336 fake APKs, ₹125 crore fraud: Gujarat Police arrest Jamtara gang in Patna

Share:
Audio Loading voice…
336 fake APKs, ₹125 crore fraud: Gujarat Police arrest Jamtara gang in Patna

Synopsis

A single ₹5 lakh WhatsApp scam in Surat unravelled a nationwide APK supply chain: 336 malicious files, 5,613 hacked devices, and ₹125.39 crore stolen — with police chasing suspects across 2,456 km from Jamtara to Patna. And investigators have only analysed a quarter of the files so far.

Key Takeaways

Surat City Cyber Crime Cell arrested four alleged members of a Jamtara -based cyber fraud network from a hotel in Patna on 11 August .
The case began with a fake 'PNB One.APK' file sent via WhatsApp that drained ₹5 lakh from a Surat victim's account.
Investigation uncovered 336 malicious APK files linked to 31,174 installations , 5,613 compromised devices , and ₹125.39 crore in fraud — from just a quarter of the total files attributed to the main accused.
Key accused Jahur Ansari alias Chand allegedly purchased around 1,248 APK files at ₹8,000 each and resold them at ₹10,000 each to Jamtara network members.
A prior arrest in Kasganj, UP — developer Rohit — revealed 121 APK files linked to roughly ₹64.38 crore in fraud.
Police have advised the public to download apps only from official stores and to call helpline 1930 if defrauded.

The Surat City Cyber Crime Cell has arrested four alleged members of a Jamtara-based cyber fraud network from a hotel in Patna on 11 August, after tracing a fake 'PNB One.APK' file used to siphon ₹5 lakh from a Surat resident. The investigation has since uncovered 336 malicious APK files linked to 31,174 installations, 5,613 compromised devices, and cyber fraud totalling ₹125.39 crore across India.

How the Fraud Operated

The case originated from a complaint filed in May, when a victim received a fake 'PNB One.APK' file via WhatsApp. Once installed, the application silently granted the accused remote access to the device, enabling them to transfer ₹5 lakh from the victim's bank account without authorisation.

An FIR was registered at the Surat Cyber Crime Police Station under sections 318(4), 336(2), 338, 336(3), 340(2), 61(2), 3(5) of the Bharatiya Nyaya Sanhita, 2023, and sections 66(c) and 66(d) of the Information Technology Act.

The Supply Chain Behind the APKs

Technical analysis first led investigators to Uttar Pradesh, where they arrested Rohit, a resident of Kasganj district, identified as the primary APK developer. According to Additional Commissioner of Police (Crime) Karanraj Vaghela, Rohit built fake applications impersonating SBI, Punjab National Bank, Axis Bank, HDFC Bank, UCO Bank, hospitals, RTO challan portals, and customer support services on demand.

Police said analysis of Rohit's laptop and phone revealed he had developed and supplied more than 121 APK files, with associated fraud data pointing to approximately ₹64.38 crore. His interrogation led investigators to a distribution network operating out of Jamtara, Jharkhand — a district long associated with organised cyber crime in India.

The 2,456-km Chase to Patna

The Surat cyber cell team travelled approximately 1,970 km to Jamtara and conducted searches in remote areas. Technical surveillance indicated that the alleged main accused, Jahur Ansari alias Chand, 35, was travelling by train. Police tracked him from Jamtara to Deoghar and finally to Patna, covering a total of about 2,456 km by road and rail before locating the suspects at a hotel.

The four arrested accused are: Jahur Ansari alias Chand, 35, of Jamtara; Rajan Kumar, 19, of Aurangabad, Bihar; Adityaraj alias Aman, 19, of Rohtas, Bihar; and Sameer alias Shaktiman, 28, of Jamtara. Police seized six mobile phones and one laptop from the four.

Scale of the Fraud Network

Police described Chand as the network's key distribution node. He allegedly purchased around 1,248 APK files with source code from developers at approximately ₹8,000 per file and resold them to Jamtara network members for around ₹10,000 each. Rajan and Adityaraj allegedly developed and modified APK files, having learnt the process from the previously arrested developer. Sameer allegedly functioned as a technical supplier and distribution partner.

