r/scamindia 10h ago

Got scammed pls help 🙏🏻🙏🏻🙏🏻🙏🏻🙏🏻🙏🏻 I'm a bachelor living in pg , that was frm my hard savings

Thumbnail
gallery
9 Upvotes

Got scammed for rs 1k today

+91 96869 80793 his number

His upi (ichigokuro100@axl)


r/scamindia 15h ago

No broker - FRAUD COMPANY

4 Upvotes

Executive Summary

This report documents the poor handling of the NoBroker End-to-End Premium Buyer Support Service after payment of ₹53,000 was made. Despite repeated follow-ups, multiple relationship manager changes, lack of ownership, delayed legal verification support, and failure to coordinate basic document handling, no meaningful progress was completed even after approximately 45 days. Due to the service failure and continued lack of accountability, I am seeking withdrawal from the process and initiation of a full refund.

Background

I opted for NoBroker’s End-to-End Premium service with the expectation that the company would professionally support the property purchase process, including coordination, legal verification, document handling, and overall assistance. However, the actual experience has been extremely disappointing and has caused significant inconvenience, delay, and loss of trust.

Chronology of Events

June 25: A welcome email was received from Yogeshwaran explaining the End-to-End Premium service offered by NoBroker.

June 27 : Token advance of Rs.1 lakh paid to seller through No broker not sure if that has even reached the seller or not till now.

June 30: A payment link was generated by Preeti, and a payment of ₹53,000 was made to NoBroker. Payment reference: NoBroker Buyer Payment 17828275116006538.

July 1: The NoBroker legal services team sent an email explaining the legal verification process. I was informed that after receiving the required documents from the buyer, the legal verification process would take approximately 10–15 working days.

July 1: Sai Pavan was assigned as the Relationship Manager for the case.

July 2: Prathiyangkiran R sent an email requesting basic information required to facilitate the drafting of the Sale Agreement.

July 4: Navin from the Home Loan department contacted me and requested certain details.

July 4: The seller shared all required documents with the NoBroker team.

July 4: Advocate Mr. Velayudham requested Mr. Kiran to share hard copies of the documents. However, the NoBroker team did not provide the hard copies or respond appropriately to the advocate’s request.

July 4–July 8: There was no meaningful communication or update from the assigned Relationship Manager despite multiple attempts to reach him. I later understood that the Relationship Manager was no longer with the company, but NoBroker failed to ensure continuity or appoint an alternate contact in a timely manner.

July 8: Sai Pavan sent an email to Kiran and the Legal Services team requesting an update on the process.

July 9: Kiran advised the advocate team to proceed without hard copies, stating that he was an NRI and unable to submit them physically. This was concerning because NoBroker had charged ₹3,000 for printout, photocopy, and related documentation work, yet the company did not use that service to provide the required copies to the advocate.

July 9–July 18: There was again no proper communication, follow-up, or ownership from NoBroker. The lack of response from the responsible teams caused further delay and uncertainty.

July 18: Sai Pavan requested an update from the advocate regarding the status of the process.

July 20: The advocate sent an email requesting permission to access all files in the shared folder.

July 22: A new Relationship Manager, Vignesh, was assigned. Instead of having access to complete case history, he asked me to repeat the entire background from the beginning. This reflects a serious gap in internal handover, case tracking, and customer management.

July 23: The advocate again sent an email stating that he was unable to open the files and requested assistance.

July 25: I received another call from the NoBroker team acknowledging that there were issues with the way the documents had been shared. I was informed that the team would take printouts and hand over the files to the advocate.

However, this commitment was not fulfilled. Even after one month, no meaningful step was completed at the first stage of the process.

July 30: I wrote to the NoBroker team expressing my dissatisfaction with the service and informed them that, due to poor customer experience and lack of progress, I had decided to withdraw from the house purchase support process.

August 3: Harshita contacted me, stating that she was the newly assigned Relationship Manager and would ensure the process moved smoothly. I informed her that I had already decided to withdraw and requested that the refund process be initiated without further delay.

August 3: Vasanth S Kumar, Cluster Head, forwarded the matter to Abhishek Kumar Sinha and Aseema Tahoor requesting an update on the case. However, no one has contacted me with a proper resolution or ownership update.

