Jharkhand Police have arrested six more alleged cyber fraudsters in separate operations across Deoghar and Jamtara, barely two days after 14 suspects were held in another crackdown involving fake applications and impersonation scams.
Four accused were arrested in Deoghar on Sunday evening, while two young men were held in Jamtara on Monday. Police recovered 11 mobile phones and nine SIM cards across the two operations.
The latest arrests show that police action in the region is continuing even after the larger September 19 operation. The methods also remain familiar: fake government benefits, customer-care impersonation and malicious Android files disguised as official communications.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
PM-Kisan and loan offers allegedly used as bait
Police said the four Deoghar accused were aged between 20 and 25 years.
They allegedly posed as customer-care representatives of e-commerce companies and payment banks. Investigators say victims were contacted through fake mobile numbers and offered benefits linked to schemes such as PM-Kisan or attractive loan offers.
Seven mobile phones and six SIM cards were seized from them.
Such impersonation scams rely less on sophisticated hacking at the beginning and more on trust. A caller or message first creates a believable reason for the victim to respond, after which the fraudster attempts to obtain financial information, account access or permission to install software.
The new Deoghar arrests come just two days after police arrested 10 people from the district’s Patharddah outpost area in a separate case. Those accused were allegedly using similar government-scheme, electricity-bill and RTO-related lures.
Fake e-challan APK allegedly used in Jamtara
The Jamtara operation involved a more technical method.
Cyber Police raided a house in Sundarjori village under Karmatanr police station and arrested Gotam Kumar Mandal, 21, and Sonu Kumar Mandal, 19. Four mobile phones and three SIM cards were recovered.
According to Cyber DSP Amit Kumar, the accused allegedly sent fraudulent APK files to WhatsApp users while presenting them as RTO e-challan notices.
A victim would receive a message claiming that a traffic challan had been issued and would be asked to download the attached application.
Police allege that once installed, the fake application could be used to obtain sensitive information from the device. That information was then allegedly used to carry out transactions through e-wallets.
Investigators say the alleged network was not confined to Jamtara and may have targeted people in several states.
A case has been registered under relevant provisions of the Bharatiya Nyaya Sanhita, Information Technology Act and Telecommunications Act.
How a fake e-challan APK compromises a phone
An APK is simply the installation file used by Android applications. Genuine apps use APKs too, but criminals exploit the format by persuading users to install applications from outside trusted app stores.
India’s Computer Emergency Response Team, CERT-In, issued a nationwide warning about almost exactly this technique in March.
It identified malicious files carrying names such as “RTO Challan.apk”, “RTO E Challan.apk” and “MParivahan.apk”. The files impersonated official transport services and were circulated through messages claiming that the recipient had an unpaid traffic challan.
CERT-In found that some variants could request access to SMS messages and calls, operate in the background and even create a VPN connection that could help attackers monitor the phone’s internet traffic.
Fake payment screens could then collect banking credentials, while access to SMS messages allowed criminals to intercept OTPs.
The government advisory specifically tells users to verify challans only through the official e-Challan portal or the relevant state traffic police service.
Repeated raids show how persistent the network remains
The latest arrests follow an unusually concentrated series of cybercrime actions in Jharkhand.
On September 19, The420.in reported the arrest of 14 alleged fraudsters across Deoghar and Jamtara. Ten were arrested in Deoghar, while four were held in Jamtara in an alleged network targeting gas customers through fake APK files.
The420.in has also previously reported on the broader fake e-challan malware campaign after CERT-In warned that such files were being circulated nationwide.
The September 21 arrests are therefore a separate development, but they reinforce the same pattern.
Fraudsters continue to use familiar institutions — banks, government schemes, RTO notices and customer-care departments — because victims already recognise those names.
The technical tool may be an APK, but the attack still begins with a believable message.
What this means for you: Never install an APK sent through WhatsApp, SMS or Telegram claiming to be an RTO challan, PM-Kisan application or loan service. Check traffic fines only through the official e-Challan portal and report financial cyber fraud immediately through 1930.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics