#FactCheck - Fake Video Uses AI Voice to Falsely Attribute Remarks on Prasidh Krishna to Virat Kohli
A video circulating widely on social media claims that Indian cricketer Virat Kohli made a sarcastic remark about fast bowler Prasidh Krishna ahead of the New Zealand series. In the clip, Kohli is allegedly heard saying that he expected to be the top scorer of the series, but lost all hope after seeing Prasidh Krishna’s name in the squad.
Users sharing the video claim that Kohli publicly commented on Prasidh Krishna in this manner.
Research by the CyberPeace Foundation has found the viral claim to be false. Our probe revealed that the viral clip has been digitally manipulated. The video is originally from a 2024 advertisement featuring Virat Kohli, in which his voice has been altered using deepfake (AI-generated) technology and falsely presented with a misleading narrative.
Claim
The video was shared on Instagram on January 6, 2025, with users claiming that Kohli made the remark after the New Zealand squad was announced. The post included the altered audio suggesting Kohli’s disappointment over Prasidh Krishna’s selection. Link, archive link

Fact Check:
To verify the claim, we extracted key frames from the viral video and conducted a Google Reverse Image Search. This led us to the original video posted by Virat Kohli himself on X (formerly Twitter) on April 15, 2024. The original clip was part of a brand advertisement, and no such statement about the New Zealand series or Prasidh Krishna was made in it. Link and Screenshot

A close review of the viral clip raised suspicions due to the unnatural tone and inconsistencies in Kohli’s voice. To confirm this, we analysed the video using the AI detection tool Aurigin AI. The tool’s results showed that the audio in the viral clip is 100 percent AI-generated, confirming that Kohli’s voice was artificially manipulated.

Conclusion
The CyberPeace Foundation’s research confirms that the viral video claiming Virat Kohli mocked Prasidh Krishna is fake and misleading. The clip is taken from an old advertisement and has been doctored using deepfake technology to alter Kohli’s voice. The video is being circulated on social media with a false claim, and Virat Kohli has made no such statement regarding the New Zealand series or Prasidh Krishna.
Related Blogs

Executive Summary
Amid rising petrol and diesel prices in India, an old video statement by Baba Ramdev is being widely shared on social media. In the viral clip, Ramdev can be heard saying that if the government permits him to open petrol pumps, he can provide petrol and diesel across the country at Rs 35-40 per litre. He is also heard suggesting that petrol and diesel should be brought under the lowest GST slab. However, CyberPeace Research Wing research found the viral claim to be misleading. The research revealed that Baba Ramdev made the statement during a private news channel event in 2018 and has not made any such recent remark.
Claim
A Facebook user named “Aman Singh Bathla” shared the old video of Baba Ramdev on May 26, 2026, and wrote:
“I can provide petrol and diesel to the entire country at Rs 35-40 if the Modi government allows me to open petrol pumps!”
- https://www.facebook.com/reel/2215528532606679
- https://www.facebook.com/reel/2215528532606679
- https://perma.cc/LA4L-3KCK

Fact Check
To verify the claim, we closely examined the viral video and noticed the logo of NDTV in the clip. Based on this clue, we searched NDTV’s official YouTube channel using relevant keywords and found the original video uploaded on September 16, 2018. In the full video, Baba Ramdev is seen making the viral statement during the NDTV Youth Conclave. During the discussion, the anchor had asked him a question regarding rising fuel prices, and Ramdev responded with the now-viral remarks in that context.

During further searches, we also found reports about the same statement on the website of Oneindia dated September 17, 2018. The report quoted Ramdev as saying that if the government allowed him to set up petrol pumps and offered some tax relief, he could provide fuel at Rs 35-40 per litre. He also suggested bringing petroleum products under GST, preferably in the 5 to 12 percent slab, to provide relief to consumers.

