Abhishek is a Telegram-based fraud actor associated with a dedicated operation that advertised alleged leaked NEET examination papers in India. The activity centered on a dedicated Telegram channel used as a hub for advertisements, updates, booking announcements, deadline reminders, and recruitment-style messaging intended to build anticipation ahead of the exam. The operation appears focused primarily on NEET-related fraud rather than broader underground trading. The actor used direct-message contact flows, urgency and scarcity claims, purported testimonials, and anti-scam messaging to persuade prospective buyers. The channel attempted to present itself as an organized and trustworthy service by posting admissions-related announcements, warning users about rival scammers, and sharing screenshots presented as prior customer interactions. No confirmed evidence establishes that genuine examination papers were actually obtained or delivered. Attribution links the operation to a deleted Telegram account whose historical profile data identified the first name Abhishek and connected the account to the dedicated NEET-themed channel through profile biography information. The activity is best characterized as a coordinated social-engineering and fraud campaign exploiting examination anxiety around India's medical entrance process, rather than a demonstrated compromise of examination systems.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.