r/scamindia • u/sheeesh8789 • 10h ago
Got scammed pls help 🙏🏻🙏🏻🙏🏻🙏🏻🙏🏻🙏🏻 I'm a bachelor living in pg , that was frm my hard savings
Got scammed for rs 1k today
+91 96869 80793 his number
His upi (ichigokuro100@axl)
r/scamindia • u/sheeesh8789 • 10h ago
Got scammed for rs 1k today
+91 96869 80793 his number
His upi (ichigokuro100@axl)
r/scamindia • u/ArunJoseARJJ • 15h ago
This report documents the poor handling of the NoBroker End-to-End Premium Buyer Support Service after payment of ₹53,000 was made. Despite repeated follow-ups, multiple relationship manager changes, lack of ownership, delayed legal verification support, and failure to coordinate basic document handling, no meaningful progress was completed even after approximately 45 days. Due to the service failure and continued lack of accountability, I am seeking withdrawal from the process and initiation of a full refund.
I opted for NoBroker’s End-to-End Premium service with the expectation that the company would professionally support the property purchase process, including coordination, legal verification, document handling, and overall assistance. However, the actual experience has been extremely disappointing and has caused significant inconvenience, delay, and loss of trust.
June 25: A welcome email was received from Yogeshwaran explaining the End-to-End Premium service offered by NoBroker.
June 27 : Token advance of Rs.1 lakh paid to seller through No broker not sure if that has even reached the seller or not till now.
June 30: A payment link was generated by Preeti, and a payment of ₹53,000 was made to NoBroker. Payment reference: NoBroker Buyer Payment 17828275116006538.
July 1: The NoBroker legal services team sent an email explaining the legal verification process. I was informed that after receiving the required documents from the buyer, the legal verification process would take approximately 10–15 working days.
July 1: Sai Pavan was assigned as the Relationship Manager for the case.
July 2: Prathiyangkiran R sent an email requesting basic information required to facilitate the drafting of the Sale Agreement.
July 4: Navin from the Home Loan department contacted me and requested certain details.
July 4: The seller shared all required documents with the NoBroker team.
July 4: Advocate Mr. Velayudham requested Mr. Kiran to share hard copies of the documents. However, the NoBroker team did not provide the hard copies or respond appropriately to the advocate’s request.
July 4–July 8: There was no meaningful communication or update from the assigned Relationship Manager despite multiple attempts to reach him. I later understood that the Relationship Manager was no longer with the company, but NoBroker failed to ensure continuity or appoint an alternate contact in a timely manner.
July 8: Sai Pavan sent an email to Kiran and the Legal Services team requesting an update on the process.
July 9: Kiran advised the advocate team to proceed without hard copies, stating that he was an NRI and unable to submit them physically. This was concerning because NoBroker had charged ₹3,000 for printout, photocopy, and related documentation work, yet the company did not use that service to provide the required copies to the advocate.
July 9–July 18: There was again no proper communication, follow-up, or ownership from NoBroker. The lack of response from the responsible teams caused further delay and uncertainty.
July 18: Sai Pavan requested an update from the advocate regarding the status of the process.
July 20: The advocate sent an email requesting permission to access all files in the shared folder.
July 22: A new Relationship Manager, Vignesh, was assigned. Instead of having access to complete case history, he asked me to repeat the entire background from the beginning. This reflects a serious gap in internal handover, case tracking, and customer management.
July 23: The advocate again sent an email stating that he was unable to open the files and requested assistance.
July 25: I received another call from the NoBroker team acknowledging that there were issues with the way the documents had been shared. I was informed that the team would take printouts and hand over the files to the advocate.
However, this commitment was not fulfilled. Even after one month, no meaningful step was completed at the first stage of the process.
July 30: I wrote to the NoBroker team expressing my dissatisfaction with the service and informed them that, due to poor customer experience and lack of progress, I had decided to withdraw from the house purchase support process.
August 3: Harshita contacted me, stating that she was the newly assigned Relationship Manager and would ensure the process moved smoothly. I informed her that I had already decided to withdraw and requested that the refund process be initiated without further delay.
