What’s Your New Year's Resolution?
2025 is knocking firmly at our door and we have promises to make and resolutions to keep. Time you make your list for the New Year and check it twice.
- Lifestyle targets 🡪 Check
- Family targets 🡪 Check
- Social targets 🡪 Check
Umm, so far so good, but what about your cybersecurity targets for the year? Hey, you look confused and concerned. Wait a minute, you do not have one, do you?
I get it. Though the digital world still puzzles, and sometimes outright scares us, we still are not in the ‘Take-Charge-Of-Your-Digital-Safety Mode. We prefer to depend on whatever software security we are using and keep our fingers crossed that the bad guys (read threat actors) do not find us.
Let me illustrate why cybersecurity should be one of your top priorities. You know that stress is a major threat to our continued good health, right? However, if your devices, social media accounts, office e-mail or network, or God forbid, bank accounts become compromised, would that not cause stress? Think about it and the probable repercussions and you will comprehend why I am harping on prioritising security.
Fret not. We will keep it brief as we well know you have 101 things to do in the next few days leading up to 01/01/2025. Just add cyber health to the list and put in motion the following:
- Install and activate comprehensive security software on ALL internet-enabled devices you have at home. Yes, including your smartphones.
- Set yourself a date to change and create separate unique passwords for all accounts. Or use the password manager that comes with all reputed security software to make life simpler.
- Keep home Wi-Fi turned off at night
- Do not set social media accounts to auto-download photos/documents
- Activate parental controls on all the devices used by your children to monitor and mentor them. But keep them apprised.
- Do not blindly trust anyone or anything online – this includes videos, speeches, emails, voice calls, and video calls. Be aware of fakes.
- Be aware of the latest threats and talk about unsafe cyber practices and behaviour often at home.
Short and sweet, as promised.
We will be back, with more tips, and answers to your queries. Drop us a line anytime, and we will be happy to resolve your doubts.
Ciao!
Related Blogs

Introduction
Embark on a groundbreaking exploration of the Darkweb Metaverse, a revolutionary fusion of the enigmatic dark web with the immersive realm of the metaverse. Unveiling a decentralised platform championing freedom of speech, the Darkverse promises unparalleled diversity of expression. However, as we delve into this digital frontier, we must tread cautiously, acknowledging the security risks and societal challenges that accompany the metaverse's emergence.
The Dark Metaverse is a unique combination of the mysterious dark web and the immersive digital world known as the metaverse. Imagine a place where users may participate in decentralised social networking, communicate anonymously, and freely express a range of viewpoints. It aims to provide an alternative to traditional online platforms, emphasizing privacy and freedom of speech. Nevertheless, it also brings new kinds of criminality and security issues, so it's important to approach this digital frontier cautiously.
In the vast expanse of the digital cosmos, there exists a realm that remains shrouded in mystery to the casual netizen—the dark web. It is a place where the surface web, the familiar territory of Google searches and social media feeds, constitutes a mere 5 per cent of the information iceberg floating in an ocean of data. Beneath this surface lies the deep web and the dark web, comprising the remaining 95 per cent, a staggering figure that beckons the brave and curious to explore its abysmal depths.
Imagine, a platform that not only ventures into these depths but intertwines them with the emerging concept of the metaverse—a digital realm that defeats the limitations of the physical world. This is the vision of the Darkweb Metaverse, the world’s premier endeavour to harness the enigmatic depths of the dark web and fuse it into the immersive experience of the metaverse.
As per Internet User Statistics 2024, There are over 5.3 billion Internet users in the world, meaning over 65% of the world’s population has access to the Internet. The Internet is used for various services. News, entertainment, and communication to name a few. The citizens of developed countries depend on the World Wide Web for a multitude of daily tasks such as academic research, online shopping, E-banking, accessing news and even ordering food online hence the Internet has become an integral part of our daily lives.
Surface Web
This layer of the internet is used by the general public on a daily basis. The contents of this layer are accessed by standard web browsers namely Google Chrome, and Mozilla Firefox to name a few. The contents of this layer of the internet are indexed by these search engines.
Deep Web
This is the second layer of the internet; its contents are not indexed by search engines. The content that is unavailable on the surface web is considered to be a part of the deep web. The deep web comprises a collection of various types of confidential information. Several Schools, Universities, Institutes, Government Offices and Departments, Multinational Companies (MNCs), and Private Companies store their database information and website-oriented server information such as online profile and accounts usernames or IDs and passwords or log in credentials and companies' premium subscription data and monetary transactional records in the Intra-net which is part of the deep web.
