Surat cyber arrest: Jamtara-linked gang used APK fraud to steal ₹6.31 lakh

Share:
Audio Loading voice…
Surat cyber arrest: Jamtara-linked gang used APK fraud to steal ₹6.31 lakh

Synopsis

A Surat man allegedly served as a cash mule for a Jamtara-linked cyber gang that stole ₹6.31 lakh by disguising malware as routine APK files — harvesting OTPs and draining bank accounts silently. The arrest exposes a well-worn playbook: distant operators, local mules, and cash deposit machines to clean the trail.

Key Takeaways

Din Mohammad Sheikh , 43, was arrested by the Surat City Cyber Crime Cell on 4 September for allegedly laundering proceeds of an APK-based cyber fraud.
The victim lost ₹6,31,414.68 after installing a malicious APK file that gave fraudsters access to his phone's SMS and OTPs.
Sheikh allegedly used his Axis Bank and Canara Bank credit cards to route ₹2,28,226.68 of stolen funds, retaining 10% as commission.
Remaining funds were transferred to accounts linked to a Jamtara -based gang via cash deposit machines; the main accused remains at large.
An FIR has been filed under the Bharatiya Nyaya Sanhita, 2023 and Section 66(D) of the IT Act, 2008 .
Police warn that such APK files are disguised as traffic challans, bank KYC updates, or insurance documents — citizens are advised not to install files from unknown sources.

The Surat City Cyber Crime Cell on 4 September arrested Din Mohammad Sheikh, a 43-year-old resident of Bhestan, Surat, for allegedly helping a Jamtara-linked cyber fraud network launder money stolen through a malicious APK file. The victim lost ₹6,31,414.68 after unknowingly installing the malware, which gave fraudsters covert access to his bank accounts.

How the Fraud Unfolded

According to police, the attackers sent the victim an APK file disguised under a seemingly legitimate name. Once installed, the malware harvested sensitive data from the victim's phone — including SMS messages and OTPs — enabling the accused to execute approximately eight unauthorised transactions from the complainant's bank account without his knowledge. The victim subsequently contacted the Cyber Crime Helpline (1930), prompting the Surat Cyber Crime Cell to launch a formal investigation.

Sheikh's Role: Mule Accounts and a 10% Cut

Investigators found that Sheikh — originally from Jowla village in Budhana tehsil of Muzaffarnagar district, Uttar Pradesh, and described by police as 'unemployed' at the time of arrest — provided his Axis Bank and Canara Bank credit cards to settle bills linked to the fraudulent funds. Police said ₹2,28,226.68 of the stolen money was routed through these two cards.

Deputy Commissioner of Police (Cyber Cell) Bishakha Jain said Sheikh allegedly converted the amount into cash after using the cards for bill settlements, retained 10 per cent as commission, and transferred the remaining funds to an absconding co-accused. That money was then deposited into personal bank accounts allegedly associated with the Jamtara-based network via cash deposit machines.

Jamtara Connection and Ongoing Manhunt

The trail leads to an absconding main accused believed to be operating from Jamtara in Jharkhand — a district that has become synonymous with organised cyber fraud in India. 'At present, the investigation in this direction is continuing to reach the main accused, who is in Jamtara,' Jain said. A team headed by Police Inspector V.D. Mandora is conducting technical surveillance to track the remaining suspects.

An FIR has been registered at the Cyber Crime Police Station under Sections 318(4), 336(2), 338, 336(3), 340(2), 61(2) and 3(5) of the Bharatiya Nyaya Sanhita, 2023, along with Section 66(D) of the Information Technology Act, 2008.

The APK Scam Playbook

Jain warned that such malicious files are routinely circulated under the guise of traffic challans, bank KYC updates, insurance policy documents, or other everyday services. 'Once a victim clicked on and installed such a file, sensitive information from the phone, including SMS messages, could be accessed and forwarded. The accused could then obtain OTPs and use internet banking to transfer money from the victim's account,' she explained.

She urged citizens not to install or click on any APK file received through social media, especially from unknown numbers, and to immediately alert local police and block the sender. This case is part of a broader pattern of APK-based cyber fraud that Surat police have been investigating, in which malicious applications are used to compromise mobile phones and facilitate unauthorised financial transfers.

Point of View

A local mule provides the financial plumbing, and cash deposit machines erase the paper trail. What is striking is how little the playbook has changed — APK-disguised malware, OTP harvesting, and commission-based mules have been documented for years, yet the fraud pipeline keeps running. The 10% mule commission also signals a commoditised criminal economy where complicity is cheap. Until telecom and banking regulators enforce real-time anomaly detection on bulk OTP requests and credit card bill settlements from flagged accounts, arrests like Sheikh's will remain downstream interventions that leave the network intact.
NationPress
4 Sept 2026

Frequently Asked Questions

What is the APK file fraud that led to the Surat arrest?
The fraud involved sending victims a malicious APK file disguised as a routine document — such as a traffic challan or bank KYC update. Once installed, the file harvested SMS messages and OTPs from the victim's phone, allowing fraudsters to transfer money from the victim's bank account without authorisation.
Who is Din Mohammad Sheikh and what was his alleged role?
Din Mohammad Sheikh is a 43-year-old resident of Bhestan, Surat, originally from Muzaffarnagar, Uttar Pradesh. He allegedly provided his Axis Bank and Canara Bank credit cards to launder ₹2,28,226.68 of stolen funds, converted the money to cash, kept a 10% commission, and passed the rest to an absconding co-accused linked to the Jamtara gang.
How much money did the victim lose and how was it stolen?
The victim lost ₹6,31,414.68 after installing a malicious APK file that gave the accused covert access to his bank account. Approximately eight unauthorised transactions were carried out without the victim's knowledge.
What is the Jamtara connection in this case?
Jamtara, a district in Jharkhand, has become associated with organised cyber fraud networks in India. In this case, the stolen funds were ultimately routed to bank accounts allegedly linked to a Jamtara-based gang. The main accused is believed to be in Jamtara and remains at large as of the date of the arrest.
How can people protect themselves from APK-based fraud?
Police advise citizens never to install or click on APK files received through social media, especially from unknown numbers. If such a file is received, the sender's number should be blocked immediately and local police should be informed. Calls can also be made to the Cyber Crime Helpline at 1930.
Nation Press
The Trail

Connected Dots

Tracing the thread behind this story — newest first.

8 Dots
  1. Latest 6 days ago
  2. 3 weeks ago
  3. 3 weeks ago
  4. 3 weeks ago
  5. 1 month ago
  6. 3 months ago
  7. 1 year ago
  8. 1 year ago
Google Prefer NP
On Google