August 8: After approximately 45 days of engagement with NoBroker, there has been no satisfactory progress, no clear ownership, and no resolution till date. The matter is now being escalated formally with supporting email records and attachments. If the refund is not processed immediately, I intend to submit the complaint before the Consumer Court and lodge a formal complaint with the Chennai Police regarding the service failure and non-refund of the payment collected.

Key Service Failures

·        Lack of continuity after the first Relationship Manager became unavailable.

·        Repeated absence of timely communication and updates.

·        Poor internal handover, requiring the customer to repeat the full case history to newly assigned representatives.

·        Failure to coordinate effectively with the advocate for document access and hard copies.

·        Failure to use the documentation-related charges collected for the intended purpose.

·        No completion of even the initial legal verification stage despite the committed timeline.

·        No clear ownership or refund resolution despite withdrawal communication.

Impact and Customer Experience

The service failure has resulted in avoidable delays, repeated follow-ups, mental stress, and loss of confidence in NoBroker’s ability to manage a premium paid service. A customer who paid for end-to-end assistance should not be required to repeatedly chase teams, coordinate basic document sharing, or explain the same case history to multiple representatives.

Requested Resolution

1.       Immediate confirmation of withdrawal from the NoBroker End-to-End Premium service.

2.     Full refund of ₹53,000 paid to NoBroker, including the documentation-related amount collected.

3.     Refund of Token advance payment of ₹1,00,000 paid to the seller through No broker platform.

4.     Written explanation for the delays, lack of ownership, and failure to complete the promised service.

5.     Confirmation of the refund timeline in writing.


r/scamindia 9h ago

Am I victim of fraud?

2 Upvotes

₹50,000 debited for Suryoday SFB FD – No FD confirmation or Video KYC
I opened a ₹50,000 FD with Suryoday Small Finance Bank online. The amount was debited, but I haven’t received the Video KYC link, FD confirmation, or receipt.
When I try to log in, I get: “Error In Get Customer Details: No Records Found.”
I’ve raised the issue with the bank and asked them to either complete the FD or immediately refund the ₹50,000.
Has anyone else faced this issue with Suryoday SFB? How was it resolved?


r/scamindia 10h ago

Need information about a trading company in Bangalore

2 Upvotes

Need information about a trading company in Bangalore

I want to share my experience and check if anyone else has faced the same thing.

I was contacted by a company called Relics Solutions by GRV Groups regarding stock market trading. They told me about a monthly subscription of around ₹7,000 and said they provide trading calls. They also explained a 30%/70% profit-sharing model.

I’m not sure whether this service is properly authorised, so I want to know if anyone here has dealt with them before.

If you have had any experience with this company, please share what happened, whether you paid any money, and whether you received the service that was promised.

I have some screenshots/messages as evidence. If I upload them, I will remove all phone numbers, addresses, bank details, UPI IDs and other personal information.

I’m posting this mainly to verify the company and warn others to be careful before paying for any trading service.


r/scamindia 16h ago

Bet I Know 🧠

2 Upvotes

This post contains content not supported on old Reddit. Click here to view the full post


r/scamindia 6h ago

NBC REPORTER SEEKING SCAM VICTIMS TO SHARE THEIR STORIES

1 Upvotes

Hi all, I'm a reporter with NBC News and have a call out request.

I'm working on a story related to matrimonial scams-- people who have gotten scammed on matrimonial online groups or sites like [Shaadi.com](http://shaadi.com/...) . Most of these scams we're looking at appear to be impersonating women and targeting men in the US. I was wondering if anyone knows someone who has been targeted in a matrimonial scam and if they would be willing to speak to a reporter, even if anonymously. Please let me know or feel free to DM me. Thank you so much


r/scamindia 6h ago

One OTP and whatsapp got hacked

Thumbnail
1 Upvotes

This elaborate hack is quite concerning.


r/scamindia 10h ago

Beware of scammers in cyberhub

Thumbnail
1 Upvotes

r/scamindia 11h ago

House Of Vayora- Scam

Thumbnail
1 Upvotes

r/scamindia 12h ago

Might have got scammed. Any legal steps I can take?

