety of ransomware, malicious codes, and disinformation campaigns to undermine their enemies' capabilities before launching an offensive. These pre-conflict cyber operations are now the primary frontline of contemporary hybrid warfare, which is changing how conflicts are fought and conducted.
The Birth of a Digital Battlefield
Hybrid Warfare is a blend of conventional military force with nonmilitary tactics like economic coercion, disinformation, and cyberattacks that have evolved rapidly in recent decades. Hybrid methods of warfare are nothing new, as the scale and sophistication of cyber operations in modern conflicts are unprecedented. Russia’s actions in Ukraine demonstrated the capability of digital tools to paralyse the critical systems before its heavy munitions could be deployed for combat operations. Within days of the 2022 invasions, Ukraine faced massive Distributed Denial of Service (DDoS) attacks targeting banks, government websites, and energy infrastructures. The digital frontlines have softened the physical defences long before the conventional warfare began.
According to the FP Analytics’ “Digital Front Lines” Project, cyber operations are no longer an auxiliary tactic but a core component of hybrid warfare, blurring the boundary between peace and war. They enable states to exert pressure, gather intelligence, and disrupt adversaries, often without being attributed or held accountable.
Cyber Operations: The modern Prelude to War
The use of digital technologies for surveillance, information network disruption, or critical infrastructure destruction is known as cyber operations. They are especially useful instruments for pre-conflict manipulation because of their ambiguity and stealth. Cyberattacks, in contrast to conventional military strikes, can accomplish strategic goals while providing plausible deniability.
Coordinated cyberattacks that spread misinformation and damaged public confidence disrupted government communication systems prior to Russia's invasion of Ukraine. These sorts of incidents highlight the integrated nature of cyber and kinetic operations, where digital assaults often serve as the initial phases of modern wars.
The Expanding Spectrum of Actors or Threat
Cyberspace has democratized warfare, which once required an army, can now be initiated by a handful of skilled programmers with access to the right tools. The cyber landscape of the present times features a wide spectrum of threat actors, which can be understood as;
- State actors like intelligence or military agencies conduct cyber operations as part of official foreign policy.
- Cybercriminals pursue financial gains, often overlapping with political motives.
- Terrorist groups use cyberspace to spread propaganda for coordinated attacks.
- Cyber mercenaries being hired by both the state and nonstate clients can blur the ethical and legal boundaries.
This diversity can complicate the attribution by determining that anyone who is actively working behind conducting cyberattacks can be notoriously difficult, allowing the states to hide behind “plausible deniability.” This ‘Gray Zone’ of conflict below the threshold of a declared war, above mere diplomacy, has become the preferred arena for modern power struggles.
Civilian Involvement and Ethical Dilemmas
Unlike traditional warfare, where the cyber domain entangles civilians as both participants and targets. Much of the nation’s critical infrastructure, which includes energy grids, hospitals, transportation, and communication systems, is owned and operated by private entities. As a result, the civilian industries and experts are becoming central to both cyber defence and offence.
During the Russia–Ukraine War, the volunteer hackers from around the world were many of whom are being coordinated through the app Telegram, which is termed as ‘IT Army of Ukraine’, are known for conducting digital strikes on Russian networks. Conversely, the Russia-affiliated hacker groups like Conti had vowed to retaliate against any nations that supported Ukraine.
This civilian participation raises profound legal and moral questions, over a private company’s role in defending their networks of becoming a combatant, or the impact of retaliatory cyberattacks on civilian infrastructure war crimes. International law has yet to provide a clear answer, which can leave dangerous gaps in the governance to counter cybercrimes.
Susceptibility of Contemporary Society to Cyber Warfare
Cyberwarfare can impact an entire global digital ecosystem due to its interconnectedness. Power grids, hospitals, air traffic systems, and even automation devices can be compromised. While the NotPetya ransomware, which was cloaked as ransomware, caused billions of losses and caused worldwide economic damage from shipping companies to pharmaceutical companies, the WannaCry ransomware attacks in 2017 paralysed hospitals throughout the UK's National Health Service.
When taken as a whole, these incidents have also shown that cyberattacks are no longer limited to espionage situations and can have real-world consequences comparable to those of conventional warfare. The consequences of cyberattacks could increase dramatically as our dependence on technology increases. Because these effects are profoundly psychological in nature and seek to sow fear, mistrust, and social disintegration, they are not merely technical or economic in nature.
The Future: Permanent Cyber Frontlines
Technological developments have made cyberspace a permanent theatre of conflict, joining the land, sea, air, and space. Countries are currently making significant investments in cyber capabilities for deterrence as well as defence. According to security experts like Eriksson and Giacomello, societies are now inherently fragile due to our increasing reliance on information technologies.
