AnyDesk Fraud Network Busted: UP ATS Exposes Multi-District Illegal ID Update Scam

www.news4hackers.com-anydesk-fraud-network-busted-up-ats-exposes-multi-district-illegal-id-update-scam-anydesk-fraud-network-busted-up-ats-exposes-multi-district-illegal-id-update-scam

The Uttar Pradesh Anti-Terrorism Squad (ATS) has dismantled a coordinated cybercriminal operation leveraging remote access tools and dormant administrative credentials to alter official identification records across multiple districts.

Unauthorized Access via Dormant Credentials and Remote Tools

Investigations reveal that the network exploited inactive operator accounts linked to terminated third-party contracts with financial institutions. These credentials, left unmanaged in administrative systems, were repurposed to bypass security protocols. A former Assistant Regional Project Manager with a private firm, Vivek Tripathi, allegedly collaborated with technical experts to revive these accounts using software cloning techniques and authentication bypass scripts. The group utilized commercial remote access platforms, primarily AnyDesk, to execute unauthorized modifications without physical presence at authorized enrollment sites. This method enabled operators to circumvent geolocation and physical verification requirements, granting remote access to administrative portals from unverified locations.

Cross-District Operations and Financial Infrastructure

Forensic examinations of seized devices uncovered extensive communication records, including AnyDesk connection keys, login schedules, and digital payment confirmations. Investigators also recovered structured spreadsheets detailing operator identities, system credentials, remote access parameters, and timestamps of completed transactions. All illicit funds were funneled through digital payment systems, including Unified Payments Interface (UPI) handles and dynamic QR code scanners. Law enforcement is tracing associated bank accounts to quantify financial gains and identify additional participants. Intelligence suggests the network operated across multiple districts, including Chitrakoot, Ayodhya, Sultanpur, and the Varanasi region, indicating a coordinated, multi-jurisdictional effort.

Mitigation Measures and Cybersecurity Recommendations

While tools like AnyDesk are designed for legitimate remote support, their misuse poses significant risks to data integrity and national infrastructure. Authorities have launched cross-verification audits to identify compromised entries in centralized databases. A cybersecurity advisory urges citizens to use only verified government enrollment centers for biometric and demographic updates. The ATS has emphasized strict protocols against sharing one-time passwords, personal identification numbers, or biometric data with unverified parties. The investigation remains ongoing, with further legal actions anticipated as forensic analyses conclude.



About Author

en_USEnglish