336 fake APKs, ₹125 crore fraud: Gujarat Police arrest Jamtara gang in Patna
Synopsis
Key Takeaways
The Surat City Cyber Crime Cell has arrested four alleged members of a Jamtara-based cyber fraud network from a hotel in Patna on 11 August, after tracing a fake 'PNB One.APK' file used to siphon ₹5 lakh from a Surat resident. The investigation has since uncovered 336 malicious APK files linked to 31,174 installations, 5,613 compromised devices, and cyber fraud totalling ₹125.39 crore across India.
How the Fraud Operated
The case originated from a complaint filed in May, when a victim received a fake 'PNB One.APK' file via WhatsApp. Once installed, the application silently granted the accused remote access to the device, enabling them to transfer ₹5 lakh from the victim's bank account without authorisation.
An FIR was registered at the Surat Cyber Crime Police Station under sections 318(4), 336(2), 338, 336(3), 340(2), 61(2), 3(5) of the Bharatiya Nyaya Sanhita, 2023, and sections 66(c) and 66(d) of the Information Technology Act.
The Supply Chain Behind the APKs
Technical analysis first led investigators to Uttar Pradesh, where they arrested Rohit, a resident of Kasganj district, identified as the primary APK developer. According to Additional Commissioner of Police (Crime) Karanraj Vaghela, Rohit built fake applications impersonating SBI, Punjab National Bank, Axis Bank, HDFC Bank, UCO Bank, hospitals, RTO challan portals, and customer support services on demand.
Police said analysis of Rohit's laptop and phone revealed he had developed and supplied more than 121 APK files, with associated fraud data pointing to approximately ₹64.38 crore. His interrogation led investigators to a distribution network operating out of Jamtara, Jharkhand — a district long associated with organised cyber crime in India.
The 2,456-km Chase to Patna
The Surat cyber cell team travelled approximately 1,970 km to Jamtara and conducted searches in remote areas. Technical surveillance indicated that the alleged main accused, Jahur Ansari alias Chand, 35, was travelling by train. Police tracked him from Jamtara to Deoghar and finally to Patna, covering a total of about 2,456 km by road and rail before locating the suspects at a hotel.
The four arrested accused are: Jahur Ansari alias Chand, 35, of Jamtara; Rajan Kumar, 19, of Aurangabad, Bihar; Adityaraj alias Aman, 19, of Rohtas, Bihar; and Sameer alias Shaktiman, 28, of Jamtara. Police seized six mobile phones and one laptop from the four.
Scale of the Fraud Network
Police described Chand as the network's key distribution node. He allegedly purchased around 1,248 APK files with source code from developers at approximately ₹8,000 per file and resold them to Jamtara network members for around ₹10,000 each. Rajan and Adityaraj allegedly developed and modified APK files, having learnt the process from the previously arrested developer. Sameer allegedly functioned as a technical supplier and distribution partner.
Analysis of 336 of the approximately 1,248 APK files linked to Chand revealed 1,06,643 debit transactions worth ₹1,25,39,48,187. The breakdown includes 59 fake RTO Challan files linked to 11,056 installations and ₹42.32 crore in fraud; 49 SBI files linked to 5,303 installations and ₹31.15 crore; and 37 PNB files linked to 2,548 installations and ₹10.77 crore. Fake applications also impersonated Axis Bank, Bandhan Bank, HDFC Bank, YONO, UCO Bank, PM-Kisan, Punjab and Sind Bank, City Union Bank, Canara Bank, Union Bank, and various hospitals and support services.
Once installed, these applications could access a victim's SMS messages, contacts, call logs, photo gallery, and banking credentials. Stolen funds were allegedly routed through mule bank accounts and mule credit cards before being cashed out to conceal the trail.
Police Advisory and What's Next
Vaghela confirmed that the technical team has so far analysed only 336 of the 1,248 APK files linked to Chand, suggesting the total fraud figure could rise significantly as the probe continues. Police said further investigation is under way into the financial links and other network members.
Authorities have advised the public never to install APK files received via WhatsApp, SMS, or unknown links, and to download applications exclusively from the official Google Play Store or App Store. Citizens are also warned against sharing banking credentials, ATM details, UPI PINs, net-banking passwords, or OTPs. Victims of cyber fraud are urged to call the national cybercrime helpline 1930 or report incidents at the National Cyber Crime Reporting Portal.