logo

PrintSteal : Exposing unauthorized CSC-Impersonating Websites Engaging in Large-Scale KYC Document Generation Fraud

ID: 05c84146-7c88-5172-b93b-19e19d41c292

STIX ID: report--05c84146-7c88-5172-b93b-19e19d41c292

Feed Name: CloudSEK Blog

Threat Score
78/100

Date Published: 2025-03-05

Date Updated: 2026-04-27

...
...

This report exposes the PrintSteal criminal enterprise (case study: crrsg.site) that has generated over 167,000 fake Indian KYC documents since 2021 via a network of ~2,700 operators and 1,800+ domains (600+ active). The operation leverages pre-built PHP admin panels, illicit APIs for Aadhaar/PAN data, deceptive QR-code verification pages, affiliate distribution through local shops and Telegram, and shared hosting; the investigation provides technical details, IOCs (domain, IP 157.90.176.32, email, phone, Telegram handles), attribution to 'Manish Kumar', estimated revenue (≈₹40 lakh for crrsg.site), impacts, and a set of law enforcement, technical, and policy recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.