Cyber operations in this context are about strategic dominance in a globalised world, not just digital espionage. Who controls the networks and algorithms that run contemporary civilisation will determine the future of war, not just who controls the skies or the seas. As per the new reality, before the drop of the first bomb, a silent war in cyberspace will already be underway.
References
- https://digitalfrontlines.io/2023/05/25/the-evolution-of-cyber-operations-in-armed-conflict/
- https://theses.ubn.ru.nl/server/api/core/bitstreams/9d74149e-fb9a-402f-aa65-a90445ad7603/content
- https://cybersecurityguide.org/resources/cyberwarfare/
- https://re.public.polimi.it/retrieve/e0c31c0b-ce6c-4599-e053-1705fe0aef77/21%20Century%20Cyber%20Warfare.pdf

Introduction
Picture every paper trade document, such as bills of lading, certificates of origin, letters of credit, and packing lists, stacked one on top of another. By one industry estimate, the roughly four billion such documents in circulation each year would form a tower over 500 kilometres high, well past the edge of space. This absurd image reflects a simple truth, global trade has relied on paper for centuries, making transactions slow, expensive, and vulnerable to loss, forgery, and disputes.
Today, however, we complete many activities that once depended on paper through digital platforms. We open bank accounts through mobile applications, sign contracts electronically, file taxes online, and access government services through websites, all without handling a single physical document. Global trade is now undergoing a similar transformation. Yet, as trade moves online, the challenge is no longer managing stacks of paper, but protecting digital trade from cyber threats. The success of this transition will therefore depend as much on robust cybersecurity as on the adoption of digital technologies.
From Paper Trails to Platforms
For decades, an Indian exporter clearing a container needed physical stamps from customs, port authorities, banks, and multiple regulatory agencies, each on its own timeline. That has been changing under India's National Trade Facilitation Action Plan, now in its third iteration (NTFAP 3.0, 2024–27), which set out to close the remaining gaps in paperless trading systems. The shift shows up in international benchmarks: India's score on the UN's Global Survey on Digital and Sustainable Trade Facilitation has climbed sharply, with the institutional-cooperation component alone improving from under 67% to nearly 89% in recent rounds. A 2026 policy brief jointly released by ICRIER, RIS, and the Centre for WTO Studies concludes that India has achieved full implementation of domestic paperless trade measures, a rare distinction globally even as cross-border digitalisation continues to deepen.
The Building Blocks: ICEGATE to BharatTradeNet
This transformation rests on a stack of interlocking platforms. ICEGATE, the customs electronic data-interchange gateway, lets traders file declarations digitally rather than in person. SWIFT, the Single Window Interface for Facilitating Trade, connects multiple regulatory agencies so a trader deals with one portal instead of dozens. e-SANCHIT digitises supporting documents for customs clearance, cutting paperwork once attached to every consignment. Faceless assessment, rolled out under the CBIC's "Turant Customs" push, separates the assessing officer from the physical location of the goods, reducing scope for delay and discretion. The newest addition, BharatTradeNet, announced in the Union Budget 2025-26, is unified digital public infrastructure linking DGFT, GSTN, banks, shipping lines, and exporters on one platform for trade documentation and financing built to complement the Unified Logistics Interface Platform and align with international conventions.
None of this works without a legal backbone. India's proposed Trade Facilitation Bill aims to give electronic trade documents the same legal standing as paper ones, closing an interoperability gap that has long complicated cross-border recognition of digital records. Recent trade agreements have also begun embedding firmer commitments on paperless trade, a sign that digitalisation is no longer a back-office IT project but a live item in trade diplomacy.
What's at Stake Economically
The economic case is straightforward: paper costs money and time. Digitised customs and documentation shrink dwell times at ports, cut transaction costs, and reduce the discretion-driven delays that disproportionately hurt smaller firms. That matters for India's MSMEs, whose export contribution has grown from roughly ₹3.95 lakh crore to ₹12.39 lakh crore in recent years, aided by platforms such as the Government e-Marketplace and ONDC, which together have onboarded well over a million sellers. Electronics exports touched a record $47 billion in 2025, helped along by production-linked incentives and smoother compliance. With India's total merchandise exports crossing $714 billion in the first ten months of FY 2025-26, the efficiency gains from digitalisation compound across an ever-larger base and help Indian firms plug into global value chains that increasingly expect real-time, verifiable documentation rather than faxed certificates.
India's Regional Moment
Beyond its own backyard, India has regional aspirations. Following deliberations at the Asia-Pacific Trade Facilitation Forum and Paperless Trade Week 2026 in Bangkok last May, international experts were of the opinion that most of the necessary digital and regulatory infrastructure for India to join the UN Framework Agreement on Facilitation of Cross-Border Paperless Trade in Asia and the Pacific (CPTA – a treaty-based and intended to make paperless trade globally, not just internationally, interoperable) had been laid in place. Joining CPTA will also allow India to have a say on digital trade frameworks in the region and thus be a game-changer in integrating SAARC, ASEAN and global supply chains together while reducing costs of trade.
