Surat Cyber Cell arrests two Jharkhand money mules in ₹10.65 lakh APK fraud

Share:
Audio Loading voice…
Surat Cyber Cell arrests two Jharkhand money mules in ₹10.65 lakh APK fraud

Synopsis

A ₹10.65 lakh APK-based bank fraud led Surat's Cyber Crime Cell on a 1,800 km chase to Jharkhand, where a four-day undercover operation netted two alleged money mules. Financial scrutiny of just two bank accounts has already surfaced over ₹65 lakh in suspicious transactions — revealing a layered commission-based network that stretches from Surat to Giridih.

Key Takeaways

Surat City Cyber Crime Cell arrested Ruplal Mandal, 29 , and Mukesh Mandal, 31 , both from Giridih district, Jharkhand , as alleged money mule operators.
The underlying fraud involved ₹10,65,375.98 siphoned from a victim's ICICI Bank account after a malicious APK file was installed via WhatsApp or SMS.
Investigators uncovered suspicious transactions exceeding ₹65 lakh across two mule bank accounts — one HDFC Bank (₹50.56 lakh) and one Axis Bank (₹15.22 lakh).
The arrests were part of Operation Mule Hunt , launched in December 2024 ; a four-day operation was conducted 1,800 km from Surat in Jharkhand.
Two earlier accused — Rajeshwar Swain and Jiaur Rehman — had already been arrested in Surat; other absconding accused are still being traced.

The Surat City Cyber Crime Cell has arrested two alleged money mule operators from Jharkhand in connection with an APK-based cyber fraud worth ₹10.65 lakh, with investigators uncovering suspicious transactions exceeding ₹65 lakh across bank accounts allegedly used to route cybercrime proceeds. The arrests, made after a four-day operation in Giridih district — roughly 1,800 km from Surat — mark a significant breakthrough in the city police's ongoing crackdown on interstate cybercrime networks.

How the Fraud Unfolded

The case traces back to 2 November 2024, when an unidentified fraudster allegedly gained unauthorised access to the victim's ICICI Bank account between 11 am and noon. According to police, the victim had unknowingly installed a malicious APK file received via WhatsApp or SMS, which enabled the fraudsters to intercept SMS messages, one-time passwords (OTPs), and banking credentials. A total of ₹10,65,375.98 was subsequently siphoned through multiple transactions.

A case was registered at Surat Cyber Crime Police Station under Sections 318(4), 61(2), and 3(5) of the Bharatiya Nyaya Sanhita, 2023, and Section 66(D) of the Information Technology Act, 2000.

Operation Mule Hunt: The Interstate Trail

Deputy Commissioner of Police (Cyber Cell) Bishakha Jain said the arrests were part of 'Operation Mule Hunt', launched in December 2024. Earlier in the investigation, police had arrested Rajeshwar Swain, a property broker from Surat originally from Odisha, and Jiaur Rehman, who runs a biryani shop in Surat and is originally from Uttar Pradesh. Their interrogation and technical analysis pointed investigators toward Jharkhand.

'In November 2025, the victim received an APK file through WhatsApp and SMS. After the APK was installed, the phone was hacked, and ₹10.65 lakh was transferred from the victim's account. During Operation Mule Hunt, we arrested Rajeshwar Swain and Jiaur Rehman. Based on their interrogation and technical analysis, we found that two money mule accused were located about 1,800 km away in Jharkhand,' DCP Jain said.

'Our teams remained there for nearly four days, working in different roles and using human intelligence with the assistance of local police and personnel from two police stations. We arrested both accused. The fraud amount in this case was ₹10.65 lakh, but examination of their bank accounts revealed transactions of around ₹75 lakh,' she added.

Who Was Arrested and What They Allegedly Did

The two arrested individuals have been identified as Ruplal Mandal, 29, and Mukesh Mandal, 31, both residents of Giridih district, Jharkhand. According to police, Ruplal Mandal opened two bank accounts in his name and allegedly handed over the bank kits, ATM cards, and account details to the absconding accused. He allegedly withdrew cyber fraud proceeds through ATMs and cheques, delivering the cash to other network members in exchange for a three per cent commission amounting to ₹1.52 lakh.

