PrintSteal : Exposing unauthorized CSC-Impersonating Websites Engaging in Large-Scale KYC Document Generation Fraud
ID: 05c84146-7c88-5172-b93b-19e19d41c292
STIX ID: report--05c84146-7c88-5172-b93b-19e19d41c292
Feed Name: CloudSEK Blog
This report exposes the PrintSteal criminal enterprise (case study: crrsg.site) that has generated over 167,000 fake Indian KYC documents since 2021 via a network of ~2,700 operators and 1,800+ domains (600+ active). The operation leverages pre-built PHP admin panels, illicit APIs for Aadhaar/PAN data, deceptive QR-code verification pages, affiliate distribution through local shops and Telegram, and shared hosting; the investigation provides technical details, IOCs (domain, IP 157.90.176.32, email, phone, Telegram handles), attribution to 'Manish Kumar', estimated revenue (≈₹40 lakh for crrsg.site), impacts, and a set of law enforcement, technical, and policy recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
