NanoBaiter Profile picture
Jan 23 16 tweets 9 min read Read on X
1/ Meet Sushil Chouhan, An Indian national who owns a scam call center in New Delhi, India. He has been scamming thousands of innocent people since November 2023. Image
Image
Image
2/ I first encountered Sushil's operation when I came across this "Microsoft scam popup." It blocked my keyboard and mouse input and played an audible warning instructing me to call a toll-free number. (This is an example of the scam popup.) Don't call the number!
3/ When I called this toll-free number, I got connected to what sounded like a busy office. The person answering the phone introduced himself as a "Microsoft Certified technician." He told me that my computer was infected with a trojan virus and that I needed to connect it to a "secure server" (remote access software).Image
4/ After the scammer gained access to my virtual machine, he started the scam by showing me non-existent issues (Event Viewer) and stopped services. Once he finished the initial scam pitch, he opened a notepad file and wrote out the so-called "Support plans." Image
Image
Image
5/ The scammer thought everything was going his way, but while he was trying to scam me, I quietly worked on reversing the connection back to his computer. (This is the scammers phone system) Image
6/ This scam call center has Wi-Fi both inside and outside the building. By using the names of the wireless networks and their signal strengths relative to the scammers' computers, we can precisely determine the location of the scam call center. (28.5182833,77.2806568) Image
Image
7/ Once I reverse the connection to one computer in a scam call center, it becomes very easy for me to pivot my access onto more machines. In this case I got access to multiple desktop computers and one laptop that gave me my first ever look into Sushil's scam operation. Image
8/ On this computer they were logged into Stripe and PayPal. They mainly used Stripe to take the payments from the victims. So I exported every single transaction that has ever been initiated on that stripe account. Image
Image
Image
9/ They run multiple ad campaigns, paying for google advertisements targeting specific keywords like "best internet provider" "internet deals" etc. So they not only impersonate Microsoft but they also claim to be from big companies like DirectTV, Xfinity, Spectrum and many more. Image
Image
10/ After I gained access to all of the employees I managed to take control of Sushil's computer. On his computer I found a ton of juicy files like ID cards, Salary slips, Company registrations and even bank statements . Image
Image
11/ Sushil typically uses the laptop to manage the finances, Website domains, the phone system and even his personal bank account. Image
Image
Image
Image
12/ This is live footage of Sushil recruiting a new scammer to the team.
13/ These are photos that were downloaded directly from Sushil's cloud server. The photos from the server match perfectly with my webcam footage. Image
Image
Image
Image
14/ Photos of Sushil and his car. Image
Image
Image
15/ At some point in my investigation the scammers realized I was spying on them and they fully panicked.

Let me know if you want to see more investigations like this one posted onto X. Leave a comment if you want me to upload the full length investigation on my second channel. Thanks for reading and have a good day.

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with NanoBaiter

NanoBaiter Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @NanoBaiter

May 15
1/ This scammer is using leaked Coinbase customer data to spam out fake SMS text messages to users.

I could dox the scammer right now but I'd rather conceal his identity until he is brought to justice!

Let's give you an inside look into the scammers perspective and workflow. Image
2/ Earlier this year, my team and I noticed a massive spike in social engineering attacks mainly aimed at @coinbase and @binance users

Reddit and X were flooded with screenshots from victims targeted by these social engineering scams. Image
3/ Typical scam wording to look out for.

1. A withdrawal request was made on your account

2. Your password was reset

3. A suspicious login attempt was made on your account

The scammers will always add a sense of urgency and provide a support number telling people to contact immediately.Image
Read 14 tweets
Apr 11
1/ A few hours ago I hacked a group of crypto scammers impersonating @Coinbase Support.

These scammers drain most of their victims out of thousands of dollars!

This thread will show you how the scam works and the methods I used to trace their exact location!👇 Image
Image
Image
2/ Earlier today I started looking into new tactics that scammers use to impersonate crypto exchanges like @coinbase and @binance.

About 20 minutes in, I stumbled across a new group targeting Coinbase users— Scammers spamming fake reviews on the Chrome Web Store. Image
3/ When I called the phone number on the fake review, I got connected to someone who had an Indian sounding accent.

The person answering the phone introduced himself as a "Coinbase support representative". Image
Read 11 tweets
Feb 17
1/ Meet Pankaj Dhingra and Awadhesh Kumar Verma, both of them run a scam call center located in Noida, india. Together they have stolen $1.4M from innocent vulnerable people since November 2021. Image
Image
Image
2/ I first came across Pankaj’s and Awadhesh’s scam operation when I saw a fake Google advertisement offering printer support. At first glance, these sites look pretty harmless, but in reality, it's a big scheme to get you to pay for useless drivers or firewall security. Image
Image
Image
3/ The scammer’s website had a 'Support Chat' option that asked for my name and phone number. A few minutes later, I received a phone call from one of their so-called 'Technicians.' The person on the phone instructed me to install a remote screen-sharing software called Zoho Assist, which allowed the scammer to remotely control my computer.Image
Image
Read 15 tweets
Jan 28
1/ This is An investigation into a group of scammers who stole millions of dollars worth of cryptocurrency by impersonating the Austrian federal police. This thread will outline our efforts, which led Indian authorities to make multiple arrests and seize over $150,000. Image
Image
Image
2/ On June 12th, 2022, I received a message from my friend and fellow scambaiter @DanGleeballsYT regarding a scam call center that spams out fake, malicious phone calls to thousands of innocent people. (Actual Robocall Audio used by these scammers) Image
3/ I began my investigation by dialing the scammers 'Call Back' number that Dan provided me. I was immediately connected to someone who introduced himself as a 'Federal Police Officer.' Image
Read 25 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us!

:(