RAGHAV SIR is a Telegram-based fraud persona associated with a coordinated campaign that advertised alleged leaked NEET examination papers in India ahead of the medical entrance exam. The persona appeared across multiple underground Telegram communities rather than relying on dedicated infrastructure, indicating an opportunistic use of pre-existing illicit marketplaces and chat groups to reach prospective buyers. Activity attributed to this branding included repeated promotional posts that pushed users into private conversations and used urgency, scarcity, and purported testimonials to create credibility and pressure victims into transactions. The operation was part of a broader ecosystem marketing supposed access to examination papers, but there is no confirmed evidence that genuine NEET papers were actually obtained or delivered. The available evidence supports characterization of the activity as fraud rather than a verified exam-compromise operation. The RAGHAV SIR branding was linked to multiple Telegram identities treated as related promotional personas, although attribution to a single individual was not established with high confidence. Beyond the NEET-themed scam activity, the persona also advertised other illicit or gray-market offerings, including gift cards, device unlock-related services, and financial offers, reinforcing the assessment that it operated as a flexible underground seller persona. The actor's observable behavior is consistent with social-engineering-driven initial victim engagement, platform-based reconnaissance of suitable communities for promotion, and spoofing of legitimacy through fabricated or unverified buyer feedback and anti-scam messaging.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.