Dark Web
It is the least explored part of the internet which is considered to be a hub of various bizarre activities. The contents of the dark web are not indexed by search engines and specific software is required to access this layer of the internet namely TOR (The Onion Router) browser which cloaks to identify its users making them anonymous. The websites of the dark web are identified from .onion TLD (Top Level Domain). Due to anonymity provided in this layer, various criminal activities take place over there including Drugs trading, Arms trading, and Illegal PayPal account details to websites offering child pornography.
The Darkverse
The Darkweb Metaverse is not a mere novelty; it is a revolutionary step forward, a decentralised social networking platform that stands in stark contrast to centralised counterparts like YouTube or Twitter. Here, the spectre of censorship is banished, and the freedom of speech reigns supreme.
The architectonic prowess behind the Darkweb Metaverse is formidable. The development team is a coalition of former infrastructure maestros from Theta Network and virtuosos of metaverse design, bolstered by backend engineers from Gensokishi Metaverse. At the helm is a CEO whose tenure at the apex of large Japanese companies has endowed him with a profound understanding of the landscape, setting a solid foundation for the platform's future triumphs.
Financially, the dark web has been a flourishing underworld, with revenues ranging from $1.5 billion to $3.1 billion between 2020 and 2022. Darkverse, with its emphasis on user-friendliness and safety, is poised to capture a significant portion of this user base. The platform serves as a truly decentralised amalgamation of the Dark Web, Metaverse, and Social Networking Services (SNS), with a mission to provide an unassailable bastion for freedom of speech and expression.
The Darkweb Metaverse is not merely a sanctuary for anonymity and privacy; it is a crucible for the diversity of expression. In a world where centralised platforms can muzzle voices, Darkverse stands as a bulwark against such suppression, fostering a community where a kaleidoscope of opinions and information thrives. The ease of use is unparalleled—a one-time portal that obviates the need for third-party software to access the dark web, protecting users from the myriad risks that typically accompany such ventures.
Moreover, the platform's ability to verify the authenticity of information is a game-changer. In an era laced with misinformation, especially surrounding contentious issues like war, Darkverse offers a sign of truth where the source of information can be scrutinised for its accuracy.
Integrating Technologies
The metaverse will be an immersive iteration of the internet, decked with interactive features of emerging technologies such as artificial intelligence, virtual and augmented reality, 3D graphics, 5G, holograms, NFTs, blockchain and haptic sensors. Each building block, while innovative, carries its own set of risks—vulnerabilities and design flaws that could pose a serious threat to the integrated meta world.
The dark web's very nature of interaction through avatars makes it a perfect candidate for a metaverse iteration. Here, in this anonymous world, commercial and personal engagements occur without the desire to unveil real identities. The metaverse's DNA is well-suited to the dark web, presenting a formidable security challenge as it is likely to evolve more rapidly than its real-world counterpart.
While Meta (formerly Facebook) is a prominent entity developing the metaverse, other key players include NVIDIA, Epic Games, Microsoft, Apple, Decentraland, Roblox Corporation, Unity Software, Snapchat, and Amazon. These companies are integral to constructing the vast network of real-time 3D virtual worlds where users maintain their identities and payment histories.
Yet, with innovation comes risk. The metaverse will necessitate police stations, not as a dystopian oversight but as a means to address the inherent challenges of a new digital society. In India, for instance, the integration of law enforcement within the metaverse could revolutionize the public's interaction with the police, potentially increasing the reporting of crimes.
The Perils within the Darkverse
The metaverse will also be a fertile ground for crimes of a new dimension—identity theft, digital asset hijacking, and the influence of metaverse interactions on real-world decisions. With a significant portion of social media profiles potentially being fraudulent, the metaverse amplifies these challenges, necessitating robust identity access management.
The integration of NFTs into the metaverse ecosystem is not without its security concerns, as token breaches and hacks remain a persistent threat. The metaverse's parallel economy will test the developers' ability to engender trust, a Herculean task that will challenge the boundaries of national economies.
Moreover, the metaverse will be a crucible for social engineering-based attacks, where the real-time and immersive nature of interactions could make individuals particularly vulnerable to deception and manipulation. The potential for early-stage fraud, such as the hyping and selling of virtual assets at unrealistic prices, is a stark reality.
