Gujarat Police arrest UP teen who built APK tools for Jamtara cyber gangs

Share:
Audio Loading voice…
Gujarat Police arrest UP teen who built APK tools for Jamtara cyber gangs

Synopsis

An 18-year-old from Uttar Pradesh allegedly built 121 fake banking and service apps — impersonating PNB, SBI, Axis Bank, and even BigBasket — and sold them to Jamtara's cybercrime syndicates for ₹10,000–₹15,000 a month each. Installed on over 21,000 devices, the apps enabled ₹64.38 crore in fraudulent transactions. Gujarat Police's Surat Cyber Crime Cell cracked the case from a single WhatsApp APK complaint.

Key Takeaways

Rohit Sakai , 18, from Kasganj, Uttar Pradesh , was arrested by the Surat City Cyber Crime Cell on 20 July from a hotel in Kanpur .
He allegedly developed 121 malicious APK files impersonating banks and services, sold to Jamtara-based cybercrime gangs for ₹10,000–₹15,000 per month per app.
The APKs were installed on 21,672 devices across India; 2,928 were compromised, resulting in 54,094 fraudulent debit transactions.
Estimated total fraud: ₹64.38 crore ; the largest category — fake RTO Challan apps — alone accounted for ₹27.82 crore .
The case was triggered by a victim receiving a fake 'PNB One.apk' on WhatsApp on 15 May , leading to the theft of ₹5 lakh from their account.
Police seized two mobile phones and one laptop ; charges filed under the Bharatiya Nyaya Sanhita, 2023 and the IT (Amendment) Act, 2008 .

The Surat City Cyber Crime Cell on Monday, 20 July arrested an 18-year-old Android application developer from Uttar Pradesh for allegedly creating malicious APK files that mimicked legitimate banking and service apps, enabling cybercrime syndicates based in Jamtara, Jharkhand to defraud victims across India of an estimated ₹64.38 crore. The accused, identified as Rohit Sakai, a resident of Patiali tehsil, Kasganj district in Uttar Pradesh, was traced to a hotel in Kanpur through technical surveillance and arrested in a coordinated operation.

How the Fraud Network Operated

According to police, Sakai — who studied only up to Class 11 — allegedly developed and sold APK files to multiple Jamtara-based cybercrime gangs, charging between ₹10,000 and ₹15,000 per application for one month's use, with renewal fees levied thereafter. Investigators allege he developed 121 different APK files in total, which were sold to various gang members and circulated primarily via WhatsApp and Telegram.

Police explained the alleged modus operandi: two Android applications were developed per operation. The first was distributed to potential victims to compromise their devices; the second allowed gang members to remotely access the hacked phones. Gang leaders allegedly trained members to distribute the apps through messaging platforms.

Scale of the Alleged Operation

Investigators claimed the 121 APK files were installed on 21,672 mobile devices across India, of which 2,928 were allegedly compromised after attackers gained unauthorised access. The operation is estimated to have resulted in 54,094 fraudulent debit transactions amounting to ₹64,38,48,837.60 (approximately ₹64.38 crore).

Police released a category-wise breakdown. 27 RTO Challan APKs were installed on 5,308 devices, compromising 1,202 of them and generating 34,486 debit transactions linked to alleged fraud of ₹27.82 crore. 13 SBI APKs were installed on 2,465 devices, with 323 compromised and losses estimated at ₹14.34 crore. 14 PNB APKs were installed on 3,362 devices, compromising 441 and causing alleged losses of ₹7.16 crore. The accused also allegedly developed APKs impersonating Axis Bank, American Express, BigBasket, UCO Bank, HSBC, Bandhan Bank, Union Bank, ICICI Bank, IndusInd Bank, City Union Bank, Federal Bank, CAMPA, Zepto, DMart, PM Kisan, and hospital and customer support services.

The Trigger: A Fake PNB App on WhatsApp

The case originated from a complaint filed after a victim received a file named 'PNB One.apk' on WhatsApp on 15 May. Once downloaded, the file allegedly granted attackers unauthorised access to the victim's device. Investigators said the accused and his associates then accessed the victim's Prime Co-operative Bank account and transferred ₹5 lakh to a Union Bank of India account without the complainant's knowledge.

