Surat cyber arrest: Jamtara-linked gang used APK fraud to steal ₹6.31 lakh
Synopsis
Key Takeaways
The Surat City Cyber Crime Cell on 4 September arrested Din Mohammad Sheikh, a 43-year-old resident of Bhestan, Surat, for allegedly helping a Jamtara-linked cyber fraud network launder money stolen through a malicious APK file. The victim lost ₹6,31,414.68 after unknowingly installing the malware, which gave fraudsters covert access to his bank accounts.
How the Fraud Unfolded
According to police, the attackers sent the victim an APK file disguised under a seemingly legitimate name. Once installed, the malware harvested sensitive data from the victim's phone — including SMS messages and OTPs — enabling the accused to execute approximately eight unauthorised transactions from the complainant's bank account without his knowledge. The victim subsequently contacted the Cyber Crime Helpline (1930), prompting the Surat Cyber Crime Cell to launch a formal investigation.
Sheikh's Role: Mule Accounts and a 10% Cut
Investigators found that Sheikh — originally from Jowla village in Budhana tehsil of Muzaffarnagar district, Uttar Pradesh, and described by police as 'unemployed' at the time of arrest — provided his Axis Bank and Canara Bank credit cards to settle bills linked to the fraudulent funds. Police said ₹2,28,226.68 of the stolen money was routed through these two cards.
Deputy Commissioner of Police (Cyber Cell) Bishakha Jain said Sheikh allegedly converted the amount into cash after using the cards for bill settlements, retained 10 per cent as commission, and transferred the remaining funds to an absconding co-accused. That money was then deposited into personal bank accounts allegedly associated with the Jamtara-based network via cash deposit machines.
Jamtara Connection and Ongoing Manhunt
The trail leads to an absconding main accused believed to be operating from Jamtara in Jharkhand — a district that has become synonymous with organised cyber fraud in India. 'At present, the investigation in this direction is continuing to reach the main accused, who is in Jamtara,' Jain said. A team headed by Police Inspector V.D. Mandora is conducting technical surveillance to track the remaining suspects.
An FIR has been registered at the Cyber Crime Police Station under Sections 318(4), 336(2), 338, 336(3), 340(2), 61(2) and 3(5) of the Bharatiya Nyaya Sanhita, 2023, along with Section 66(D) of the Information Technology Act, 2008.
The APK Scam Playbook
Jain warned that such malicious files are routinely circulated under the guise of traffic challans, bank KYC updates, insurance policy documents, or other everyday services. 'Once a victim clicked on and installed such a file, sensitive information from the phone, including SMS messages, could be accessed and forwarded. The accused could then obtain OTPs and use internet banking to transfer money from the victim's account,' she explained.
She urged citizens not to install or click on any APK file received through social media, especially from unknown numbers, and to immediately alert local police and block the sender. This case is part of a broader pattern of APK-based cyber fraud that Surat police have been investigating, in which malicious applications are used to compromise mobile phones and facilitate unauthorised financial transfers.