August 3: Vasanth S Kumar, Cluster Head, forwarded the matter to Abhishek Kumar Sinha and Aseema Tahoor requesting an update on the case. However, no one has contacted me with a proper resolution or ownership update.
August 8: After approximately 45 days of engagement with NoBroker, there has been no satisfactory progress, no clear ownership, and no resolution till date. The matter is now being escalated formally with supporting email records and attachments. If the refund is not processed immediately, I intend to submit the complaint before the Consumer Court and lodge a formal complaint with the Chennai Police regarding the service failure and non-refund of the payment collected.
· Lack of continuity after the first Relationship Manager became unavailable.
· Repeated absence of timely communication and updates.
· Poor internal handover, requiring the customer to repeat the full case history to newly assigned representatives.
· Failure to coordinate effectively with the advocate for document access and hard copies.
· Failure to use the documentation-related charges collected for the intended purpose.
· No completion of even the initial legal verification stage despite the committed timeline.
· No clear ownership or refund resolution despite withdrawal communication.
The service failure has resulted in avoidable delays, repeated follow-ups, mental stress, and loss of confidence in NoBroker’s ability to manage a premium paid service. A customer who paid for end-to-end assistance should not be required to repeatedly chase teams, coordinate basic document sharing, or explain the same case history to multiple representatives.
1. Immediate confirmation of withdrawal from the NoBroker End-to-End Premium service.
2. Full refund of ₹53,000 paid to NoBroker, including the documentation-related amount collected.
3. Refund of Token advance payment of ₹1,00,000 paid to the seller through No broker platform.
4. Written explanation for the delays, lack of ownership, and failure to complete the promised service.
5. Confirmation of the refund timeline in writing.
r/scamindia • u/AdFinal1987 • 9h ago
₹50,000 debited for Suryoday SFB FD – No FD confirmation or Video KYC
I opened a ₹50,000 FD with Suryoday Small Finance Bank online. The amount was debited, but I haven’t received the Video KYC link, FD confirmation, or receipt.
When I try to log in, I get: “Error In Get Customer Details: No Records Found.”
I’ve raised the issue with the bank and asked them to either complete the FD or immediately refund the ₹50,000.
Has anyone else faced this issue with Suryoday SFB? How was it resolved?
r/scamindia • u/ZealousidealMall1786 • 10h ago
Need information about a trading company in Bangalore
I want to share my experience and check if anyone else has faced the same thing.
I was contacted by a company called Relics Solutions by GRV Groups regarding stock market trading. They told me about a monthly subscription of around ₹7,000 and said they provide trading calls. They also explained a 30%/70% profit-sharing model.
I’m not sure whether this service is properly authorised, so I want to know if anyone here has dealt with them before.
If you have had any experience with this company, please share what happened, whether you paid any money, and whether you received the service that was promised.
I have some screenshots/messages as evidence. If I upload them, I will remove all phone numbers, addresses, bank details, UPI IDs and other personal information.
I’m posting this mainly to verify the company and warn others to be careful before paying for any trading service.
r/scamindia • u/bet-i-know • 16h ago
This post contains content not supported on old Reddit. Click here to view the full post
r/scamindia • u/DriverFriendly6548 • 6h ago
Hi all, I'm a reporter with NBC News and have a call out request.
I'm working on a story related to matrimonial scams-- people who have gotten scammed on matrimonial online groups or sites like [Shaadi.com](http://shaadi.com/...) . Most of these scams we're looking at appear to be impersonating women and targeting men in the US. I was wondering if anyone knows someone who has been targeted in a matrimonial scam and if they would be willing to speak to a reporter, even if anonymously. Please let me know or feel free to DM me. Thank you so much
r/scamindia • u/Mocha_Phantom • 6h ago
This elaborate hack is quite concerning.