The victim subsequently contacted the National Cyber Crime Helpline, prompting the Cyber Crime Cell to investigate. Technical analysis identified Sakai as the developer of the file and traced him to Kanpur.

How Victims Were Targeted

The fake applications used the names, logos, and icons of banks and well-known organisations to appear genuine. Victims were prompted to enter banking and Know Your Customer (KYC) details, while the apps allegedly captured SMS messages, contacts, call logs, and photographs stored on the devices. Once banking credentials were obtained, funds were transferred to mule bank accounts or credit cards, converted to cash, and deposited through Cash Deposit Machines (CDMs) to conceal the identities of gang members.

Charges and Seizures

A case has been registered under Sections 318(4), 336(2), 338, 336(3), 340(2), 61(2), and 3(5) of the Bharatiya Nyaya Sanhita, 2023, along with Sections 66(C) and 66(D) of the Information Technology (Amendment) Act, 2008. Police seized two mobile phones and one laptop allegedly used by Sakai for APK development. Interrogation is ongoing, and investigators are pursuing leads on the Jamtara-based gang members who procured the applications.

Point of View

000 a month exposes the industrial, franchise-like structure of India's cyber fraud economy — where development, distribution, and cash-out are separate, outsourced functions. What is striking is the scale achievable by a single developer: 121 apps, 21,000-plus installs, ₹64 crore in alleged losses. India's National Cyber Crime Helpline remains the entry point for most victims, but the gap between complaint and arrest — in this case traced back to a May incident — points to the bandwidth constraints facing state cyber cells. The Jamtara network has been disrupted repeatedly since 2020, yet it continues to recruit and adapt, now commissioning custom app development rather than relying on off-the-shelf phishing kits. The policy question is not just about arresting developers but about tightening the APK sideloading ecosystem and compelling telecom and messaging platforms to flag or block known malicious file hashes at the network level.
NationPress
21 Jul 2026

Frequently Asked Questions

Who is Rohit Sakai and why was he arrested?
Rohit Sakai is an 18-year-old Android app developer from Patiali tehsil, Kasganj district, Uttar Pradesh, arrested by the Surat City Cyber Crime Cell on 20 July. He is accused of developing 121 malicious APK files that impersonated banking and service apps and selling them to Jamtara-based cybercrime gangs to facilitate financial fraud across India.
What is the Jamtara cyber gang connection?
According to investigators, Sakai allegedly developed APK files specifically for cybercrime syndicates operating from Jamtara district in Jharkhand — a region long associated with organised phone and cyber fraud in India. He reportedly sold the apps to multiple gang members, who then distributed them to victims via WhatsApp and Telegram.
How much money was allegedly stolen using these fake apps?
Police estimate the operation resulted in 54,094 fraudulent debit transactions totalling approximately ₹64.38 crore. The apps were installed on 21,672 devices, of which 2,928 were compromised and used to drain bank accounts.
Which banks and services were impersonated by the fake APKs?
The fake apps impersonated a wide range of institutions including Punjab National Bank (PNB), State Bank of India (SBI), Axis Bank, ICICI Bank, HSBC, UCO Bank, Union Bank, IndusInd Bank, Bandhan Bank, City Union Bank, Federal Bank, American Express, as well as services like BigBasket, Zepto, DMart, PM Kisan, and hospital and customer support portals.
What should people do if they receive an APK file on WhatsApp?
Police advise never downloading APK files received via WhatsApp or Telegram from unknown sources, as legitimate banks and services do not distribute apps this way. If you suspect fraud, contact the National Cyber Crime Helpline immediately. Always download banking apps only from official app stores.
Nation Press
The Trail

Connected Dots

Tracing the thread behind this story — newest first.

8 Dots
  1. Latest 3 days ago
  2. 1 week ago
  3. 3 weeks ago
  4. 1 month ago
  5. 2 months ago
  6. 2 months ago
  7. 7 months ago
  8. 1 year ago
Google Prefer NP
On Google