PrintSteal : Exposing unauthorized CSC-Impersonating Websites Engaging in Large-Scale KYC Document Generation Fraud
ID: f480b875-c2bf-5069-b7bb-d6ca1fd10606
STIX ID: report--f480b875-c2bf-5069-b7bb-d6ca1fd10606
Feed Name: CloudSEK Blog
This CloudSEK investigation details a large-scale criminal operation, “PrintSteal,” that has generated over 160,000 fraudulent Indian KYC documents through a network of ~600 active fraudulent domains (1,800+ identified historically), affiliates (2,700+ operators on crrsg.site), illicit APIs, deceptive QR verification, and shared hosting; the report includes technical analysis, attribution to an individual (Manish Kumar), IoCs (domains, hosting IP, Telegram handle, email, UPI), impact assessment (financial, reputational, national security), and comprehensive takedown and prevention recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