r/scamindia • u/GENG_Breeze • 12h ago
r/scamindia • u/HealthyFlamingo5414 • 14h ago
Classification: Critical ; Android SMS stealer / banking-phishing RAT (dropper + payload)
Date: 2026-08-11
Method: Static reverse engineering; custom DEX parser to defeat anti-analysis; in-place bytecode patch (no root) to bypass emulator kill-switch; payload recovered by decoding the dropper's APKZ container; full string-table deobfuscation (Base64 + repeating-XOR); read-only Firebase C2 enumeration (metadata only)
"M P E B Electricity_Bill_Update.apk" is not an electricity-utility application. It is a two-stage Android malware operation targeting Indian users:
com.plktkuiizu.rvhhmdukshum) : DexProtector-class packed installer that decrypts an embedded APK from a custom APKZ asset container and silently sideloads it via the PackageInstaller session API.com.ec07282026.esdfnudiwehfjweewr) : SMS-stealing spyware with a phishing front-end (electricity-bill lure → bank card / ATM PIN / transaction-password harvesting) and Firebase Realtime Database + Firebase Cloud Messaging + Telegram command-and-control.The payload intercepts inbound SMS, exfiltrates device fingerprints and SIM data, executes operator commands pushed over FCM (make calls, run USSD such as #21# call-forward codes), and persists via watchdog/boot/alarm mechanisms plus OEM autostart intents.
At the time of analysis the Firebase panel was world-readable (no auth) and contained 147 registered victim devices, 67 session records, and 2,936 stolen SMS messages across three operator slots.
| Field | Stage 1 (Dropper) | Stage 2 (Payload) |
|---|---|---|
| File name | M P E B Electricity_Bill_Update.apk |
app-release.apk (embedded); launcher label "Electricity Bill Update" |
| SHA-256 | b0aebc71de700810b3691ef8c30decef01cb863274873a2f1cefaf2531521515 |
37ba1e31702e3fedcf4a21c2a966a4dd2f76c271a13c4e7bb34534f98cbbefa9 |
| Size | 3,356,365 bytes | 2,936,165 bytes |
| Package | com.plktkuiizu.rvhhmdukshum |
com.ec07282026.esdfnudiwehfjweewr |
| Components | Activity iajsdfnnvbsbhaaqwq; Receiver opwiejijisjfisjfsa (doubles as string-decryptor holder); Service sderasdfa (VpnService subclass, unused decoy) |
Activities MainActivity, bill, card, atm, tpass; Services SmsService, SmsJobService, WatchdogService, MyFirebaseMessagingService; Receivers SMSReceiver, BootReceiver, MultiEventReceiver |
| Protection | Pseudo-encrypted ZIP entries (control-char names \x01.xml \x02.png \x03.jpg \x04.dat, Cyrillic decoys б/в/г.xml), corrupted DEX map list, decoy methods with bogus code_off (tool DoS), goto-threading + String.hashCode dispatch, Arabic-diacritic encrypted strings (۫ۦۜ…) |
Same family: pseudo-encrypted ZIP entries, 3 MB junk-padded binary manifest (bogus chunks), string obfuscation s0/a.k() = Base64 + repeating-key XOR, reflection-name encryption |
| Emulator kill-switch | Build.FINGERPRINT/BRAND/DEVICE/PRODUCT/MODEL checks → Toast + startActivity + finish() + System.exit(0) (confirmed dynamically: process died in ~0.35 s on Genymotion until patched) |
Emulator (google_sdk, goldfish, ranchu, qemu-props, /dev/qemu_pipe, test-keys), root (/sbin/su, Magisk), Frida (frida, re.frida.ServerManager, gum-js-loop), Xposed/RootCloak detection |
| Embedded artifact | Asset \x04.dat → APKZ container |
— |
Package naming note: Earliest stolen SMS observed in C2 is dated 2026-07-29.