Our research confirmed that Baba Ramdev’s viral statement dates back to 2018 and has no connection with the recent rise in fuel prices.
Conclusion
The viral post was found to be misleading. Baba Ramdev made the statement in September 2018 during a private news channel event. His old remarks are now being circulated out of context to create confusion over the current fuel price situation.
.webp)
Introduction
Recently in July 2026, India's Cyber Crime Coordination Centre (I4C) under the Ministry of Home Affairs quietly tried to do something almost no government has managed before: switch off an app that doesn't need the internet to work. On July 23, 2026, I4C sent takedown notices to Google, Apple and GitHub, ordering them to pull three offline messaging apps – like BitChat, Briar and Bridgefy – from the Play Store, App Store and GitHub's code repository, respectively, giving a three-hour deadline. The notices followed a period of student-led demonstrations at Jantar Mantar, New Delhi, associated with a group "Cockroach Janata Party," a period that also saw a mobile internet shutdown in parts of central Delhi. When Twitter co-founder Jack Dorsey, who built and open-sourced BitChat, publicised the GitHub notice on X, the episode made international news. Google and Apple got near-identical orders the same night, and telecom operators were reportedly told, and then just as quickly untold, to block the apps at the network level. By July 29, all three apps were still live on both app stores, and BitChat's code was still on GitHub. This incident is worth unpacking carefully, because it sits at the intersection of three things most people care about but rarely see explained together: how this technology actually works, what the law actually allows, and why an app can be "banned" on paper while still working perfectly on your phone.
What makes these apps different
Ordinary apps like WhatsApp or Telegram are centralised: your message travels from your phone to a company's server, and then to the recipient's phone. Block or seize the server, and communication stops. BitChat, Briar and Bridgefy are built differently. They use Bluetooth mesh networking, a system where nearby phones talk directly to each other, and each device also relays messages onwards to phones further away, like a bucket brigade. No message ever touches a central server. Briar adds a further layer by routing traffic over Tor, an anonymity network, when internet access is available, and falls back to Bluetooth or Wi-Fi Direct when it isn't. Bridgefy is tuned for larger crowds, useful during concerts, natural disasters, or protests where thousands of phones are packed into a small area and cellular networks buckle under the load. This design, often called decentralised or peer-to-peer communication, is precisely why these apps are useful during disasters and precisely why they worry law enforcement: they keep working when the internet doesn't, whether that's because a cyclone knocked out cell towers or because the government itself ordered a shutdown.
The legal machinery behind a takedown notice
India's power to block online content mainly comes from Section 69A of the Information Technology Act, 2000, which lets the central government order blocking on grounds like sovereignty, public order or preventing incitement to an offence but only through a defined process set out in the IT (Blocking) Rules, 2009: a designated officer, a review committee, and recorded written reasons. The Supreme Court examined this exact provision in its landmark 2015 ruling, Shreya Singhal v. Union of India. While the judgement is best remembered for striking down the vague "offensive speech" law under Section 66A, it separately upheld Section 69A specifically because it came with procedural guardrails, a reasoned order, an opportunity to be heard, and the possibility of judicial review that stopped it from becoming an unchecked censorship tool. The July 23 notices, however, reportedly leaned on a different lever: Section 79(3)(b) of the IT Act, read with Rule 3(1)(d) of the IT Intermediary Guidelines and Digital Media Ethics Code Rules, 2021. That provision governs when an intermediary loses its legal immunity ("safe harbour") for user content if it fails to act on a government or court order, a mechanism built for content takedowns, not necessarily for pulling an entire app off a store shelf within three hours. Legal commentators have flagged this as significant, since Shreya Singhal itself read down Section 79(3)(b) to require action only pursuant to a court order or a properly authorised government direction, not an informal notice. This isn't the first time a mesh-messaging app has run into this machinery. In 2023, following an I4C request, the government blocked Briar and thirteen other apps in Jammu and Kashmir under Section 69A, citing use, the first known instance of Section 69A being used for a regional block. Briar's developers challenged this in the Delhi High Court; in 2024, the court dismissed the challenge, holding that principles of natural justice can give way in matters of national security.
Why you can't easily switch off a mesh network
Here's the technical wrinkle that made the July order largely symbolic: removing an app from the Play Store stops new downloads, but it does nothing to phones that already have it installed, and it does nothing at all to the Bluetooth radios exchanging messages between those phones. Unlike an internet shutdown, which works by controlling the pipes that all traffic must pass through, a mesh network has no chokepoint, no server to seize, no IP address to blacklist, and no single company to compel.
GitHub, for its part, said it followed its standard process of notifying the account holder and offering an appeal before taking any action, which is one reason BitChat's source code stayed publicly accessible throughout. Within a day, officials reportedly told the companies orally that enforcement wasn't necessary after all, though no public clarification or official document has been released explaining why the notices were issued or withdrawn.
Two legitimate, competing interests
None of this means the government's underlying worry is baseless. Law enforcement agencies genuinely lose visibility when communication moves off networks they can lawfully intercept, and coordination of unlawful assembly or violence is a real concern during volatile protests.
The transparency gap
The single biggest problem with how this played out isn't the underlying concern it's the absence of a public, reasoned order. Under the blocking rules, disclosure is restricted, and courts, including the Supreme Court in Anuradha Bhasin v. Union of India, have said that when access is restricted, reasons must be recorded and, where possible, made available. A three-hour notice, issued and then informally withdrawn without explanation, sits uneasily with that standard. A more durable approach, one that CyberPeace and other digital-rights researchers have called for, would combine clearly identified statutory authority; published (even if redacted) reasoning; proportionality review; and investment in lawful digital forensics, rather than blanket app-store takedowns that decentralised technology is, by design, built to survive.
CyberPeace's policy recommendations
Alongside the legal analysis above, CyberPeace puts forward a ten-point framework for how India should approach decentralised communication technologies going forward, instead of defaulting to blanket takedowns:
- Strengthen transparency in blocking decisions
- Ensure statutory clarity
- Apply legality, necessity and proportionality
- Differentiate technology from misuse
- Invest in advanced investigative capabilities
- Establish a multi-stakeholder advisory mechanism
- Develop a framework for emerging decentralised technologies
- Promote responsible innovation
- Enhance public awareness
- Foster international cooperation
Conclusion
The referred incident illustrates that regulating decentralised technologies requires more than swift takedown notices. As communication networks become increasingly resilient and distributed, effective governance must combine legal certainty, technical realism, transparency, and proportionate enforcement. India's challenge is not simply to regulate emerging technologies but to develop a kind of regulatory framework that safeguards national security and the constitutional values of privacy, free expression, and due process.
Sources
- MediaNama — Bitchat was not the only mesh-messaging app targeted by a government takedown notice
- Outlook Business — Beyond GitHub, Govt Also Directed Google To Take Down Bitchat, Briar And Bridgefy
- The Wire — Government Asks GitHub to Remove Bluetooth Messaging App Bitchat Over Concerns of 'Misuse'
- The Tech Trace (Substack) — The Indian govt's crackdown on Bluetooth-enabled messaging apps that wasn't?
- Bar and Bench — Section 69A IT Act and the expanding architecture of digital censorship in India
- Supreme Court Observer — X relies on 'Shreya Singhal' in arbitrary content-blocking case in Karnataka HC
- LiveLaw — Internet Freedom, Shreya Singhal v Union of India, IT Act, Blocking Rules 2009
- Manupatra — Full text, Shreya Singhal v. Union of India (2015) 5 SCC 1
- Open Magazine — CJP Protests at Jantar Mantar: How Offline Mesh Messaging Apps Powered a Network of Resistance