The Cybersecurity Imperative
The catch is that every portal, system and API that takes the place of a paper stamp has the potential to become an attack vector. The increase in overall ransomware activity reached more than 50% worldwide in 2025, and supply-chain attacks almost doubled. These types of attacks hit manufacturing, now a key part of India's export basket, hardest of all industrial ransomware attacks.
The notorious NotPetya attack in 2017, which effectively brought Maersk's worldwide shipping operations to a halt and shut down container movement at Mumbai's Jawaharlal Nehru Port, serves as a painful reminder that the compromise of even a single system can bring physical cargo movement within a network to a standstill.
For a trade ecosystem running on digital trust, the nature of risks include: ransomware that immobilizes ports and customs systems, supply-chain attacks that leverage a single trusted service provider to get access to dozens of downstream clients, data theft revealing shipment and financial data, impostor fraud to trick people into assuming the identity of a banks or exporter, modification of digital bills of lading, certificates of origin or other essential trade documents. When an original physical document is misplaced, it has no effect on anyone but its keeper. A corrupted digital file, on the other hand, can be stealthily changed and propagate across every system it touches instantly.
Building Trust by Design
It is a prerequisite to digital commerce to have these systems so they can even be trusted. This means a zero-trust architecture where all users and devices are authenticated rather than just assumed to be safe once you cross an organisational boundary; transport-level encryption; digital signatures & PKI for crypto-validating shipping documents; identity & access controls ensuring access to shipment data is limited to authorised persons; and anomaly detection to alert on intrusions before the problems can snowball. India's legal & policy framework for cybersecurity is indeed evolving, with the Digital Personal Data Protection Act, 2023 (and its rules finalised Jan 2025) obligating data fiduciaries & stipulating breaches must be reported within 6 hours to CERT-In; the National Cyber Security Reference Framework provides a foundational blueprint for digital public infrastructure, all under the stewardship of the National Critical Information Infrastructure Protection Centre, which monitors systems vital for the functioning of commerce.
Conclusion
India's digitised trade infrastructure from ICEGATE and SWIFT to e-SANCHIT, BharatTradeNet, and faceless customs has effectively brought it into the running for the title of regional digital trade leader. However, the success of this transformation will ultimately be measured not by the number of digital platforms it deploys, but by the trust, security, and resilience of the ecosystem that supports them. As trade becomes increasingly digital, robust cybersecurity will remain the foundation for protecting commercial data, maintaining confidence among trading partners, and ensuring that India's digital trade ambitions translate into sustainable economic growth.
Sources
- Cyble — Ransomware Attacks and Supply Chain Threats in 2025
- Chambers and Partners — Cybersecurity 2026: India
- Drishti IAS — Key Cyberthreats India is Facing and Key Measures India has Adopted to Strengthen Cybersecurity
- Protium — MSME Export Contribution Has Grown from ₹3.95 Lakh Crore to ₹12.39 Lakh Crore
- IBEF — India's E-commerce Boom: Growth, Trends & Future Prospects
- News on Air — India Achieves Record Electronics Exports of $47 Billion in 2025

Executive Summary:
BrazenBamboo’s DEEPDATA malware represents a new wave of advanced cyber espionage tools, exploiting a zero-day vulnerability in Fortinet FortiClient to extract VPN credentials and sensitive data through fileless malware techniques and secure C2 communications. With its modular design, DEEPDATA targets browsers, messaging apps, and password stores, while leveraging reflective DLL injection and encrypted DNS to evade detection. Cross-platform compatibility with tools like DEEPPOST and LightSpy highlights a coordinated development effort, enhancing its espionage capabilities. To mitigate such threats, organizations must enforce network segmentation, deploy advanced monitoring tools, patch vulnerabilities promptly, and implement robust endpoint protection. Vendors are urged to adopt security-by-design practices and incentivize vulnerability reporting, as vigilance and proactive planning are critical to combating this sophisticated threat landscape.
Introduction
The increased use of zero-day vulnerabilities by more complex threat actors reinforces the importance of more developed countermeasures. One of the threat actors identified is BrazenBamboo uses a zero-day vulnerability in Fortinet FortiClient for Windows through the DEEPDATA advanced malware framework. This research explores technical details about DEEPDATA, the tricks used in its operations, and its other effects.
Technical Findings
1. Vulnerability Exploitation Mechanism
The vulnerability in Fortinet’s FortiClient lies in its failure to securely handle sensitive information in memory. DEEPDATA capitalises on this flaw via a specialised plugin, which:
- Accesses the VPN client’s process memory.