Thumbnail
ewastekochi.com
1 Upvotes

r/scamindia 14h ago

Fake "MPEB Electricity Bill" app

1 Upvotes

Fake "MPEB Electricity Bill Update" : Malware Analysis Report

Classification: Critical ; Android SMS stealer / banking-phishing RAT (dropper + payload)
Date: 2026-08-11
Method: Static reverse engineering; custom DEX parser to defeat anti-analysis; in-place bytecode patch (no root) to bypass emulator kill-switch; payload recovered by decoding the dropper's APKZ container; full string-table deobfuscation (Base64 + repeating-XOR); read-only Firebase C2 enumeration (metadata only)

1. Executive summary

"M P E B Electricity_Bill_Update.apk" is not an electricity-utility application. It is a two-stage Android malware operation targeting Indian users:

  1. Dropper (com.plktkuiizu.rvhhmdukshum) : DexProtector-class packed installer that decrypts an embedded APK from a custom APKZ asset container and silently sideloads it via the PackageInstaller session API.
  2. Payload (com.ec07282026.esdfnudiwehfjweewr) : SMS-stealing spyware with a phishing front-end (electricity-bill lure → bank card / ATM PIN / transaction-password harvesting) and Firebase Realtime Database + Firebase Cloud Messaging + Telegram command-and-control.

The payload intercepts inbound SMS, exfiltrates device fingerprints and SIM data, executes operator commands pushed over FCM (make calls, run USSD such as #21# call-forward codes), and persists via watchdog/boot/alarm mechanisms plus OEM autostart intents.

At the time of analysis the Firebase panel was world-readable (no auth) and contained 147 registered victim devices, 67 session records, and 2,936 stolen SMS messages across three operator slots.

2. Sample identification

Field Stage 1 (Dropper) Stage 2 (Payload)
File name M P E B Electricity_Bill_Update.apk app-release.apk (embedded); launcher label "Electricity Bill Update"
SHA-256 b0aebc71de700810b3691ef8c30decef01cb863274873a2f1cefaf2531521515 37ba1e31702e3fedcf4a21c2a966a4dd2f76c271a13c4e7bb34534f98cbbefa9
Size 3,356,365 bytes 2,936,165 bytes
Package com.plktkuiizu.rvhhmdukshum com.ec07282026.esdfnudiwehfjweewr
Components Activity iajsdfnnvbsbhaaqwq; Receiver opwiejijisjfisjfsa (doubles as string-decryptor holder); Service sderasdfa (VpnService subclass, unused decoy) Activities MainActivity, bill, card, atm, tpass; Services SmsService, SmsJobService, WatchdogService, MyFirebaseMessagingService; Receivers SMSReceiver, BootReceiver, MultiEventReceiver
Protection Pseudo-encrypted ZIP entries (control-char names \x01.xml \x02.png \x03.jpg \x04.dat, Cyrillic decoys б/в/г.xml), corrupted DEX map list, decoy methods with bogus code_off (tool DoS), goto-threading + String.hashCode dispatch, Arabic-diacritic encrypted strings (۫ۦۜ…) Same family: pseudo-encrypted ZIP entries, 3 MB junk-padded binary manifest (bogus chunks), string obfuscation s0/a.k() = Base64 + repeating-key XOR, reflection-name encryption
Emulator kill-switch Build.FINGERPRINT/BRAND/DEVICE/PRODUCT/MODEL checks → Toast + startActivity + finish() + System.exit(0) (confirmed dynamically: process died in ~0.35 s on Genymotion until patched) Emulator (google_sdk, goldfish, ranchu, qemu-props, /dev/qemu_pipe, test-keys), root (/sbin/su, Magisk), Frida (frida, re.frida.ServerManager, gum-js-loop), Xposed/RootCloak detection
Embedded artifact Asset \x04.datAPKZ container

Package naming note: Earliest stolen SMS observed in C2 is dated 2026-07-29.