The metaverse also presents numerous risks, particularly for children and adolescents who may struggle to distinguish between virtual and real worlds. The implications of such immersive experiences are intense, with the potential to influence behaviour in hazardous ways.
Security risks extend to the technologies supporting the metaverse, such as virtual and augmented reality. The exploitation of biometric data, the bridging of virtual and real worlds, and the tendency for polarisation and societal isolation are all issues requiring immediate attention.
A Way Forward
As we stand on the cusp of this new digital frontier, it is evident that the metaverse, despite its reliance on blockchain, is not immune to the privacy and security breaches that have plagued conventional IT infrastructure. Data security, Identity theft, network security, and ransomware attacks are just a few of the challenges on the way.
In this quest into the unknown, the Darkweb Metaverse radiates with the promise of freedom and the thrill of discovery. Yet, as we navigate these shadowy depths, we must remain vigilant, for the very technologies that empower us also rear the seeds of our grim vulnerabilities. The metaverse is not just a new chapter in the story of the internet—it is a whole narrative, one that we must write with caution and care.
References
- https://spores.medium.com/the-worlds-first-platform-to-deploy-the-dark-web-in-the-metaverse-releap-ido-on-spores-launchpad-a36387b184de
- https://www.makeuseof.com/how-hackers-sell-trade-data-in-metaverse/
- https://www.demandsage.com/internet-user-statistics/#:~:text=There%20are%20over%205.3%20billion,has%20access%20to%20the%20Internet.

Introduction
As we navigate the digital realm that offers unlimited opportunities, it also exposes us to potential cyber threats and scams. A recent incident involving a businessman in Pune serves as a stark reminder of this reality. The victim fell prey to a sophisticated online impersonation fraud, where a cunning criminal posed as a high-ranking official from Hindustan Petroleum Corporation Limited (HPCL). This cautionary tale exposes the inner workings of the scam and highlights the critical need for constant vigilance in the virtual world.
Unveiling the scam
It all began with a phone call received by the victim, who lives in Taware Colony, Pune, on September 5, 2023. The caller, who identified himself as "Manish Pande, department head of HPCL," lured the victim by taking advantage of his online search for an LPG agency. With persuasive tactics, the fraudster claimed to be on the lookout for potential partners.
When a Pune man received a call on September 5, 2023. The caller, who introduced himself as “department head of HPCL”, was actually a cunning fraudster. It turns out, the victim had been searching for an LPG agency online, which the fraudster cleverly used to his advantage. In a twisted plot, the fraudster pretended to be looking for potential locations to establish a new LPG cylinder agency in Pune.
Enthralled by the illusion
The victim fell for the scam, convinced by the mere presence of "HPCL" in the bank account's name. Firstly victim transferred Rs 14,500 online as “registration fees”. Things got worse when, without suspicion, the victim obediently transferred Rs 1,48,200 on September 11 for a so-called "dealership certificate." To add to the charade of legitimacy, the fraudster even sent the victim registration and dealership certificates via email.
Adding to the deception, the fraudster, who had targeted the victim after discovering his online inquiry, requested photos of the victim's property and personal documents, including Aadhaar and PAN cards, educational certificates, and a cancelled cheque. These seemingly legitimate requests only served to reinforce the victim's belief in the scam.
The fraudster said they were looking for a place to allot a new LPG cylinder agency in Pune and would like to see if the victim’s place fits in their criteria. The victim agreed as it was a profitable business opportunity. The fraudster called the victim to “confirm” that his documents have been verified and assured that HPCL would be allotting him an LPG cylinder agency. On September 12, the fraudster again demanded a sum of money, this time for the issuance of an "HPCL license."
As the victim responded that he did not have the money, the fraudster insisted on an immediate payment of at least 50 per cent of the stipulated amount. So the victim transferred Rs 1,95,200 online. On the following day the 13th of September 2023, the fraudster asked the victim for the remaining amount. The victim said he would arrange the money in a few days. Meanwhile, on the same day, the victim went to the HPCL’s office in the Pune Camp area with the documents he had received through the emails. The HPCL employees confirmed these documents were fake, even though they looked very similar to the originals. The disclosure was a pivotal moment, causing the victim to fully comprehend the magnitude of the deceit and ultimately pursue further measures against the cybercriminal.
