#FactCheck- Old Bangladesh Clip Misused as West Bengal Election Incident
Research Wing
Innovation and Research
PUBLISHED ON
Apr 21, 2026
10
Executive Summary
A video showing two men attempting to break into a house, only to be confronted by armed personnel who force them to kneel, is being widely shared on social media in the context of the upcoming West Bengal Assembly elections. The clip is being circulated with claims that it shows Central Reserve Police Force personnel intervening after workers of the Trinamool Congress allegedly tried to intimidate locals. However, an research by the CyberPeace Research Wing found that the claim is false. The viral video has no connection to India or the West Bengal elections and is being shared with a misleading narrative.
Claim
A Facebook user named Devashish Ajitkumar Bhattacharya shared the video on April 20, 2026, with the caption suggesting that TMC workers attempted to threaten people but were stopped by CRPF personnel deployed in West Bengal.
To verify the claim, we extracted keyframes from the viral video and conducted a reverse image search. This led us to the same video uploaded on August 17, 2024, on the official YouTube channel of Bangladeshi news outlet Dhaka Post. The details accompanying the video confirmed that the incident took place in Bangladesh.
Further research led us to a report published on August 17, 2024, by 24 Hours Khobor, which stated that the incident occurred in Faridpur, Bangladesh. According to the report, a clash broke out between two groups, following which the army intervened and arrested two individuals identified as Tutul Hossain and Dukhu Mia. Both were later sent to jail by a court.
Conclusion
The viral claim linking the video to the West Bengal Assembly elections is false. The footage does not show any incident involving CRPF personnel or political workers in India. Instead, it is from an unrelated घटना in Bangladesh that took place in 2024. The video has been taken out of context and is being circulated with a misleading narrative to create confusion around the ongoing election environment.
A recent addition to the list of cybercrime is SharpRhino, a RAT (Remote Access Trojan) actively used by Hunters International ransomware group. SharpRhino is highly developed and penetrates into the network mask of IT specialists, primarily due to the belief in the tools’ legitimacy. Going under the genuine software installer, SharpRhino started functioning in mid-June 2024. However, Quorum Cyber discovered it in early August 2024 while investigating ransomware.
About Hunters International Group:
Hunters International emerged as one of the most notorious groups focused on ransomware attacks, having compromised over 134 targets worldwide in the first seven months of 2024. It is believed that the group is the rebranding of Hive ransomware group that was previously active, and there are considerable similarities in the code. Its focus on IT employees in particular demonstrates the fact that they move tactically in gaining access to the organizations’ networks.
Modus Operandi:
1. Typosquatting Technique
SharpRhino is mainly distributed by a domain that looks like the genuine Angry IP Scanner, which is a popular network discovery tool. The malware installer, labeled as ipscan-3.9.1-setup. It is a 32-bit Nullsoft installer which embeds a password protected 7z archive in it.
2. Installation Process
Execution of Installer: When the victim downloads and executes the installer and changes the windows registry in order to attain persistence. This is done by generating a registry entry that starts a harmful file, Microsoft. AnyKey. exe, are fakes originating from fake versions of true legitimate Microsoft Visual Studio tools.
Creation of Batch File: This drops a batch file qualified as LogUpdate at the installer.bat, that runs the PowerShell scripts on the device. These scripts are to compile C# code into memory to serve as a means of making the malware covert in its operation.
Directory Creation: The installer establishes two directories that allow the C2 communication – C:\ProgramData\Microsoft: WindowsUpdater24 and LogUpdateWindows.
3. Execution and Functionality:
Command Execution: The malware can execute PowerShell commands on the infected system, these actions may involve privilege escalation and other extended actions such as lateral movement.
C2 Communication: SharpRhino interacts with command and control servers located on domains from platforms such as Cloudflare. This communication is necessary for receiving commands from the attackers and for returning any data of interest to the attackers.
Data Exfiltration and Ransomware Deployment: Once SharpRhino has gained control, it can steal information and then proceed to encrypt it with a .locked extension. The procedure generally concludes with a ransom message, which informs users on how to purchase the decryption key.
4. Propagation Techniques:
Also, SharpRhino can spread through the self-copying method, this is the virus may copy itself to other computers using the network account of the victim and pretending to be trustworthy senders such as emails or network-shared files. Moreover, the victim’s machine may then proceed to propagate the malware to other systems like sharing in the company with other employees.
Indicators of Compromise (IOCs):
LogUpdate.bat
Wiaphoh7um.t
ipscan-3.9.1-setup.exe
kautix2aeX.t
WindowsUpdate.bat
Command and Control Servers:
cdn-server-1.xiren77418.workers.dev
cdn-server-2.wesoc40288.workers.dev
Angryipo.org
Angryipsca.com
Analysis:
Graph:
Precautionary measures to be taken:
To mitigate the risks posed by SharpRhino and similar malware, organizations should implement the following measures:
Implement Security Best Practices: It is important only to download software from official sites and avoid similar sites to confuse the user by changing a few letters.
