#FactCheck: Chhatarpur Protest Video Falsely Shared as Indian Army Atrocities in Manipur
Research Wing
Innovation and Research
PUBLISHED ON
Aug 10, 2026
10
Executive Summary
A video is going viral on social media showing police personnel allegedly dragging an elderly woman. The video is being shared with the claim that it was filmed in Manipur and shows the Indian Army committing atrocities against women. The CyberPeace Research Wing found that the viral video is not from Manipur. It was recorded during protests against the Ken-Betwa Link Project in Chhatarpur, Madhya Pradesh, and is being circulated with a misleading claim.
Claim:
A video shared on social media claims that the Indian Army is committing atrocities against local people, particularly women, in Manipur. The post further alleges that R&AW chief Parag Jain is allowing Manipur to burn and that people will never forget the alleged brutality.
To verify the claim, our team extracted keyframes from the viral video and conducted a reverse image search using Google Lens. During the search, we found the same video uploaded on the Facebook page of Public Vani News on July 31. The accompanying description stated: “Police action against an elderly tribal woman is shameful. During protests against the Ken-Betwa Link Project in Chhatarpur, a video showing police removing an elderly tribal woman has gone viral. Protesters claim they were holding a Jal Satyagraha, hunger strike and Chita Andolan while demanding fair compensation and protection of their land, forests and homes.”
In the next step of the research, we found the same video on an Instagram channel named policemedianews, where it was shared without the misleading Manipur-related claim. The post link and screenshot are provided below
The research found that the viral claim is misleading. The video is not from Manipur and does not show Indian Army personnel targeting women there. The footage is from protests against the Ken-Betwa Link Project in Chhatarpur, Madhya Pradesh, where police were seen removing an elderly tribal woman during the demonstration. The video is being shared on social media with a false context.
A video is being widely shared on social media after a fire incident in Aliganj, Lucknow. The approximately 15-second clip shows a building engulfed in flames, where a woman is seen hanging her small child outside a window while desperately seeking help. The video is being circulated as if it shows the recent Lucknow fire incident. CyberPeace Research Wing research found the claim to be misleading. The viral video is not related to the Lucknow fire incident. In fact, the clip is around 16 years old and originates from a completely different incident in the United States. It is being falsely shared on social media with a misleading context.
Claim:
A Facebook user shared the viral video on June 22, 2026, claiming: “A mother’s love is so powerful that even in front of death, she goes to any extent to save her child.” The post link, archived link, and screenshots are provided below.
To verify the claim, we conducted a reverse image search of the video keyframes using Google Lens. During the research, we found the same visuals published in a HuffPost report dated 2010. According to the report, the incident shows a fire in an apartment in the Bronx, New York, USA. https://www.huffpost.com/entry/photo-captures-baby-dangl_n_463780
According to a report by Dainik Bhaskar, a fire incident at a coaching center in Aliganj, Lucknow resulted in the death of around 15 people. The government suspended four officials and police arrested four accused in connection with the incident. However, it was confirmed that the actual footage from the Lucknow coaching center fire is different from the viral video and has no relation to it. https://www.bhaskar.com/local/uttar-pradesh/lucknow/news/lucknow-coaching-center-fire-children-rescue-effort-138258629.html
Conclusion:
Our research confirms that the viral video is not related to the Lucknow fire incident. The footage is actually from a 16-year-old fire incident in the Bronx, New York, USA, and is being falsely shared with a misleading context on social media.
A video of India’s Defence Minister Rajnath Singh is going viral on social media. The post claims that Rajnath Singh is openly supporting Israeli-American attacks against Iran. In the video, he can allegedly be heard saying that Prime Minister Narendra Modi had visited Israel before the war began and warned Tehran that disturbing peace would have serious consequences.
Research by CyberPeace found that the viral video is a deepfake created using Artificial Intelligence (AI). Rajnath Singh has not made any such statement about Iran or the Israel-US conflict.
Claim
A Facebook user “Sheikh Sadeque Ali” shared the video on March 2, 2026. The caption of the post reads, “Indian Defence Minister Rajnath Singh is supporting Israel’s attack on Iran. This clearly shows that India supports the killing of Muslims.”
In the viral video, Rajnath Singh appears to say in English: “Prime Minister Modi’s visit to Israel before the attack on Iran reflects India’s solidarity with its strategic partner… He warned Tehran that hostile actions would have serious consequences for regional peace.”
To verify the claim, we extracted keyframes from the viral video and conducted a reverse image search. During the research , we found the original video on Rajnath Singh’s official YouTube channel. The video was uploaded on November 23, 2025.In the original video, Rajnath Singh was addressing a Sindhi community conference in Delhi. During his speech, he was talking about Sindhi culture and the history of Partition. He did not mention Israel, Iran or any Middle East conflict during the entire program.
Upon closely examining the viral video, technical inconsistencies between the lip movements and the audio (lip-sync discrepancies) can be observed, which strongly indicate that the video may have been generated using AI. To verify this, we analysed the clip using several AI-detection tools. The AI detection tool Hive Moderation indicated that the video has a 99% probability of being AI-generated.
