Lushai Dev.
Back to Articles.
Platform Security

Security Advisory: Cyber Attack Thwarted — Hacker Identified & Permanently Blacklisted (Anurag Dubey)

Ethan Zosangkima
5 min read
89 views
Security Advisory: Cyber Attack Thwarted — Hacker Identified & Permanently Blacklisted (Anurag Dubey)

🚨 Official Security Advisory: Cyber Attack Thwarted & Threat Actor Disclosed

Incident Identifier: SEC-ADV-20261008-WAPI-EXPOSURE Publication Date: October 8, 2026 Incident Severity: Moderate / Neutralized Author: Ethan Zosangkima, Founder & Lead Software Architect


1. Executive Summary & Incident Timeline

On October 8, 2026, between 12:48 PM IST and 12:56 PM IST (07:18 UTC to 07:26 UTC), automated security telemetry on the Lushai.dev WAPI (WhatsApp Gateway) detected unauthorized intrusion attempts and malicious credential probes originating from an Indian mobile internet subscriber.

Our automated defense layers, zero-trust database checks, and real-time firewall engines intercepted the attempt. No customer databases, personal messages, or payment channels were compromised.

Following comprehensive correlation across our cloud access logs, the offender has been conclusively unmasked as Anurag Dubey, a repeat threat actor previously flagged for fraudulent price manipulation activity.


2. Threat Actor Identification & Forensic Profile

Our digital forensics unit has assembled the following verified technical identity:

| Forensic Parameter | Verified Intelligence | | :--- | :--- | | Legal Subject Name | Anurag Dubey | | Operational Aliases | \crazy\, \tech\, \bhybghj\ (User ID #8 on ProlificSMM) | | Primary Registered Mobile | +91 9702974993 (Mumbai / Maharashtra Circle) | | Secondary Support Mobile | +91 7300404217 (North India / UP West Circle) | | Malicious Burner Email | anonmoys21@gmail.com | | Linked Primary Email | arpitdubey20222@gmail.com | | Associated Scam Endeavor | \freesmmpanels.online\ & WhatsApp Channel \Social Blast SMM\ |


3. Network Telemetry & Telecom Carrier Verification

The attacks were routed through high-speed Indian mobile infrastructure:

  • Source IP Address: \2409:4090:f051:2204:25c4:7f04:b036:ff32\
  • IPv6 Subnet Block: \2409:4090:f051:2204::/64\ (part of Reliance Jio \2409:4090::/32\)
  • Internet Service Provider: Reliance Jio Infocomm Limited
  • Connection Type: Jio 5G / 4G Mobile Data
  • Telecom Circle: Mumbai / Maharashtra, India
  • Recorded Attack Window: 2026-10-08 07:18:13 UTC to 2026-10-08 07:26:46 UTC

4. Modus Operandi & Malicious Intent

The attacker sought to abuse Lushai.dev WAPI infrastructure to automate illicit promotional blasts for a low-reputation Social Media Marketing (SMM) bot scheme:

  1. Burner Registration: Registered on WAPI using \anonmoys21@gmail.com\ and phone \+91 9702974993\.
  2. Channel Provisioning: Established WhatsApp channels (\Social Blast SMM\) advertising illegitimate engagement services:
  3. Gateway Probe: Attempted to exploit API endpoints to blast messages without valid authorization tokens.
  4. Synchronous Reconnaissance: Within minutes, sent unsolicited chat pings (\hii\) to admin portals from the exact same Reliance Jio IP address.

5. Defensive Countermeasures & Engineering Remediation

  1. Real-Time Network Firewall Enforcement:
  2. Global Blacklist Synchronizer:
  3. Strict Zero-Trust Architecture:

6. Official Advisory & Legal Disclosure

Lushai Dev maintains a Zero-Tolerance Policy against cyber attacks, platform abuse, and unauthorized intrusions:

  • Consumers and developers are warned not to conduct financial transactions with phone numbers \+91 9702974993\ or \+91 7300404217\.
  • All digital telemetry, timestamps, and network artifacts have been compiled into a formal evidentiary dossier for submission under the Information Technology Act, 2000 (Sections 43, 66, 66C, 66D) and Bharatiya Nyaya Sanhita (BNS) Section 318.
Published by Ethan Zosangkima

Engineering and technical publication desk at Lushai Dev, Lunglei, Mizoram.

More Publications.
HomeAPIs & DocsPricingToolsAccount