Malicious Android application packages, commonly known as APK files, have become one of the most dangerous tools used by cybercriminals across India.
Unlike regular applications downloaded safely from official app stores, these rogue files are sent directly through text messages and WhatsApp links. Scammers exploit everyday household concerns—such as electricity disconnection notices, pending traffic fines, or gas-meter reading updates—to convince people to install these unverified files on their phones.
Once installed, these malicious apps secretly request access to critical mobile features, including SMS and accessibility permissions. This allows fraudsters to monitor the victim’s screen, record keystrokes, and automatically read one-time passwords (OTPs) sent by banks. Because the user is tricked into entering payment or personal details on what looks like a genuine form, the cybercriminals can easily access bank accounts and transfer funds without triggering typical fraud alarms.
A recent incident in Mumbai highlights the growing threat of this method. Kandivali Police arrested three men—identified as Urvishkumar Patel, Janikumar Patel, and Ankitkumar Patel—from Surat in Gujarat for duping two local residents of ₹6.25 lakh.
Algoritha Security Launches ‘Make in India’ Cyber Lab for Educational Institutions
The fraudsters contacted the victims while pretending to be customer care executives from Mahanagar Gas Limited. Claiming that the victims needed to update their meter readings or pay a small ₹12 fee to avoid disruption, they sent links to download a file named after the gas company. Once the victims installed the file, the accused gained remote access to their devices and siphoned ₹2.70 lakh and ₹4.17 lakh from their savings accounts. Police later discovered that the stolen money was used to repay personal gold loans.
Cybersecurity experts warn that utility companies and banks never ask customers to download installation files via chat or messaging apps. Users should never install files from unknown links, avoid granting unnecessary permissions to apps, and always manage utility services through official websites or verified app stores.
Investigators are now examining the financial transactions to determine how much of the alleged fraud proceeds was used to repay the gold loan and whether the remaining money was transferred to other accounts or channels.
The financial trail eventually led the police team to Olpad village in Surat district. A Kandivali police team reached the location on Friday and apprehended the three accused. The suspects were arrested in connection with both cases and brought to Mumbai on the same day.
The case highlights a growing cyber fraud tactic in which criminals impersonate officials of trusted utility companies and use routine services such as meter readings, bill payments or connection updates as a pretext to persuade victims to install malicious APK files. Once installed, such files can potentially give attackers unauthorised access to devices and sensitive information.
Cybercrime expert and former IPS officer Prof. Triveni Singh said fraudsters often create urgency around utility services to persuade victims to install unauthorised applications. People should verify the source of any APK file before installing it and should use only official customer-care channels provided by the service provider. Files or links received from unknown numbers can expose both personal information and banking credentials to serious risks.
Kandivali police are now investigating whether the arrested trio was involved in similar cyber frauds against other victims. Investigators are examining their previous financial transactions, mobile records and digital activities to determine the extent of the alleged network.