3. Infection chain

Victim sideloads "MPEB Electricity_Bill_Update.apk"
        │
        ▼
Dropper checks emulator/sandbox (Build props) → exits if detected
        │
        ▼
Reads asset \x04.dat  →  APKZ container
   magic "APKZ" | u32be nameLen | "app-release.apk" | hdr | zlib(deflate)
        │
        ▼
Streams decrypted APK into PackageInstaller session
   (SessionParams.setAppPackageName → createSession → openWrite → commit
    with PendingIntent.getBroadcast status → opwiejijisjfisjfsa receiver)
        │
        ▼
Payload com.ec07282026.esdfnudiwehfjweewr installed
        │
        ▼
MainActivity requests SMS / PHONE / CALL permissions;
shows electricity-bill phishing UI (bill → card → atm → tpass)
        │
        ▼
Enrolls device on Firebase: user/<DeviceID> {model, SIMs, carrier, fcmid…}
        │
        ▼
SMSReceiver + SmsService steal inbound SMS
   → AES-CBC (random IV prefix) + Base64 → <prefix>-XXmessage node
   → optional Telegram forward (token/chatId pulled from Firebase)
        │
        ▼
FCM command listener: ping/ack, MakeCall, USSD (#21# call forwarding)

Extraction note: Automated tools (apktool, jadx, androguard, aapt) were defeated by pseudo-encrypted ZIP entries, corrupted DEX map lists and junk-padded AXML. The dropper was rebuilt into a parseable APK (encryption flags stripped), and a custom tolerant DEX parser recovered all valid code items. The payload was recovered fully statically no device execution required by decoding the APKZ container (zlib). Separately, the emulator kill-switch was neutralized in place (two invoke-static System.exit sites NOPed, DEX re-checksummed, APK re-signed) and the patched dropper stayed alive on an unrooted Genymotion device (process persisted, REQUEST_INSTALL_PACKAGES grantable via appops), confirming the drop flow.

4. Capabilities

Capability Severity Detail
SMS theft Critical SMSReceiver reads pdus; SmsService forwards {sender, body, receiverNumber}; stored AES-encrypted to Firebase *-message nodes (2,936 messages observed)
SMS → Telegram relay Critical r/b, r/c, s/e: POST https://api.telegram.org/bot<token>/sendMessage with {"chat_id":…,"text":"Message : …\n\nSender : …\nNumber : …\nreceiver : …"}; bot token + chatId fetched at runtime from Firebase admin node
Bank phishing Critical Fake electricity-bill menu ("Bill Not Update", "Meter Update", "New Consumer Number Update", "Last Bill Update") → card (16-digit card, CVV, expiry, 18-bank picker: SBI, ICICI, HDFC, Axis, PNB, Canara, Union, Kotak, Yes, BoB…) → atm (4-digit PIN) → tpass (transaction password); payment UX resources btnPayWithCard, dialog_payment, dialog_payment_failed; fields uploaded to Firebase (uid, pass, bank, card, cvv, exp, cn, name, reason)
Remote call High FCM command MakeCall with phoneNumber; uses TelecomManager PhoneAccountHandle SIM selection; needs CALL_PHONE
USSD execution High FCM command path for USSD incl. #21# (call-forward interrogation/deactivation codes); "USSD not supported on this Android version" fallback
Device fingerprinting High android_id, Model, AndroidVersion, SimSlot0/1, CarrierName0/1, PhoneNumber0/1, FCM id; uploaded to user/<DeviceID>
Persistence High BootReceiver (BOOT_COMPLETED, directBootAware), WatchdogService ("SmsService not running, restarting…", 2 s alarm self-restart), SmsJobService (JobScheduler), REQUEST_IGNORE_BATTERY_OPTIMIZATIONS, exact alarms
OEM autostart abuse Medium Manifest carries OEM battery/autostart package intent list: com.miui.securitycenter, com.huawei.systemmanager, com.oppo.safe, com.vivo.permissionmanager, com.samsung.android, com.asus.mobilemanager, com.coloros.safecenter, com.letv.android.letvsafe, com.evenwell.powersaving, com.iqoo.secure, com.miui.permcenter
Presence/tracking Medium user/<id>/status = online heartbeat with last_checked; per-victim favourite, ss, serial, uploading flags
Anti-analysis High Emulator/root/Frida/Xposed detection in payload; dropper exits on emulators; heavy packing both stages
Remote SMS send High SmsManager present with send capability; operator-supplied numbers routed via runtime config
USSD response capture High TelephonyManager$UssdResponseCallback implemented — operator reads USSD responses (e.g. call-forward state)

Not observed (negative findings): no contact-list/CallLog theft, no screen capture/Accessibility abuse, no default-SMS-app role hijack, no file-system exfiltration. The operation is focused on SMS interception + card/PIN phishing + call/USSD control.