Overview:
A recent addition to the list of cybercrime is SharpRhino, a RAT (Remote Access Trojan) actively used by Hunters International ransomware group. SharpRhino is highly developed and penetrates into the network mask of IT specialists, primarily due to the belief in the tools’ legitimacy. Going under the genuine software installer, SharpRhino started functioning in mid-June 2024. However, Quorum Cyber discovered it in early August 2024 while investigating ransomware.
About Hunters International Group:
Hunters International emerged as one of the most notorious groups focused on ransomware attacks, having compromised over 134 targets worldwide in the first seven months of 2024. It is believed that the group is the rebranding of Hive ransomware group that was previously active, and there are considerable similarities in the code. Its focus on IT employees in particular demonstrates the fact that they move tactically in gaining access to the organizations’ networks.
Modus Operandi:
1. Typosquatting Technique
SharpRhino is mainly distributed by a domain that looks like the genuine Angry IP Scanner, which is a popular network discovery tool. The malware installer, labeled as ipscan-3.9.1-setup. It is a 32-bit Nullsoft installer which embeds a password protected 7z archive in it.
2. Installation Process
- Execution of Installer: When the victim downloads and executes the installer and changes the windows registry in order to attain persistence. This is done by generating a registry entry that starts a harmful file, Microsoft. AnyKey. exe, are fakes originating from fake versions of true legitimate Microsoft Visual Studio tools.
- Creation of Batch File: This drops a batch file qualified as LogUpdate at the installer.bat, that runs the PowerShell scripts on the device. These scripts are to compile C# code into memory to serve as a means of making the malware covert in its operation.
- Directory Creation: The installer establishes two directories that allow the C2 communication – C:\ProgramData\Microsoft: WindowsUpdater24 and LogUpdateWindows.
3. Execution and Functionality:
- Command Execution: The malware can execute PowerShell commands on the infected system, these actions may involve privilege escalation and other extended actions such as lateral movement.
- C2 Communication: SharpRhino interacts with command and control servers located on domains from platforms such as Cloudflare. This communication is necessary for receiving commands from the attackers and for returning any data of interest to the attackers.
- Data Exfiltration and Ransomware Deployment: Once SharpRhino has gained control, it can steal information and then proceed to encrypt it with a .locked extension. The procedure generally concludes with a ransom message, which informs users on how to purchase the decryption key.
4. Propagation Techniques:
Also, SharpRhino can spread through the self-copying method, this is the virus may copy itself to other computers using the network account of the victim and pretending to be trustworthy senders such as emails or network-shared files. Moreover, the victim’s machine may then proceed to propagate the malware to other systems like sharing in the company with other employees.
Indicators of Compromise (IOCs):
- LogUpdate.bat
- Wiaphoh7um.t
- ipscan-3.9.1-setup.exe
- kautix2aeX.t
- WindowsUpdate.bat
Command and Control Servers:
- cdn-server-1.xiren77418.workers.dev
- cdn-server-2.wesoc40288.workers.dev
- Angryipo.org
- Angryipsca.com
Analysis:

Graph:

Precautionary measures to be taken:
To mitigate the risks posed by SharpRhino and similar malware, organizations should implement the following measures:
- Implement Security Best Practices: It is important only to download software from official sites and avoid similar sites to confuse the user by changing a few letters.
- Enhance Detection Capabilities: Use technology in detection that can detect the IOCs linked to Sharp Rhino.
- Educate Employees: Educate IT people and employees on phishing scams and the requirement to check the origin of the application.
- Regular Backups: It is also important to back up important files from systems and networks in order to minimize the effects of ransomware attacks on a business.
Conclusion:
SharpRhino could be deemed as the evolution of the strategies used by organizations like Hunters International and others involved in the distribution of ransomware. SharpRhino primarily focuses on the audience of IT professionals and employs complex delivery and execution schemes, which makes it an extremely serious threat for corporate networks. To do so it is imperative that organizations have an understanding of its inner workings in order to fortify their security measures against this relatively new threat. Through the enforcement of proper security measures and constant enlightenment of organizations on the importance of cybersecurity, firms can prevent the various risks associated with SharpRhino and related malware. Be safe, be knowledgeable, and most importantly, be secure when it comes to cyber security for your investments.
Reference:
https://cybersecuritynews.com/sharprhino-ransomware-alert/
https://cybersecsentinel.com/sharprhino-explained-key-facts-and-how-to-protect-your-data/
https://www.dataprivacyandsecurityinsider.com/2024/08/sharprhino-malware-targeting-it-professionals/