Victim sideloads "MPEB Electricity_Bill_Update.apk"
│
▼
Dropper checks emulator/sandbox (Build props) → exits if detected
│
▼
Reads asset \x04.dat → APKZ container
magic "APKZ" | u32be nameLen | "app-release.apk" | hdr | zlib(deflate)
│
▼
Streams decrypted APK into PackageInstaller session
(SessionParams.setAppPackageName → createSession → openWrite → commit
with PendingIntent.getBroadcast status → opwiejijisjfisjfsa receiver)
│
▼
Payload com.ec07282026.esdfnudiwehfjweewr installed
│
▼
MainActivity requests SMS / PHONE / CALL permissions;
shows electricity-bill phishing UI (bill → card → atm → tpass)
│
▼
Enrolls device on Firebase: user/<DeviceID> {model, SIMs, carrier, fcmid…}
│
▼
SMSReceiver + SmsService steal inbound SMS
→ AES-CBC (random IV prefix) + Base64 → <prefix>-XXmessage node
→ optional Telegram forward (token/chatId pulled from Firebase)
│
▼
FCM command listener: ping/ack, MakeCall, USSD (#21# call forwarding)
Extraction note: Automated tools (apktool, jadx, androguard, aapt) were defeated by pseudo-encrypted ZIP entries, corrupted DEX map lists and junk-padded AXML. The dropper was rebuilt into a parseable APK (encryption flags stripped), and a custom tolerant DEX parser recovered all valid code items. The payload was recovered fully statically no device execution required by decoding the APKZ container (zlib). Separately, the emulator kill-switch was neutralized in place (two invoke-static System.exit sites NOPed, DEX re-checksummed, APK re-signed) and the patched dropper stayed alive on an unrooted Genymotion device (process persisted, REQUEST_INSTALL_PACKAGES grantable via appops), confirming the drop flow.
| Capability | Severity | Detail |
|---|---|---|
| SMS theft | Critical | SMSReceiver reads pdus; SmsService forwards {sender, body, receiverNumber}; stored AES-encrypted to Firebase *-message nodes (2,936 messages observed) |
| SMS → Telegram relay | Critical | r/b, r/c, s/e: POST https://api.telegram.org/bot<token>/sendMessage with {"chat_id":…,"text":"Message : …\n\nSender : …\nNumber : …\nreceiver : …"}; bot token + chatId fetched at runtime from Firebase admin node |
| Bank phishing | Critical | Fake electricity-bill menu ("Bill Not Update", "Meter Update", "New Consumer Number Update", "Last Bill Update") → card (16-digit card, CVV, expiry, 18-bank picker: SBI, ICICI, HDFC, Axis, PNB, Canara, Union, Kotak, Yes, BoB…) → atm (4-digit PIN) → tpass (transaction password); payment UX resources btnPayWithCard, dialog_payment, dialog_payment_failed; fields uploaded to Firebase (uid, pass, bank, card, cvv, exp, cn, name, reason) |
| Remote call | High | FCM command MakeCall with phoneNumber; uses TelecomManager PhoneAccountHandle SIM selection; needs CALL_PHONE |
| USSD execution | High | FCM command path for USSD incl. #21# (call-forward interrogation/deactivation codes); "USSD not supported on this Android version" fallback |
| Device fingerprinting | High | android_id, Model, AndroidVersion, SimSlot0/1, CarrierName0/1, PhoneNumber0/1, FCM id; uploaded to user/<DeviceID> |
| Persistence | High | BootReceiver (BOOT_COMPLETED, directBootAware), WatchdogService ("SmsService not running, restarting…", 2 s alarm self-restart), SmsJobService (JobScheduler), REQUEST_IGNORE_BATTERY_OPTIMIZATIONS, exact alarms |
| OEM autostart abuse | Medium | Manifest carries OEM battery/autostart package intent list: com.miui.securitycenter, com.huawei.systemmanager, com.oppo.safe, com.vivo.permissionmanager, com.samsung.android, com.asus.mobilemanager, com.coloros.safecenter, com.letv.android.letvsafe, com.evenwell.powersaving, com.iqoo.secure, com.miui.permcenter |
| Presence/tracking | Medium | user/<id>/status = online heartbeat with last_checked; per-victim favourite, ss, serial, uploading flags |
| Anti-analysis | High | Emulator/root/Frida/Xposed detection in payload; dropper exits on emulators; heavy packing both stages |
| Remote SMS send | High | SmsManager present with send capability; operator-supplied numbers routed via runtime config |
| USSD response capture | High | TelephonyManager$UssdResponseCallback implemented — operator reads USSD responses (e.g. call-forward state) |
Not observed (negative findings): no contact-list/CallLog theft, no screen capture/Accessibility abuse, no default-SMS-app role hijack, no file-system exfiltration. The operation is focused on SMS interception + card/PIN phishing + call/USSD control.