Best Practices
- Ensuring Caller Identity- Prioritize confirming the identity of anyone reaching out to you, especially when conducting financial transactions. Hold back from divulging confidential information until you have verified the credibility of the request.
- Utilize Official Channels- Communicate with businesses or governmental organizations through their verified contact details found on their official websites or trustworthy sources. Avoid solely relying on information gathered from online searches.
- Maintaining Skepticism with Unsolicited Communication- Exercise caution when approached by unexpected calls or emails, particularly those related to monetary transactions. Beware of manipulative tactics used by scammers to pressure swift decisions.
- Double-Check Information- To ensure accuracy, it is important to validate the information given by the caller on your own. This can be done by double-checking and cross-referencing the details with the official source. If you come across any suspicious activities, do not hesitate to report it to the proper authorities.
- Report Suspicious Activities- Reporting can aid in conducting investigations and providing assistance to the victim and also preventing similar incidents from occurring. It is crucially important to promptly report cyber crimes so law enforcement agencies can take appropriate action. A powerful resource available to victims of cybercrime is the National Cyber Crime Reporting Portal, equipped with a 24x7 helpline number, 1930. This portal serves as a centralized platform for reporting cybercrimes, including financial fraud.
Conclusion
This alarming event serves as a powerful wake-up call to the constant danger posed by online fraud. It is crucial for individuals to remain sceptical, diligently verifying the credibility of unsolicited contacts and steering clear of sharing personal information on the internet. As technology continues to evolve, so do the strategies of cyber criminals, heightening the need for users to stay on guard and knowledgeable in the complex digital world.
References:
- https://indianexpress.com/article/cities/pune/cybercriminal-posing-hindustan-petroleum-official-cheat-pune-man-9081057/
- https://www.timesnownews.com/mirror-now/crime/pune-man-duped-of-rs-3-5-lakh-by-cyber-fraudster-impersonating-hpcl-official-article-106253358
.webp)
Introduction
It might seem too good to be true: free movies, live TV and sports without any subscription plan are deals that no one in India could actually refuse, and that’s precisely the explanation as to why applications such as Pikashow have gained tremendous traction in India and all over the world as well. However, cybersecurity authorities have a strong cause of concern: the threat that this type of application poses towards lakhs of Indians with malicious software, stealing information and even money. Pikashow may be a perfect case study to establish this problem, but in fact, it all ties down to how downloading anything without the recognised applications has certain risks attached to it.
The Pikashow Warning
With no monthly subscription fees, Pikashow is a popular free app for streaming movies, web series, live TV channels and sports programmes. Since its development, Pikashow has had a reputation for never being found on the Google Play Store or Apple’s App Store, which necessitates a process of side-loading. A side load, in this case, entails downloading the Pikashow APK file from an unofficial third-party source and manually installing the app, circumventing the security measures of official download channels.
The latter is significant because security experts who have analysed Pikashow argue that it acts as an informal content aggregator; movies and TV series are illegally scooped up from online streaming services, then shared via various third-party links and streamed without a content licence or any agreement with legitimate providers.
Without going through the rigorous checks conducted by Google or Apple, security researchers discovered that even while the app appeared to be working fine with its promised streams, hidden malware within the installer can run silently, leading to potentially significant security risks such as data theft of user logins, one-time passwords, and private files, including banking credentials. This has been cited to be so problematic for India that law enforcement agencies like the Indian Cyber Crime Coordination Centre under the Ministry of Home Affairs and the Cyber Dost platform are expected to have issued public advisories linking Pikashow to a proliferation of cases of cybercrime. Users should take into account the legal implications alongside security concerns, as using piracy apps may not only lead to device-compromising issues but can also be against the Copyright Act of India as well, thus increasing the risk of legal prosecution.
Why This Isn't Just a "Pikashow Problem"
This should not be viewed as a single warning concerning one app. Pikashow is merely an illustration of one app from millions that exists outside official app stores and is built with the same mechanics that make Pikashow dangerous and applicable to virtually any app, game, or "modded" file which is downloaded from a random website, third-party app store, or Telegram channel.
Some issues that persist are-
- Official app stores are like a filter that is not perfect, but it is still critical to the security on a user's device. Both Google and Apple's App stores run automatic and manual malware scanners, screen permissions for legitimate use, and have the ability to remove malicious developers as necessary. Empirical research has estimated just how important this is: more than fifty-times more malware exists on sideloaded, "unofficial" apps versus official. Mobile security firm Zimperium claims nearly 40% of all devices tested with malware were infected due to downloading an app from outside the official app stores; furthermore, nearly 80% of malicious, sideloaded apps contained riskware or trojans.
