A malicious file disguised as an ordinary application has cost a Chandigarh resident ₹99,000, in a case that ended with the arrest of a 22-year-old man in Ghaziabad after investigators followed the money through an unusual and traceable detour: a petrol pump in Hapur. Chandigarh Cyber Crime Police arrested Sarvar Khan, a resident of Bhamera village in Uttar Pradesh, in connection with the fraud, which police say began after an APK file was installed on the victim’s phone.
According to the complaint, the victim’s mobile device was compromised once the APK was installed, giving the attackers unauthorised access that was subsequently used to move ₹99,000 out of his SBI account through its linked Google Pay mechanism. A case has been registered against Khan under sections of the Bharatiya Nyaya Sanhita, and he has been sent to judicial custody following his arrest.
Tracing money to a petrol pump
Once the complaint was filed, the cyber crime team began analysing the compromised device alongside the transaction history tied to the victim’s bank account. That analysis led investigators to an Airtel Payments Bank account linked to Khan, where the stolen funds had been credited before being spent, notably, at a petrol pump in Hapur.
That single transaction at a physical location proved decisive. Unlike a purely digital trail that can be laundered through successive accounts and wallets, a point-of-sale purchase ties a specific individual to a specific place and time, giving investigators the kind of concrete lead that digital forensics alone often cannot supply. Combining that detail with technical analysis of the compromised device and financial records, Chandigarh Police traced Khan to Ghaziabad and carried out the raid that led to his arrest.
During questioning, Khan allegedly disclosed the involvement of two other people in the fraud, an admission that has since widened the investigation considerably. Police are now working to establish the identities and precise roles of these two additional suspects, treating the case as a potentially organised operation rather than the work of a single actor.
A malware category expanding rapidly
The APK file at the centre of the case fits into a broader surge in Android banking malware that security researchers have tracked with growing alarm through 2025 and into 2026. Kaspersky’s mobile malware research recorded a 56 per cent rise in Trojan banker attacks on Android smartphones in 2025, alongside a 271 per cent jump in newly created malicious installation packages compared with the previous year, a trend attributed to the substantial profits such tools generate for the criminals distributing them.
India has featured prominently in these campaigns. Security firms have repeatedly documented malware engineered to impersonate Indian banking and utility apps, distributed through messaging platforms and designed to steal financial credentials once installed, exploiting the trust a familiar-looking application name or icon can generate. Once installed, such malware can intercept SMS messages, harvest login credentials and, in more advanced variants, initiate transactions directly on the victim’s device without requiring the attacker to separately obtain an OTP.
Investigators in the Chandigarh case are still working to establish how the APK reached the victim’s phone in the first place and what method was allegedly used to persuade him to install it, whether through a suspicious link, a message on a social media platform or another digital channel. Establishing that distribution method matters beyond this single case, since it could indicate whether the same technique was used against other, as yet unidentified victims.
Building the full picture of the network
Police are examining the Airtel Payments Bank account further to determine whether its holder was directly involved in the fraud or was instead functioning as an intermediary, a distinction that often separates active participants in a cyber fraud ring from account holders whose credentials were rented or coerced. Call records, additional banking transactions and other digital evidence are being reviewed to determine whether Khan and the two other named suspects were operating as part of a larger network.
The involvement of a physical transaction, a routine fuel purchase, standing out amid what would otherwise have been an entirely digital trail underscores a recurring lesson for investigators: even well-executed cyber fraud eventually intersects with the physical world, and that intersection often provides the clearest evidentiary opening. Whether this case reveals a broader operation will depend on what the ongoing analysis uncovers about the two remaining suspects.
Police continue to advise mobile users against installing APK files obtained through unverified sources, noting that such applications can compromise not just banking credentials but broader access to a device, including SMS interception capabilities that undermine the OTP-based verification most Indian banking apps still rely on as a primary safeguard.