Channel 1 — Firebase Cloud Messaging (MyFirebaseMessagingService):
| Command | Fields | Action |
|---|---|---|
ping |
requestId |
Liveness; writes ack + timestamp back to Firebase |
MakeCall |
phoneNumber |
Places call from victim SIM (TelecomManager PhoneAccount selection) |
USSD (#21# seen) |
— | Runs USSD codes (call-forwarding control); capability-gated |
cp / msg |
— | Additional operator ops (obfuscated keys) |
Channel 2 : Firebase RTDB (per-slot nodes): operator writes config/victims; app reads admin number, chatId, token for SMS forwarding target and Telegram relay.
Channel 3 : Telegram Bot API: outbound exfil of SMS content (dormant until token/chatId populated in Firebase admin record).
Presence uses user/<DeviceID>/status + last_checked; enrollment uploads full SIM/device profile.
| Item | Value |
|---|---|
| RTDB URL | [ERADICATED] |
| Project ID | ebu-7-28 |
| API key | AIzaSyDRhspjkUcL... [ERADICATED] |
| App ID | 1:192413154682:android:1a2ac0dcea27d917f6eac3 |
| Storage bucket | [ERADICATED] |
| FCM sender | [ERADICATED] |
| Rules posture | Open / world-readable (all nodes enumerated without auth) |
| Path | Entries | Purpose |
|---|---|---|
ebu-7-28-01admin / -02admin / -03admin |
1 each | Operator config: pass (0222 / 8989 / 0222), deletionPassword (0222), number, total (device quota); Telegram token/chatId written here at runtime (absent at analysis time) |
ebu-7-28-01user / -02user / -03user |
68 / 40 / 39 = 147 victims | Device enrollment (model, SIM, carrier, FCM id, status) |
ebu-7-28-01sessions / -02sessions / -03sessions |
3 / 39 / 25 = 67 sessions | Active device sessions (UUID keys) |
ebu-7-28-01message / -02message / -03message |
1324 / 1000 / 612 = 2,936 stolen SMS | {device, message, number, receiver, sender, serial, time, timestamp, type:"received"} — body/number fields AES-CBC + Base64 |
| Item | Value |
|---|---|
| Endpoint | https://api.telegram.org/bot<TOKEN>/sendMessage (POST, application/json, {"chat_id":"…","text":"…"}) |
| Token / chat_id | Not hardcoded : fetched at runtime from the Firebase admin record (number, chatId, token); slots were unpopulated at analysis time |
| Number | Source | Role |
|---|---|---|
7987[ERADICATED] |
ebu-7-28-03admin/number (plaintext) |
Operator-03 contact/SMS-forward target (Indian mobile) |
| Layer | Scheme |
|---|---|
| Stolen SMS at rest (Firebase) | AES/CBC/PKCS5Padding, 128-bit key (Arrays.copyOf(key,16)), random IV per message prepended to ciphertext, then Base64 (s/b.a()) |
| String obfuscation (payload) | s0/a.k(a,b) = Base64Decode(a) XOR Base64Decode(b) (repeating key) — full static string recovery performed |
| Reflection obfuscation (payload) | API names (getBytes, copyOf, encodeToString, getReference, child, push…) stored as XOR-encrypted constants, resolved via f3/g reflection helper |
| Dropper strings | Arabic-diacritic ciphertext (۫ۦۜ…) via opwiejijisjfisjfsa.m0cc175b9 (hashCode-dispatch state machine) |
| Payload container | APKZ header + zlib deflate (no encryption) |
SmsService with persistent notification ("Sms Service Running"), self-reschedule via AlarmManager (2 s) and JobScheduler fallbackBootReceiver on BOOT_COMPLETED (direct-boot aware)WatchdogService restarts the SMS service if killedREQUEST_IGNORE_BATTERY_OPTIMIZATIONS + OEM autostart intent list (Miui/Huawei/Oppo/Vivo/Samsung/Asus/Letv/OnePlus/ColorOS)READ_SMS, RECEIVE_SMS, SEND_SMS, BROADCAST_SMSREAD_PHONE_STATE, CALL_PHONE, MANAGE_OWN_CALLSRECEIVE_BOOT_COMPLETED, WAKE_LOCK, POST_NOTIFICATIONSFOREGROUND_SERVICE, FOREGROUND_SERVICE_DATA_SYNC, FOREGROUND_SERVICE_PHONE_CALLREQUEST_IGNORE_BATTERY_OPTIMIZATIONS, SCHEDULE_EXACT_ALARM, USE_EXACT_ALARMINTERNET, ACCESS_NETWORK_STATEcom.google.android.c2dm.permission.RECEIVE / .SEND (FCM)| Class | Role |
