: Gujarat Police arrest another alleged Jamtara network operative after tracing ₹2.72 lakh in fraud proceeds tied to a fake RTO e-challan APK scam.

Gujarat Police Arrest Jamtara Gang Aide Over Fake RTO Challan Fraud

The420 Web Correspondent
6 Min Read

Gujarat Police have arrested another alleged operative of a Jamtara-based cyber fraud network, this time in a case built around a fake RTO e-challan APK file that investigators say drained ₹5.02 lakh from a Surat family’s bank account. The Surat Cyber Crime Cell took 26-year-old Sitaram Mandal into custody from Sabarmati Jail in Ahmedabad, where he was already lodged in connection with an earlier case, and has now booked him separately for the Surat fraud.

The arrest is the latest thread in an investigation that has, over recent months, exposed how deeply organised and geographically dispersed these APK-based fraud rings have become. What began as a single family’s complaint about a malicious file circulated over WhatsApp has, through banking records and technical tracing, opened a window into a wider network allegedly supplying customised malware to hundreds of fraudsters across the country.

How the Fraud Unfolded

According to the police complaint, the episode began on November 20, 2025, when an unknown WhatsApp number sent a file disguised as an RTO e-challan notice to a man named Rakesh Sharma, a friend of the victim’s family. The compromised WhatsApp account was then used to forward the same APK into a group that included the victim’s son and his friends, a tactic investigators say is designed to exploit trust between contacts rather than target strangers directly.

Once installed, the malicious application allegedly gave criminals remote access to the victim’s phone, enabling multiple unauthorised transactions that together amounted to ₹5,02,562. The family reported the fraud to the national cybercrime helpline before formally approaching the Surat Cyber Crime Cell on December 14, 2025, leading to a case under the Bharatiya Nyaya Sanhita and the Information Technology Act.

Investigators tracing the stolen funds allege that ₹1,47,954 of the money was routed through an accused named Nishit Nathwani to settle a credit card bill, with Nathwani retaining a 15 to 20 per cent commission before depositing the balance into Mandal’s Axis Bank account through cash deposit machines. Mandal, police allege, took a further cut of 5 to 10 per cent before passing the remaining cash to absconding members of the network based in Jharkhand.

A Mule Account That Moved Nearly ₹16 Lakh

Bank records examined by investigators show that Mandal’s Axis Bank account received credit transactions totalling ₹15,87,400 between September 2025 and January 2026, of which roughly ₹2.72 lakh has been linked specifically to this and related cyber fraud cases. Such layering through mule accounts and cash deposit machines has become a hallmark of Jamtara-linked operations, allowing stolen money to be broken into smaller, less conspicuous transfers before reaching handlers.

Mandal’s case connects to a broader investigation the Ahmedabad Cyber Crime Cell opened earlier this year into an alleged malware-distribution syndicate. Police have named Purnanand alias Mukesh Tiwari as the alleged developer of the malicious APK files and operator of a Telegram bot through which the software was marketed, while another accused, Vikas Das, is alleged to have supplied malware to nearly four hundred fraudsters. Mandal’s role, according to police, extended to arranging bank cards and helping distribute the malicious files further within the network.

Court and police records cited in the investigation indicate Mandal is no newcomer to such cases. He was named in a 2017 case in Giridih involving cheating and forgery, and has since been linked to five separate cybercrime cases registered in Ahmedabad in 2026, suggesting a criminal trajectory that began with smaller-scale OTP and billing frauds before evolving into technically sophisticated APK distribution.

Jamtara’s Enduring Grip on India’s Cyber Fraud Landscape

The Jamtara region of Jharkhand has for years functioned as an informal hub for organised digital fraud in India, and recent months have shown the model has only grown more sophisticated. Separate investigations this year uncovered networks distributing over a hundred custom-built APK files impersonating major banks and government departments, and police forces across states, from Odisha to Gujarat, have dismantled cells built around similar structures of developers, distributors and cash handlers.

What distinguishes the current phase of Jamtara-linked fraud is its assembly-line character, with distinct roles for coding malware, marketing it through Telegram bots, opening mule accounts and physically converting digital theft into untraceable cash. Investigators in Gujarat are now examining whether Mandal’s alleged involvement extends beyond the Surat case to other complaints routed through the national cybercrime helpline.

Stay Connected