- Extracts unencrypted VPN credentials from memory, bypassing typical security protections.
- Transfers credentials to a remote C2 server via encrypted communication channels.
2. Modular Architecture
DEEPDATA exhibits a highly modular design, with its core components comprising:
- Loader Module (data.dll): Decrypts and executes other payloads.
- Orchestrator Module (frame.dll): Manages the execution of multiple plugins.
- FortiClient Plugin: Specifically designed to target Fortinet’s VPN client.
Each plugin operates independently, allowing flexibility in attack strategies depending on the target system.
3. Command-and-Control (C2) Communication
DEEPDATA establishes secure channels to its C2 infrastructure using WebSocket and HTTPS protocols, enabling stealthy exfiltration of harvested data. Technical analysis of network traffic revealed:
- Dynamic IP switching for C2 servers to evade detection.
- Use of Domain Fronting, hiding C2 communication within legitimate HTTPS traffic.
- Time-based communication intervals to minimise anomalies in network behavior.
4. Advanced Credential Harvesting Techniques
Beyond VPN credentials, DEEPDATA is capable of:
- Dumping password stores from popular browsers, such as Chrome, Firefox, and Edge.
- Extracting application-level credentials from messaging apps like WhatsApp, Telegram, and Skype.
- Intercepting credentials stored in local databases used by apps like KeePass and Microsoft Outlook.
5. Persistence Mechanisms
To maintain long-term access, DEEPDATA employs sophisticated persistence techniques:
- Registry-based persistence: Modifies Windows registry keys to reload itself upon system reboot.
- DLL Hijacking: Substitutes legitimate DLLs with malicious ones to execute during normal application operations.
- Scheduled Tasks and Services: Configures scheduled tasks to periodically execute the malware, ensuring continuous operation even if detected and partially removed.
Additional Tools in BrazenBamboo’s Arsenal
1. DEEPPOST
A complementary tool used for data exfiltration, DEEPPOST facilitates the transfer of sensitive files, including system logs, captured credentials, and recorded user activities, to remote endpoints.
2. LightSpy Variants
- The Windows variant includes a lightweight installer that downloads orchestrators and plugins, expanding espionage capabilities across platforms.
- Shellcode-based execution ensures that LightSpy’s payload operates entirely in memory, minimising artifacts on the disk.
3. Cross-Platform Overlaps
BrazenBamboo’s shared codebase across DEEPDATA, DEEPPOST, and LightSpy points to a centralised development effort, possibly linked to a Digital Quartermaster framework. This shared ecosystem enhances their ability to operate efficiently across macOS, iOS, and Windows systems.
Notable Attack Techniques
1. Memory Injection and Data Extraction
Using Reflective DLL Injection, DEEPDATA injects itself into legitimate processes, avoiding detection by traditional antivirus solutions.
- Memory Scraping: Captures credentials and sensitive information in real-time.
- Volatile Data Extraction: Extracts transient data that only exists in memory during specific application states.
2. Fileless Malware Techniques
DEEPDATA leverages fileless infection methods, where its payload operates exclusively in memory, leaving minimal traces on the system. This complicates post-incident forensic investigations.
3. Network Layer Evasion
By utilising encrypted DNS queries and certificate pinning, DEEPDATA ensures that network-level defenses like intrusion detection systems (IDS) and firewalls are ineffective in blocking its communications.
Recommendations
1. For Organisations
- Apply Network Segmentation: Isolate VPN servers from critical assets.
- Enhance Monitoring Tools: Deploy behavioral analysis tools that detect anomalous processes and memory scraping activities.
- Regularly Update and Patch Software: Although Fortinet has yet to patch this vulnerability, organisations must remain vigilant and apply fixes as soon as they are released.
2. For Security Teams
- Harden Endpoint Protections: Implement tools like Memory Integrity Protection to prevent unauthorised memory access.
- Use Network Sandboxing: Monitor and analyse outgoing network traffic for unusual behaviors.
- Threat Hunting: Proactively search for indicators of compromise (IOCs) such as unauthorised DLLs (data.dll, frame.dll) or C2 communications over non-standard intervals.
3. For Vendors
- Implement Security by Design: Adopt advanced memory protection mechanisms to prevent credential leakage.
- Bug Bounty Programs: Encourage researchers to report vulnerabilities, accelerating patch development.
Conclusion
DEEPDATA is a form of cyber espionage and represents the next generation of tools that are more advanced and tunned for stealth, modularity and persistence. While Brazen Bamboo is in the process of fine-tuning its strategies, the organisations and vendors have to be more careful and be ready to respond to these tricks. The continuous updating, the ability to detect the threats and a proper plan on how to deal with incidents are crucial in combating the attacks.