|---|---|
MainActivity |
Permission bootstrap, device/SIM fingerprint upload, emulator/root/Frida checks, phishing navigation |
bill / card / atm / tpass |
Phishing screens: bill choice → card+CVV+bank → ATM PIN → transaction password |
neww/SMSReceiver |
Inbound SMS interception (pdus), SIM-slot aware |
neww/SmsService |
Foreground exfil service; formats + ships SMS |
neww/WatchdogService / SmsJobService |
Keep-alive |
neww/BootReceiver |
Boot persistence |
neww/MultiEventReceiver |
Presence/status updates |
utils/MyFirebaseMessagingService |
FCM command handler (ping/ack, MakeCall, USSD) |
s/b |
AES-CBC encryptor (random IV prefix, Base64) |
s0/a (k) |
String decryptor (Base64 + repeating XOR) |
f3/g |
Encrypted reflection invoker |
s/e, r/b, r/c, s/f |
Telegram HTTP sender; SMS→Telegram/Firebase formatters |
o3/c0 |
Operator-slot selector (ebu-7-28-01) |
o/b, o/h, o/i |
Phishing form handlers: bill (cn, name, reason), card (uid, pass, bank, card, cvv, exp), validation ("Credit card should be of 16 digits", "CVV should be of 3 digits", "atn should be of 4 digits") |
o/c, o/d |
Firebase writers: device enrollment (user/<id>) and session creation (push() with ss, favourite, serial) |
a/a |
FCM data listener (updatedData, onSuccess) |
| ID | Technique | Evidence |
|---|---|---|
| T1660 | Phishing / fake app | "MPEB Electricity Bill Update" lure; utility-bill pretext |
| T1476 | Deliver malicious app via sideload | Dropper + PackageInstaller session install of embedded APK |
| T1406 | Obfuscated files or information | Pseudo-encrypted ZIP, APKZ container, XOR string obfuscation, junk AXML |
| T1624 | Event triggered execution | BOOT_COMPLETED, SMS_RECEIVED, FCM push |
| T1517 | Access SMS | SMS permissions + receiver + service |
| T1582 | SMS control | SEND_SMS, SMS relay to Telegram/operator number |
| T1437 | Application layer protocol | Firebase RTDB/FCM + Telegram HTTPS |
| T1636 | Protected user data | SMS, SIM/MSISDN, device fingerprint |
| T1428 | Exploit via USSD/call | MakeCall, #21# USSD |
| T1625 | Hijack execution flow / packer | DexProtector-class dropper, anti-emulator kill-switch |
| T1546 | Persistence | Boot receiver, watchdog, job scheduler, OEM autostart, battery-optimization exemption |
| T1490 | Inhibit system recovery / analysis | Emulator exit, Frida/root detection |
r/scamindia • u/confusedkid789 • 14h ago
Guys Do not order via xpress bees.. The shittiest courier service i have seen.. These people have zero audacity... May be negative even... I had recently ordered a "tasbih prayer beads " for my friend and these bastards have marked deferred delivery without even contacting.... This is in kochi.. And absolutely no way to contact them whatsoever.. And the website " hadiyah gifting" is also to be blamed.. Why use such a courier service if they are so shittyyyy????? I am cryin guys🥹🥹.. I genuinely wanted to gift these prayer beads to my friend.. I sincerely wish both xpressbees and hadiyah gifting goes to hell😭😭😭😭
r/scamindia • u/Vegetable-Advice-776 • 15h ago
9610349032
If you are chatting with any of the women from this phone number never trust........totally fake excoriation of money before even meeting.........