New Delhi: At 9:25 a.m. on 10 September, the Gandhinagar district court received an email threatening blasts at Pragati Maidan amid the BRICS summit. Twelve minutes on, another menacing message was sent to the Department of Legislative and Parliamentary Affairs targeting the Gujarat Assembly, the CMO, top central leadership, and nations supporting India at BRICS.
The threats sent from ‘mortonrenisch73@gmail.com’ and ‘jondmoragn52627@gmail.com’ were among a batch of emails delivered to government buildings, schools, colleges, and court premises across Gujarat.
Probe led Gujarat Police’s Cyber Center of Excellence (CCoE) to a mind-boggling trove of 5,13,847 unique email IDs and passwords as well as the arrest of two suspects from Bihar and Jharkhand.
The supects—Roshan Kumar Bhumihar arrested in Bhagalpur and Gulshan in Deoghar—allegedly activated and accessed these accounts using VPNs.
What was alarming for the investigators was the network’s trans-border reach with the handlers allegedly having links to Bangladesh and using crypto currency wallets for carrying out the act.
The two suspects
A senior police officer with CCoE told ThePrint that they began looking into digital forensics, including the IP addresses from where the emails were sent. “The investigation revealed that the accused who sent the email threatening to blow up the secretariat with a bomb, was arrested from Bhagalpur. The prima facie motive so far is monetary gains.”
Meanwhile, the officer said, the alleged mastermind of 5 lakh-plus email IDs and passwords for bomb threats was arrested from Deoghar.
Rai, a 12th-grade graduate working as a freelance website developer, directly operated the account (jondmoragn52627@gmail.com) used to send the threat emails to Gujarat officials, the officer said.
Gulshan, according to the officer, had been operating in the digital marketing business. “He had been generating mass email IDs since 2022. He served as the primary supplier who provided Roshan with the ready-to-use accounts.”
During the raids, investigators found the physical devices used to transmit the threats, alongside a database containing the unique email IDs and passwords.
‘Bangladeshi’ links, crypto wallets
The CCoE’s investigation reveals that the primary motive behind creating more than 5 lakh email accounts was monetary gain, “and backed by supporting anti-national cyber campaigns.”
“The accused were well-versed with technology. They remained in touch with handlers in Bangladesh. The entire network has been found to be receiving financial support and guidance from Bangladesh. Crypto wallets have also been found to be used for this purpose,” the above-mentioned officer said.
Investigation found that the accused would allegedly share the Google Sheets and Excel documents of every single email ID and password with his contact in Bangladesh. “So far, we have managed to find data of over 10,000 USDT. However, there are multiple other crypto wallets, so the amount is a lot.”
A digital token that acts like a digital dollar, USDT or Tether is not an official government-issued legal money.
“To bypass security protocols, Gulshan bypassed two-factor authentication and Google Authenticator systems, he would configure the accounts so that OTPs were routed away from mobile numbers,” the officer said, explaining the modus operandi of the two accused.
“They then activated and accessed these accounts using VPNs to obscure their locations.”
(Edited by Tony Rai)
Also Read: Ankit Baliyan sang of guns & gangs. ‘Moosewala-like’ killing leaves Shamli asking ‘why him?’
