Airtel Email - Cyber Swachh - System infected with malware Detected by govt CERT-IN

  • Thread starter Thread starter Smh
  • Start date Start date
  • Replies Replies 15
  • Views Views 7,172

Smh

Messages
3,530
Location
Delhi-Hyderadbad
ISP
Local-
ACT-
AirtelFiber
Just got this scary email WTF.

Some other users have also reported they got these emails. I have checked it is real email sent by airtel.com and very sure none of my devices are infected. It could be the NAT ip shared among many users or some false detection because idk how they detect these.

Reddit post is not mine but its exactly same issue.

 
In typical Airtel "Premium Brand" fashion...
But really how's this even possible?
Any backdoor in their ONT's/OLT's?
 
These emails are very generic template. No info about who reported or how they came to this conclusion. Just scan your devices.

How anyone is supposed to find if their devices are really infected.

It could be their cheap router or they are sending spam emails.

Or it could be google reporting to govt and govt to Airtel then airtel. My last IP was triggering robot checks in incognito mode but that's very common because of NAT issue.

Waking up and seeing this email makes you panic a bit.
 
UwAwMtC.webp


Dear Customer,
We have been informed by CERT-IN that your device is infected by bot/malware.
Please follow the below mentioned steps as advised by CERT-IN:
1. Install and maintain updated anti-virus and anti-spyware software at desktop level.
2. Scan computer system with updated anti-virus for possible infections and disinfect the same.
3. Install and maintain personal desktop firewall.
4. Check for the suspicious network activities of infected computer system mentioned in list and disinfect the same if found.
5. Use only genuine software.
6. Keep up-to-date patches and fixes on the operating system and application software.
7. Exercise caution while opening email attachments.
8. Do not browse un-trusted websites or follow un-trusted links and exercise caution while click on the link provided in any unsolicited emails.
For further remedial measures please visit Cyber Swachhta Kendra or
In case of further queries please write to incident@cert-in.org.in or info@cert-in.org.in.
Bharti Airtel
Cyber Swachhta

email headers:
From: Cyberswachhta <cyberswachhta@airtel.com>
To: xxxx
Subject: Important information: System infected with malware
SPF: PASS with IP 182.66.239.3
DKIM: 'PASS' with domain airtel.com
DMARC: 'PASS' Learn more


screenshot and full message.
 
Last edited by a moderator:
I knew about this old message but the wordings of this message is scary. Like they are sure malware is present in my system.

And this is the first time I received this message from any isp.

Hope this is generic bs.
 
This is more of an a advisory note and could be based on anomalous behavior observed from the IP currently assigned to you. If it is DHCP then it may have been another machine that caused the issue and if this IP is static and is assigned to you need to be careful. Scan your machine with a good AV just to be sure, it is essential to be wary of cracks, keygens etc they can contain trojans or worse.
 
Message is also very outdated. Most people currently are scammed on mobile through social engineering.
 
Back