DESCAM Logo

DESCAM

System Initialized
Core Value“Nation first, always first.” Every student we train and every school we protect is a step toward a safer, self-reliant digital India.
DESCAM Security Research Lab & Threat Intelligence

Defensive Intelligence & Field Reports

Practical threat analyses, digital forensics investigations, and hands-on laboratory architectures authored by cybersecurity researchers protecting Indian infrastructure.

6
Research Dossiers
51+
Min Total Intel
100%
Hands-On & Open
0%
Rote Fluff
Filter Tags:
★ Featured DossierCase Study

The ₹30,000-Crore Pipeline: How a Single 'Digital Arrest' Scam Exposed India's Industrial-Scale Money Laundering Machine

// From a ₹2.60-crore cyber extortion in Goa to an international syndicate moving ₹27,850 crore across 400 layered accounts and automated cash kiosks.

An investigation by the Directorate of Enforcement (ED) into a digital arrest case in Goa has uncovered an underground money-laundering ecosystem executing over ₹27,850 crore in transactions across 20 States and Union Territories.

DESCAM Research Team30 Aug 20267 min readInvestigation Scope: ₹27,850 Cr

All Research Papers & Articles

6 Articles
Case Study

The ₹30,000-Crore Pipeline: How a Single 'Digital Arrest' Scam Exposed India's Industrial-Scale Money Laundering Machine

An investigation by the Directorate of Enforcement (ED) into a digital arrest case in Goa has uncovered an underground money-laundering ecosystem executing over ₹27,850 crore in transactions across 20 States and Union Territories.

30 Aug 20267 min read
Read
Threat Intelligence

Reverse-Proxy Phishing: Bypassing SMS OTP & Session Hijacking in Indian Banking Portals

Traditional SMS-based 2FA is no longer sufficient against AitM (Adversary-in-the-Middle) phishing campaigns. Learn how transparent proxying captures live session cookies and how FIDO2 WebAuthn provides origin-bound cryptographic protection.

25 Aug 20269 min read
Read
Application Security

Dissecting BOLA & Broken Object Level Authorization in Enterprise REST APIs

Broken Object Level Authorization (BOLA/IDOR) allows malicious actors to access, manipulate, or delete arbitrary customer records simply by manipulating IDs in REST parameters. Here is the technical breakdown and defense blueprint.

20 Aug 20268 min read
Read
Scam Analysis

The Anatomy of Mule Account Supply Chains: Exploiting Unmanned Cash Deposit Kiosks

How threat actors weaponize ATM cash deposit machines, fake current account documentation, and digital banking credentials to defeat fraud monitoring in financial institutions.

15 Aug 20266 min read
Read
Guides

Cloud Incident Response & Immutable WORM Backups: Neutralizing Double Extortion

Modern ransomware strains explicitly target cloud backups and shadow copies before encrypting production nodes. Learn how to architect air-gapped immutable storage under the 3-2-1-1-0 backup rule.

10 Aug 202611 min read
Read
Education

Zero Trust Network Access (ZTNA) vs Legacy IPsec VPNs: The Architecture Paradigm Shift

In a post-perimeter enterprise world, connecting a remote employee via VPN is equivalent to placing their laptop directly into your core server room. Explore the architectural migration to identity-aware Zero Trust proxies.

5 Aug 202610 min read
Read
Interactive Diagnostic

Check Your Enterprise & Personal Cyber Resilience

Step 0 of 3 Answered
1

How does your organization protect against SMS OTP reverse-proxy phishing attacks?

2

What is your backup retention policy against modern ransomware with shadow copy wipers?

3

How do your developers prevent Broken Object Level Authorization (BOLA) in REST APIs?

DESCAM Threat Intelligence Dispatch

Direct Security Advisories in Your Inbox

Zero marketing noise. Only technical threat bulletins, zero-day mitigation playbooks, and student laboratory setups delivered bi-weekly.

🔒 Zero-Knowledge Privacy🚫 No Promotional Spam⚡ 1-Click Unsubscribe