Mukesh Mandal allegedly served as the link between the absconding accused and account holders, reportedly making contact through Facebook. He allegedly arranged bank accounts for routing fraud proceeds, retaining four per cent of a total seven per cent commission while passing the remaining three per cent to the account holders.

Financial Trail: Transactions Across Two Accounts

A financial investigation revealed that one HDFC Bank account recorded transactions worth ₹50.56 lakh between 10 July 2025 and 13 February 2026. Of this, ₹18.58 lakh was withdrawn through ATMs in Giridih and ₹4.30 lakh through cheques. Police also found that ₹30.10 lakh in cash had been deposited into the account in Surat by previously arrested accused Jiaur Rehman, while ₹60,000 had been transferred to Mukesh Mandal's account.

A second Axis Bank account recorded transactions of ₹15.22 lakh between 7 October 2025 and 23 February 2026, of which ₹9.49 lakh was withdrawn through ATMs in Giridih. Investigators have so far flagged suspicious transactions exceeding ₹65 lakh across the two mule accounts. Efforts are continuing to arrest other absconding accused and trace the remaining financial trail.

Public Advisory

Surat City Police urged citizens not to install APK files received through unknown WhatsApp messages or SMS links, to download applications only from official app stores, never share banking credentials or OTPs with anyone, and to avoid allowing others to use their bank accounts or banking instruments in exchange for commissions. This is the latest in a series of APK-based fraud cases that have seen cybercriminals exploit messaging platforms to compromise banking access across India.

Point of View

Coordinators pocket 4%, and the actual fraudsters stay invisible behind layers of mules. What is striking is the scale: a ₹10.65 lakh victim complaint has unlocked a ₹65 lakh-plus transaction trail across just two accounts. The real network is almost certainly larger. India's cyber fraud problem is not merely technical — it is a rural livelihood crisis being exploited by organised criminal networks that recruit through Facebook and pay commissions like a franchise. Until enforcement reaches the recruiters, not just the mules, the pipeline will keep refilling.
NationPress
7 Aug 2026

Frequently Asked Questions

What is an APK-based cyber fraud and how did it work in this case?
An APK-based fraud involves tricking a victim into installing a malicious Android application file (APK) outside official app stores, which then grants fraudsters access to SMS messages, OTPs, and banking credentials. In this case, the victim received such a file via WhatsApp or SMS, and after installation, ₹10,65,375.98 was transferred from their ICICI Bank account without their knowledge.
Who are the accused arrested in Jharkhand?
The two arrested individuals are Ruplal Mandal, 29, and Mukesh Mandal, 31, both residents of Giridih district in Jharkhand. They allegedly operated as money mules — opening or arranging bank accounts to route cyber fraud proceeds and withdrawing cash in exchange for commissions.
What is Operation Mule Hunt?
Operation Mule Hunt is a Surat City Police initiative launched in December 2024 to identify and arrest individuals who provide bank accounts and financial infrastructure to cybercriminals. The operation has so far led to four arrests across Surat and Jharkhand.
How much money was traced in the investigation?
While the original fraud amounted to ₹10.65 lakh, financial scrutiny of two bank accounts linked to the accused revealed suspicious transactions exceeding ₹65 lakh — including ₹50.56 lakh through an HDFC Bank account and ₹15.22 lakh through an Axis Bank account.
How can citizens protect themselves from APK-based fraud?
Surat City Police advise the public never to install APK files received through unknown WhatsApp or SMS links, to download apps only from official stores like Google Play or the Apple App Store, never share OTPs or banking credentials, and never allow others to use their bank accounts in exchange for commissions.
Nation Press
The Trail

Connected Dots

Tracing the thread behind this story — newest first.

8 Dots
  1. Latest Yesterday
  2. 1 month ago
  3. 1 month ago
  4. 1 month ago
  5. 2 months ago
  6. 2 months ago
  7. 2 months ago
  8. 1 year ago
Google Prefer NP
On Google