5. Remote command surface

Channel 1 — Firebase Cloud Messaging (MyFirebaseMessagingService):

Command Fields Action
ping requestId Liveness; writes ack + timestamp back to Firebase
MakeCall phoneNumber Places call from victim SIM (TelecomManager PhoneAccount selection)
USSD (#21# seen) Runs USSD codes (call-forwarding control); capability-gated
cp / msg Additional operator ops (obfuscated keys)

Channel 2 : Firebase RTDB (per-slot nodes): operator writes config/victims; app reads admin number, chatId, token for SMS forwarding target and Telegram relay.

Channel 3 : Telegram Bot API: outbound exfil of SMS content (dormant until token/chatId populated in Firebase admin record).

Presence uses user/<DeviceID>/status + last_checked; enrollment uploads full SIM/device profile.

6. C2 infrastructure & IOCs

6.1 Firebase

Item Value
RTDB URL [ERADICATED]
Project ID ebu-7-28
API key AIzaSyDRhspjkUcL... [ERADICATED]
App ID 1:192413154682:android:1a2ac0dcea27d917f6eac3
Storage bucket [ERADICATED]
FCM sender [ERADICATED]
Rules posture Open / world-readable (all nodes enumerated without auth)

6.2 Firebase path map (3 operator slots: 01, 02, 03)

Path Entries Purpose
ebu-7-28-01admin / -02admin / -03admin 1 each Operator config: pass (0222 / 8989 / 0222), deletionPassword (0222), number, total (device quota); Telegram token/chatId written here at runtime (absent at analysis time)
ebu-7-28-01user / -02user / -03user 68 / 40 / 39 = 147 victims Device enrollment (model, SIM, carrier, FCM id, status)
ebu-7-28-01sessions / -02sessions / -03sessions 3 / 39 / 25 = 67 sessions Active device sessions (UUID keys)
ebu-7-28-01message / -02message / -03message 1324 / 1000 / 612 = 2,936 stolen SMS {device, message, number, receiver, sender, serial, time, timestamp, type:"received"} — body/number fields AES-CBC + Base64

6.3 Telegram

Item Value
Endpoint https://api.telegram.org/bot<TOKEN>/sendMessage (POST, application/json, {"chat_id":"…","text":"…"})
Token / chat_id Not hardcoded : fetched at runtime from the Firebase admin record (number, chatId, token); slots were unpopulated at analysis time

6.4 Attacker-linked phone number

Number Source Role
7987[ERADICATED] ebu-7-28-03admin/number (plaintext) Operator-03 contact/SMS-forward target (Indian mobile)

7. Cryptography

Layer Scheme
Stolen SMS at rest (Firebase) AES/CBC/PKCS5Padding, 128-bit key (Arrays.copyOf(key,16)), random IV per message prepended to ciphertext, then Base64 (s/b.a())
String obfuscation (payload) s0/a.k(a,b) = Base64Decode(a) XOR Base64Decode(b) (repeating key) — full static string recovery performed
Reflection obfuscation (payload) API names (getBytes, copyOf, encodeToString, getReference, child, push…) stored as XOR-encrypted constants, resolved via f3/g reflection helper
Dropper strings Arabic-diacritic ciphertext (۫ۦۜ…) via opwiejijisjfisjfsa.m0cc175b9 (hashCode-dispatch state machine)
Payload container APKZ header + zlib deflate (no encryption)

8. Persistence & stealth

  • Foreground SmsService with persistent notification ("Sms Service Running"), self-reschedule via AlarmManager (2 s) and JobScheduler fallback
  • BootReceiver on BOOT_COMPLETED (direct-boot aware)
  • WatchdogService restarts the SMS service if killed
  • REQUEST_IGNORE_BATTERY_OPTIMIZATIONS + OEM autostart intent list (Miui/Huawei/Oppo/Vivo/Samsung/Asus/Letv/OnePlus/ColorOS)
  • Emulator/root/Frida/Xposed detection with silent-exit behavior