- Informational channels can also be used to gain the trust of users by mimicking familiar brands One frequently mentioned scheme is one where malicious actors repackage popular apps with a malignant intent to syphon the app, disguised as a free, trustworthy app. Often when these apps are available, they work exactly the same as the legitimate app, as a matter of fact, but quietly in the background steal passwords or log keystrokes; this was discovered to be occurring with a financial trojan called TeaBot, where bank details and login info were intercepted through the device's Accessibility Service.
- There is generally no recourse or legal liability that applies once something has gone wrong. While official app stores are official developers that can be identified to submit complaints against them, if a third-party download leads to damages, that developer generally cannot be located to establish liability or legal standing.
- Excessive app permissions will often go undetected This occurs for the similar reasons that a malicious actor can include such a clause as explained above. There's really nothing to stop the developer from asking to utilise one's SMS, call log, camera, microphone, storage or location when there's not one reason for one application to need access to everything on the device.
- Expired software has the same or more risk It's actually very common to see apps that receive security updates out in the wild that either don't have the appropriate update sent over to third-party app stores or third-party stores don't have the capacity to update the affected applications. That's why most official third-party app downloads should be of fairly new versions; for example, outdated versions of a banking app, which is being patched as well as receiving other updates from Google or Apple still, will continue to persist on third-party download sites for some time after patching, which could then be malicious.
- Even legitimate, globally recognised apps can and have been compromised The same vulnerability was noted for TikTok in 2023, which, when found on unofficial APK download sites, contained hidden data-tracking malware yet looked identical to the official app version.
How to Protect Yourself
The reassuring thing is that the vast majority of this risk can be eliminated through simple, repeatable habits. Use trusted sources like Google Play and Apple's App Store, which are not faultless, of course, but they remove many infected apps from circulation following review.
- Be sceptical of "free" premium-paid apps.
- If something in a file from a site you don't recognise offers content or features that are normally behind a paywall and they want nothing to do with it, that is a bad sign, not a good deal. Review app permissions when you go to install anything. A flashlight doesn't need access to your SMS messages or contacts, as one recently downloaded on a colleague's Android allegedly attempted to acquire them from the Google Play store. After sideloading any app that you do not fully trust, it's always a wise idea to uninstall it and scan the handset to ensure malicious files aren't still lingering around.
- Choose legitimate services to avoid malware.
- In entertainment terms this will apply most clearly to piracy but applies similarly elsewhere in many senses. Trusted sources that are licensed include YouTube, JioCinema, Hotstar, Netflix, Amazon Prime Video, and MX Player, among others, which will offer content similar to illegally acquired or pirated versions without the security, as well as the legal risks. If you have recently used the file installation route to any degree of caution on a sensitive device, then also monitor banking and payment apps.
- That is not least because the most reported consequence of infection from an illicit or unknown source is the theft of financial account login details.
Conclusion
Free entertainment can look tempting, but as cybersecurity experts keep pointing out, "free" often just means the cost has been shifted from your wallet to your data, your device, and potentially your bank account. The safest rule of thumb remains simple: if an app isn't on an official store, ask why and think twice before installing it.
Sources
- Pikashow app risky, may expose users to malware and data theft: Experts — Times of India
- Free OTT Hack or Cyber Trap? Pikashow Flagged for Serious Security Risks — The420.in
- Pikashow Warning: Free Movies Could Empty Your Bank Account, Government Issues Strong Alert — The420.in
- Is Pikashow Safe or Risky to Use in 2025? Expert's Advice — AiPlex AntiPiracy
- Why Pikashow May Not Be Safe for Your Device — AiPlex AntiPiracy
- Concerns Rise Over the Safety of Popular Streaming App Pikashow — openPR
- Beyond the App Store: The Hidden Risks of Sideloading Apps — Zimperium
- App Sideloading: Risks, Rules, and How IT Admins Respond — Trio
- What Are the Risks of Sideloading Apps on Your Smartphone? — Bitdefender
- Sideloading Risk: Alternative App Stores and Brand Protection — Allure Security
- Building a Trusted Ecosystem for Millions of Apps: A Threat Analysis of Sideloading — Apple