Enhance Detection Capabilities: Use technology in detection that can detect the IOCs linked to Sharp Rhino.
Educate Employees: Educate IT people and employees on phishing scams and the requirement to check the origin of the application.
Regular Backups: It is also important to back up important files from systems and networks in order to minimize the effects of ransomware attacks on a business.
Conclusion:
SharpRhino could be deemed as the evolution of the strategies used by organizations like Hunters International and others involved in the distribution of ransomware. SharpRhino primarily focuses on the audience of IT professionals and employs complex delivery and execution schemes, which makes it an extremely serious threat for corporate networks. To do so it is imperative that organizations have an understanding of its inner workings in order to fortify their security measures against this relatively new threat. Through the enforcement of proper security measures and constant enlightenment of organizations on the importance of cybersecurity, firms can prevent the various risks associated with SharpRhino and related malware. Be safe, be knowledgeable, and most importantly, be secure when it comes to cyber security for your investments.
Amid renewed military tensions between Iran and Israel in West Asia, a video is widely circulating on social media showing a multi-storey building being struck, followed by a massive explosion and fire. Several users are sharing this clip with the claim that it shows a recent Iranian attack on Tel Aviv, Israel. However, CyberPeace Research Wing research found that the claim is misleading. The viral video has no connection to the current Iran–Israel conflict. It is actually from a Russian drone strike in Ukraine that took place in September 2025, and is now being falsely linked to the ongoing tensions in West Asia.
Claim
An Instagram user shared the viral video with the caption:“Iran–Israel tensions at peak, reports of retaliatory action towards Tel Aviv… New wave of Iranian response towards Tel Aviv amid escalating tensions between Iran and Israel. The situation in the region continues to intensify as both sides accuse each other, while the international community closely monitors developments. The Middle East situation is rapidly evolving and updates are emerging. It is important to rely only on official information and credible sources.”
To verify the authenticity of the video, we extracted keyframes and conducted a Google Lens reverse image search. The same footage was found in a report published by The Guardian on 16 September 2025.
According to the report, the video shows a Russian drone strike on a building in Kharkiv, Ukraine, in which three men and one woman were injured.
Further verification through keyword search led us to the same footage on the official YouTube channel of Associated Press, published on 17 September 2025.
The Associated Press also confirmed that the video shows a Russian drone strike on a building in Kharkiv, Ukraine.
Conclusion
Our research found that the viral video has no connection to the ongoing Iran–Israel tensions or any attack on Tel Aviv. The footage is from a Russian drone strike in Kharkiv, Ukraine (September 2025), and is being misleadingly shared in the context of the West Asia conflict.
Following the official launch of E85 petrol in India on June 5, 2026, several videos have surfaced on social media claiming unusual side effects of ethanol-blended fuel. One such viral clip alleges that a swarm of bees gathers on a motorcycle fuel tank due to the use of ethanol mixed petrol. CyberPeace Research Wing research found the claim to be false and misleading. The viral video has been identified as AI-generated and does not depict any real-world incident related to ethanol-blended fuel.
Claim:
An X user shared an 11-second video on June 13, 2026, claiming that bees are being attracted to vehicles using ethanol-blended petrol. The post sarcastically suggested that E20 fuel is causing such unusual effects and questioned the impact of E85 petrol. https://x.com/khan_tahkeek/status/2065751435451437185?s=20, https://archive.ph/bMsL7
Fact Check:
A Google search using relevant keywords did not return any credible media reports supporting the claim, raising initial doubts about its authenticity. Closer inspection of the viral video revealed multiple visual inconsistencies suggesting digital manipulation. The video was further analysed using AI detection tools. Hive Moderation flagged the content as having a 98% probability of being AI-generated, indicating strong likelihood of synthetic creation.
In addition, analysis using the AI detection tool “WasItAI” also confirmed that the video is AI-generated.
Further verification found an official post by Bharat Petroleum Corporation Limited (BPCL) dated June 17, 2026, debunking similar misinformation circulating around ethanol-blended petrol https://x.com/BPCLimited/status/2067167037710020929?s=20
Conclusion:
The research confirms that the viral video showing bees swarming on a motorcycle fuel tank is AI-generated. The claim linking it to ethanol-blended petrol (E85/E20) is false and misleading, with no real-world basis.
Become a part of our vision to make the digital world safe for all!
Numerous avenues exist for individuals to unite with us and our collaborators in fostering global cyber security
Awareness
Stay Informed: Elevate Your Awareness with Our Latest Events and News Articles Promoting Cyber Peace and Security.
Your institution or organization can partner with us in any one of our initiatives or policy research activities and complement the region-specific resources and talent we need.