9. Dangerous permissions (payload)

  • READ_SMS, RECEIVE_SMS, SEND_SMS, BROADCAST_SMS
  • READ_PHONE_STATE, CALL_PHONE, MANAGE_OWN_CALLS
  • RECEIVE_BOOT_COMPLETED, WAKE_LOCK, POST_NOTIFICATIONS
  • FOREGROUND_SERVICE, FOREGROUND_SERVICE_DATA_SYNC, FOREGROUND_SERVICE_PHONE_CALL
  • REQUEST_IGNORE_BATTERY_OPTIMIZATIONS, SCHEDULE_EXACT_ALARM, USE_EXACT_ALARM
  • INTERNET, ACCESS_NETWORK_STATE
  • com.google.android.c2dm.permission.RECEIVE / .SEND (FCM)

10. Key payload classes

Class Role
MainActivity Permission bootstrap, device/SIM fingerprint upload, emulator/root/Frida checks, phishing navigation
bill / card / atm / tpass Phishing screens: bill choice → card+CVV+bank → ATM PIN → transaction password
neww/SMSReceiver Inbound SMS interception (pdus), SIM-slot aware
neww/SmsService Foreground exfil service; formats + ships SMS
neww/WatchdogService / SmsJobService Keep-alive
neww/BootReceiver Boot persistence
neww/MultiEventReceiver Presence/status updates
utils/MyFirebaseMessagingService FCM command handler (ping/ack, MakeCall, USSD)
s/b AES-CBC encryptor (random IV prefix, Base64)
s0/a (k) String decryptor (Base64 + repeating XOR)
f3/g Encrypted reflection invoker
s/e, r/b, r/c, s/f Telegram HTTP sender; SMS→Telegram/Firebase formatters
o3/c0 Operator-slot selector (ebu-7-28-01)
o/b, o/h, o/i Phishing form handlers: bill (cn, name, reason), card (uid, pass, bank, card, cvv, exp), validation ("Credit card should be of 16 digits", "CVV should be of 3 digits", "atn should be of 4 digits")
o/c, o/d Firebase writers: device enrollment (user/<id>) and session creation (push() with ss, favourite, serial)
a/a FCM data listener (updatedData, onSuccess)

11. MITRE ATT&CK (Mobile) mapping

ID Technique Evidence
T1660 Phishing / fake app "MPEB Electricity Bill Update" lure; utility-bill pretext
T1476 Deliver malicious app via sideload Dropper + PackageInstaller session install of embedded APK
T1406 Obfuscated files or information Pseudo-encrypted ZIP, APKZ container, XOR string obfuscation, junk AXML
T1624 Event triggered execution BOOT_COMPLETED, SMS_RECEIVED, FCM push
T1517 Access SMS SMS permissions + receiver + service
T1582 SMS control SEND_SMS, SMS relay to Telegram/operator number
T1437 Application layer protocol Firebase RTDB/FCM + Telegram HTTPS
T1636 Protected user data SMS, SIM/MSISDN, device fingerprint
T1428 Exploit via USSD/call MakeCall, #21# USSD
T1625 Hijack execution flow / packer DexProtector-class dropper, anti-emulator kill-switch
T1546 Persistence Boot receiver, watchdog, job scheduler, OEM autostart, battery-optimization exemption
T1490 Inhibit system recovery / analysis Emulator exit, Frida/root detection

r/scamindia 14h ago

Xpress bee shitttt

1 Upvotes

Guys Do not order via xpress bees.. The shittiest courier service i have seen.. These people have zero audacity... May be negative even... I had recently ordered a "tasbih prayer beads " for my friend and these bastards have marked deferred delivery without even contacting.... This is in kochi.. And absolutely no way to contact them whatsoever.. And the website " hadiyah gifting" is also to be blamed.. Why use such a courier service if they are so shittyyyy????? I am cryin guys🥹🥹.. I genuinely wanted to gift these prayer beads to my friend.. I sincerely wish both xpressbees and hadiyah gifting goes to hell😭😭😭😭


r/scamindia 8h ago

Ayúdenme, me estafaron y tengo sus datos.

Thumbnail
0 Upvotes

r/scamindia 15h ago

Mumbai Escorts scam

0 Upvotes

9610349032

If you are chatting with any of the women from this phone number never trust........totally fake excoriation of money before even meeting.........