Indian authorities ordered the blocking of seven battery management system mobile apps, including BAT-BMS, after they were abused to remotely disable electric rickshaws and some e-scooters by connecting over Bluetooth to compatible lithium batteries. The misuse spread through viral videos and a prank trend known as the Tirri Challenge, leaving drivers stranded in traffic and causing service disruptions in multiple locations. Officials also linked the capability to extortion, including a case in Ujjain, Madhya Pradesh, where police arrested a suspect accused of immobilizing e-rickshaws and demanding payment from drivers.
The Ministry of Electronics and Information Technology directed Google and Apple to remove the identified apps from their Indian app stores and warned marketplaces to apply greater due diligence where public safety is at risk. The action does not fully eliminate the threat, however, because the apps may still be available through third-party stores or alternate store regions, and vulnerable battery systems can still be accessed over Bluetooth if they lack password or PIN protection. The incident has intensified scrutiny of missing cybersecurity requirements in India’s e-rickshaw certification standards and the broader risks posed by connected electric mobility systems.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
The Indian central government is preparing new cybersecurity regulations for electric two- and three-wheelers to address unauthorized battery and software tampering. Proposed measures include stronger software security requirements, possible restrictions on exploitable mobile apps, and linking future roadworthiness certification to the absence of such vulnerabilities.
The Indian government ordered the blocking of seven battery management system mobile applications after determining they were being misused to remotely disable batteries in electric vehicles and e-rickshaws. MeitY directed Google and Apple to remove the identified apps from their Android and iOS app stores in India.
In Ujjain, Madhya Pradesh, police arrested a suspect accused of remotely immobilizing e-rickshaws and demanding payment from drivers. The arrest tied the battery-disabling abuse to a criminal extortion scheme rather than only prank activity.
Attackers and pranksters misused the legitimate Bluetooth-enabled BAT-BMS battery management app to connect to compatible lithium batteries and shut down e-rickshaws, causing service disruptions in multiple locations in India. Some incidents also reportedly affected e-scooters, and the abuse was linked to extortion in at least one case.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcenews.risky.biz
Open sourcecysecurity.news
Open sourceasec.ahnlab.com
Open sourcecloud.google.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.