Conclusion:
Our research found that the viral video of Rajnath Singh is a deepfake. He has not made any statement supporting Israel or opposing Iran. The original video is from a Sindhi community event in Delhi, which has been digitally altered using AI to spread a misleading claim.
A new Android malware called NGate is capable of stealing money from payment cards through relaying the data read by the Near Field Communication (“NFС”) chip to the attacker’s device. NFC is a device which allows devices such as smartphones to communicate over a short distance wirelessly. In particular, NGate allows forging the victims’ cards and, therefore, performing fraudulent purchases or withdrawing money from ATMs. .
About NGate Malware:
The whole purpose of NGate malware is to target victims’ payment cards by relaying the NFC data to the attacker’s device. The malware is designed to take advantage of phishing tactics and functionality of the NFC on android based devices.
Modus Operandi:
Phishing Campaigns: The first step is spoofed emails or SMS used to lure the users into installing the Progressive Web Apps (“PWAs”) or the WebAPKs presented as genuine banking applications. These apps usually have a layout and logo that makes them look like an authentic app of a Targeted Bank which makes them believable.
Installation of NGate: When the victim downloads the specific app, he or she is required to input personal details including account numbers and PIN numbers. Users are also advised to turn on or install NFC on their gadgets and place the payment cards to the back part of the phone to scan the cards.
NFCGate Component:One of the main working features of the NGate is the NFCGate, an application created and designed by some students of Technical University of Darmstadt. This tool allows the malware to:
Collect NFC traffic from payment cards in the vicinity.
Transmit, or relay this data to the attacker’s device through a server.
Repeat data that has been previously intercepted or otherwise copied.
It is important to note that some aspects of NFCGate mandate a rooted device; however, forwarding NFC traffic can occur with devices that are not rooted, and therefore can potentially ensnare more victims.
Technical Mechanism of Data Theft:
Data Capture: The malware exploits the NFC communication feature on android devices and reads the information from the payment card, if the card is near the infected device. It is able to intercept and capture the sensive card details.
Data Relay: The stolen information is transmitted through a server to the attacker’s device so that he/she is in a position to mimic the victim’s card.
Unauthorized Transactions: Attackers get access to spend money on the merchants or withdraw money from the ATM that has NFC enabled. This capability marks a new level of Android malware in that the hackers are able to directly steal money without having to get hold of the card.
Social Engineering Tactics:
In most cases, attackers use social engineering techniques to obtain more information from the target before implementing the attack. In the second phase, attackers may pretend to be representatives of a bank that there is a problem with the account and offer to download a program called NGate, which in fact is a Trojan under the guise of an application for confirming the security of the account. This method makes it possible for the attackers to get ITPIN code from the sides of the victim, which enables them to withdraw money from the targeted person’s account without authorization.
Technical Analysis:
The analysis of malicious file hashes and phishing links are below:
Additionally, several distinct phishing websites have been identified, including:
rb.2f1c0b7d.tbc-app[.]life
geo-4bfa49b2.tbc-app[.]life
rb-62d3a.tbc-app[.]life
csob-93ef49e7a.tbc-app[.]life
george.tbc-app[.]life.
Analysis:
Img Source: Virus Total
Broader Implications of NGate:
The ultramodern features of NGate mean that its manifestation is not limited to financial swindling. An attacker can also generate a copy of NFC access cards and get full access when hacking into restricted areas, for example, the corporate offices or restricted facility. Moreover, it is also safe to use the capacity to capture and analyze NFC traffic as threats to identity theft and other forms of cyber-criminality.
Precautionary measures to be taken:
To protect against NGate and similar threats, users should consider the following strategies:
Disable NFC: As mentioned above, NFC should be not often used, it is safe to turn NFC on Android devices off. This perhaps can be done from the general control of the device in which the bursting modes are being set.
Scrutinize App Permissions: Be careful concerning the permission that applies to the apps that are installed particularly the ones allowed to access the device. Hence, it is very important that applications should be downloaded only from genuine stores like Google Play Store only.
Use Security Software: The malware threat can be prevented by installing relevant security applications that are available in the market.
Stay Informed: As it has been highlighted, it is crucial for a person to know risks that are associated with the use of NFC while attempting to safeguard an individual’s identity.
Conclusion:
The presence of malware such as NGate is proof of the dynamism of threats in the context of mobile payments. Through the utilization of NFC function, NGate is a marked step up of Android malware implying that the attackers can directly manipulate the cash related data of the victims regardless of the physical aspect of the payment card. This underscores the need to be careful when downloading applications and to be keen on the permission one grants on the application. Turn NFC when not in use, use good security software and be aware of the latest scams are some of the measures that help to fight this high level of financial fraud. The attackers are now improving their methods. It is only right for the people and companies to take the right steps in avoiding the breach of privacy and identity theft.
Your institution or organization can partner with us in any one of our initiatives or policy research activities and complement the region-specific resources and talent we need.