Analysis of 336 of the approximately 1,248 APK files linked to Chand revealed 1,06,643 debit transactions worth ₹1,25,39,48,187. The breakdown includes 59 fake RTO Challan files linked to 11,056 installations and ₹42.32 crore in fraud; 49 SBI files linked to 5,303 installations and ₹31.15 crore; and 37 PNB files linked to 2,548 installations and ₹10.77 crore. Fake applications also impersonated Axis Bank, Bandhan Bank, HDFC Bank, YONO, UCO Bank, PM-Kisan, Punjab and Sind Bank, City Union Bank, Canara Bank, Union Bank, and various hospitals and support services.

Once installed, these applications could access a victim's SMS messages, contacts, call logs, photo gallery, and banking credentials. Stolen funds were allegedly routed through mule bank accounts and mule credit cards before being cashed out to conceal the trail.

Police Advisory and What's Next

Vaghela confirmed that the technical team has so far analysed only 336 of the 1,248 APK files linked to Chand, suggesting the total fraud figure could rise significantly as the probe continues. Police said further investigation is under way into the financial links and other network members.

Authorities have advised the public never to install APK files received via WhatsApp, SMS, or unknown links, and to download applications exclusively from the official Google Play Store or App Store. Citizens are also warned against sharing banking credentials, ATM details, UPI PINs, net-banking passwords, or OTPs. Victims of cyber fraud are urged to call the national cybercrime helpline 1930 or report incidents at the National Cyber Crime Reporting Portal.

Point of View

Distributors, resellers, and end-users, with per-file pricing and bulk discounts. What is striking is that investigators have analysed only 336 of 1,248 files linked to a single accused, and already crossed ₹125 crore. The real figure, once the full dataset is processed, could dwarf current estimates. India's cyber crime enforcement remains reactive — triggered by individual complaints rather than proactive monitoring of malicious APK distribution on WhatsApp and Telegram, where these files circulate openly. Until platform-level interception improves, arrests like these, however impressive in their cross-state logistics, will remain a game of catch-up.
NationPress
11 Aug 2026

Frequently Asked Questions

What is the Jamtara cyber fraud gang and how were they caught?
The Jamtara gang is a Jharkhand-based cyber crime network that distributes fake banking and government-service APK files to defraud victims. The Surat City Cyber Crime Cell traced them after a victim reported losing ₹5 lakh via a fake 'PNB One.APK' file received on WhatsApp, eventually arresting four members at a hotel in Patna after a 2,456-km pursuit.
What are fake APK files and how do they steal money?
Fake APK files are malicious Android applications disguised as legitimate banking, government, or service apps. Once installed, they grant criminals access to a victim's SMS messages, contacts, banking credentials, and call logs, enabling unauthorised fund transfers to mule accounts.
How much money was stolen and how many people were affected?
Analysis of 336 APK files linked to the arrested accused revealed fraud totalling ₹125.39 crore, with 31,174 installations recorded and 5,613 devices confirmed compromised. Investigators note this covers only about a quarter of the approximately 1,248 files attributed to the main accused, Jahur Ansari alias Chand.
Who are the four accused arrested in Patna?
The four arrested are Jahur Ansari alias Chand, 35, of Jamtara; Rajan Kumar, 19, of Aurangabad, Bihar; Adityaraj alias Aman, 19, of Rohtas, Bihar; and Sameer alias Shaktiman, 28, of Jamtara. Chand is described by police as the network's primary buyer and distributor of APK files.
How can people protect themselves from fake APK scams?
Police advise downloading apps only from the official Google Play Store or Apple App Store and never installing APK files received via WhatsApp, SMS, or unknown links. Citizens should also avoid sharing banking credentials, UPI PINs, OTPs, or ATM details. Victims can call the national cybercrime helpline 1930 or report at the National Cyber Crime Reporting Portal.
Nation Press
The Trail

Connected Dots

Tracing the thread behind this story — newest first.

8 Dots
  1. Latest 3 weeks ago
  2. 3 weeks ago
  3. 1 month ago
  4. 1 month ago
  5. 1 month ago
  6. 3 months ago
  7. 3 months ago
  8. 7 months ago
Google Prefer NP
On Google