🚨 OFFICIAL CYBERSECURITY DISCLOSURE & PUBLIC FRAUD NOTICE
Report Status: Active Security Advisory & Public Alert
Incident Reference: CC-ALERT-ANURAG-DUBEY-20261008
Applicable Legal Sections: Information Technology Act, 2000 (Sections 43, 66, 66C, 66D) & Bharatiya Nyaya Sanhita (BNS) Section 318 (Cheating / IPC 420)
1. Perpetrator Identification Details
Through comprehensive digital forensic analysis, network telemetry, and cross-platform verification across our ecosystem (CeeProlific Store, Lushai.dev WAPI, and ProlificSMM), the threat actor responsible for malicious activities has been decisively identified:
| Forensic Parameter | Identification Data |
|---|---|
| Full Legal Name | Anurag Dubey |
| Known Aliases | \crazy\, \tech\, \bhybghj\ (User ID #8) |
| Primary Registered Mobile | +91 9702974993 (Mumbai / Maharashtra Circle) |
| Secondary Support Mobile | +91 7300404217 (North India / UP West Circle) |
| Primary Email Address | anonmoys21@gmail.com |
| Associated Email Address | arpitdubey20222@gmail.com |
| Affiliated Fraud / Bot Ventures | \freesmmpanels.online\ / \Social Blast SMM\ |
2. Network Telemetry & Geolocation Trace
The perpetrator carried out unauthorized intrusions and system probe requests originating from mobile telecom infrastructure in India:
- Attacker IP Address: \
2409:4090:f051:2204:25c4:7f04:b036:ff32\ - Subnet Allocation: \
2409:4090::/32\(/64 dynamic host range) - Internet Service Provider (ISP): Reliance Jio Infocomm Limited
- Connection Type: Jio 5G / 4G Mobile Internet
- Geographic Circle: Mumbai, Maharashtra, India
- Recorded Attack Timestamps: October 8, 2026 at 12:48 PM IST to 12:56 PM IST (07:18:13 UTC to 07:26:46 UTC)
3. Attack Methodology & Modus Operandi
The perpetrator has engaged in a repeated pattern of malicious activity targeting our digital platforms:
- 1E-Commerce Exploitation & Price Manipulation (October 7, 2026):
Using account \arpitdubey20222@gmail.com\, the suspect manipulated payment gateway payloads attempting to illicitly acquire software source code packages.
- 1API Intrusion & Gateway Abuse (October 8, 2026):
Using burner alias \anonmoys21@gmail.com\ and registered phone \+91 9702974993\, the perpetrator attempted unauthorized access on the Lushai.dev WhatsApp B2B Gateway to hijack messaging channels for an illegal SMM follower boosting scheme (\Social Blast SMM\).
- 1Concurrently Pinging Systems:
Within minutes of registration, the suspect pinged live chat sessions on ProlificSMM using nickname \bhybghj\ from the exact same Reliance Jio IPv6 address.
4. Associated Illicit Business & Scammer Copy
The following promotional text was extracted directly from the channels established by the attacker:
*"📱✨ Followers • Likes • Views • Subscribers all at one place!
🚀 Boost your social media without any tension!
💥 100% Real & Instant Delivery ✅
🌐 Visit Now: freesmmpanels.online
🛒 Services: Instagram | YouTube | Facebook | Telegram | More
💸 Starting ₹5 Only | Auto & Manual Payment Available
📞 Contact WhatsApp: 9702974993, 7300404217
🔥 Trusted by 1500+ Users | Fast Support Available!"*
5. Security Countermeasures Deployed
Our engineering team has taken the following immediate technical and defensive actions:
- 1Permanent Network Firewall Rule:
IP \2409:4090:f051:2204:25c4:7f04:b036:ff32\ and the entire \2409:4090:f051:2204::/64\ prefix have been blocked at the network perimeter with automated socket termination (\403 Forbidden\).
- 1Global Blacklist Enforcement:
All accounts, phone numbers (+91 9702974993, +91 7300404217), and associated email addresses have been blacklisted permanently across all database clusters.
- 1Architecture Hardening:
All API endpoints and session ownership verification layers have been strengthened with zero-trust database authentication.
6. Official Advisory to the Public
We urge all developers, business owners, and consumers to exercise extreme vigilance:
- Do not engage with \
freesmmpanels.online\or any services operating under \Social Blast SMM\. - Do not conduct transactions with phone numbers \
+91 9702974993\or \+91 7300404217\. - All digital evidence, server logs, and IP telecommunication records have been documented for submission to the National Cyber Crime Reporting Portal (cybercrime.gov.in).

