Four Teenagers
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor known as “Four Teenagers” operated primarily from India, with arrests made in Delhi and Gurgaon. The group consisted of four individuals, including a BTech dropout identified as Sunny Nehra who was described as the alleged mastermind, another BTech dropout, an engineering student, and a BCA graduate from Delhi University. They were apprehended by Delhi police in January 2017 after a complaint from the administrators of gyftr.com regarding the loss of vouchers valued at Rs92 lakh. The alias reflects their youth and the small size of the crew, and their location is confined to the national capital region based on the police investigation and the hotels where they were staying.
Their activities focused on exploiting e‑commerce payment gateways to commit financial fraud, specifically by tampering with voucher values during the transaction process. The actors targeted online voucher platforms such as gyftr.com and subsequently used the altered vouchers on major Indian e‑commerce sites including MakeMyTrip, Flipkart, Amazon, Dominos Pizza, Myntra and Shoppers Stop. Their strategic objective was monetary gain, as evidenced by the theft of high‑value vouchers, the purchase of goods and services with those vouchers, and their public display of a lavish lifestyle through hired luxury vehicles and discounted electronics offered to friends. No indications of espionage, disruption or state sponsorship appear in the reported details.
The group’s tactics involved obtaining credit or debit cards fabricated with false documents, initiating a purchase on the voucher site, and then using the PayU payment gateway where they pressed the cancel button to freeze the processing page. At that point they modified transaction parameters—such as reducing a Rs5,000 voucher to Re1—before allowing the payment to complete, a technique they had rehearsed after analyzing the gateway’s source code. They employed specialized hacking software and reportedly used a Dell laptop equipped with 256 GB of RAM to run their tools. Their capabilities were bolstered by training received from professional hackers linked to India, the Netherlands and Indonesia, indicating a loose collaborative network rather than a formal state‑affiliated unit. The operation culminated in the fraudulent acquisition and use of vouchers worth Rs92 lakh, which led to the seizure of iPhones and iPads purchased with the illicit funds; tracing the IP addresses of those devices to a Facebook profile facilitated the police raid on the Gurgaon hotel where the suspects were apprehended.
Incidents
Attributed incidents are available to members.
0 incidents