Gujarat Police arrest UP teen who built APK tools for Jamtara cyber gangs
Synopsis
Key Takeaways
The Surat City Cyber Crime Cell on Monday, 20 July arrested an 18-year-old Android application developer from Uttar Pradesh for allegedly creating malicious APK files that mimicked legitimate banking and service apps, enabling cybercrime syndicates based in Jamtara, Jharkhand to defraud victims across India of an estimated ₹64.38 crore. The accused, identified as Rohit Sakai, a resident of Patiali tehsil, Kasganj district in Uttar Pradesh, was traced to a hotel in Kanpur through technical surveillance and arrested in a coordinated operation.
How the Fraud Network Operated
According to police, Sakai — who studied only up to Class 11 — allegedly developed and sold APK files to multiple Jamtara-based cybercrime gangs, charging between ₹10,000 and ₹15,000 per application for one month's use, with renewal fees levied thereafter. Investigators allege he developed 121 different APK files in total, which were sold to various gang members and circulated primarily via WhatsApp and Telegram.
Police explained the alleged modus operandi: two Android applications were developed per operation. The first was distributed to potential victims to compromise their devices; the second allowed gang members to remotely access the hacked phones. Gang leaders allegedly trained members to distribute the apps through messaging platforms.
Scale of the Alleged Operation
Investigators claimed the 121 APK files were installed on 21,672 mobile devices across India, of which 2,928 were allegedly compromised after attackers gained unauthorised access. The operation is estimated to have resulted in 54,094 fraudulent debit transactions amounting to ₹64,38,48,837.60 (approximately ₹64.38 crore).
Police released a category-wise breakdown. 27 RTO Challan APKs were installed on 5,308 devices, compromising 1,202 of them and generating 34,486 debit transactions linked to alleged fraud of ₹27.82 crore. 13 SBI APKs were installed on 2,465 devices, with 323 compromised and losses estimated at ₹14.34 crore. 14 PNB APKs were installed on 3,362 devices, compromising 441 and causing alleged losses of ₹7.16 crore. The accused also allegedly developed APKs impersonating Axis Bank, American Express, BigBasket, UCO Bank, HSBC, Bandhan Bank, Union Bank, ICICI Bank, IndusInd Bank, City Union Bank, Federal Bank, CAMPA, Zepto, DMart, PM Kisan, and hospital and customer support services.
The Trigger: A Fake PNB App on WhatsApp
The case originated from a complaint filed after a victim received a file named 'PNB One.apk' on WhatsApp on 15 May. Once downloaded, the file allegedly granted attackers unauthorised access to the victim's device. Investigators said the accused and his associates then accessed the victim's Prime Co-operative Bank account and transferred ₹5 lakh to a Union Bank of India account without the complainant's knowledge.
The victim subsequently contacted the National Cyber Crime Helpline, prompting the Cyber Crime Cell to investigate. Technical analysis identified Sakai as the developer of the file and traced him to Kanpur.
How Victims Were Targeted
The fake applications used the names, logos, and icons of banks and well-known organisations to appear genuine. Victims were prompted to enter banking and Know Your Customer (KYC) details, while the apps allegedly captured SMS messages, contacts, call logs, and photographs stored on the devices. Once banking credentials were obtained, funds were transferred to mule bank accounts or credit cards, converted to cash, and deposited through Cash Deposit Machines (CDMs) to conceal the identities of gang members.
Charges and Seizures
A case has been registered under Sections 318(4), 336(2), 338, 336(3), 340(2), 61(2), and 3(5) of the Bharatiya Nyaya Sanhita, 2023, along with Sections 66(C) and 66(D) of the Information Technology (Amendment) Act, 2008. Police seized two mobile phones and one laptop allegedly used by Sakai for APK development. Interrogation is ongoing, and investigators are pursuing leads on the Jamtara-based gang members who procured the applications.