After Gas Scam, Cybercriminals Turn Traffic Challans Into a New Trap

The420.in Staff
6 Min Read

Cybercriminals in Lucknow are using fake traffic challan messages carrying malicious APK files to gain access to victims’ phones and steal banking information, with police saying at least half a dozen complaints have surfaced in recent weeks.

In one case, an Aliganj resident allegedly lost nearly ₹2 lakh after opening an APK sent from an unknown number. Investigators said the tactic resembles the “Green Gas” APK scam already being used to target residents.

How Does the Fake Challan Scam Work?

The fraud begins with a WhatsApp message claiming that a traffic challan has been issued in the recipient’s name. The message asks the person to open an attached APK file to verify the notice.

Police said the message is designed to appear official and create panic or urgency, increasing the likelihood that a recipient will open the attachment without checking whether it is genuine.

Once installed, the malicious application can potentially give criminals access to personal data, banking details, passwords and other sensitive information stored on the device.

How Did the Victim Lose Nearly ₹2 Lakh?

The latest victim identified in the report was Uttam of Chaudhary Tola in Aliganj. He received a WhatsApp message from an unknown number on September 6 claiming that a traffic challan had been issued in his name.

The message asked him to open an attached APK file to verify the notice. Believing it was genuine, Uttam opened the file.

The malicious application allegedly compromised his phone. The first indication of trouble came the following day when a small transaction of ₹2 was made through one of his credit cards. Investigators said cybercriminals sometimes use such small transactions to test whether banking credentials remain active.

Uttam initially ignored the small deduction. Investigators suspect the fraudsters retained access to his device for several days, monitoring activity and collecting sensitive information.

What Happened After the Phone Was Compromised?

On September 10, Uttam’s phone suddenly switched off and could not be restarted despite repeated attempts.

The device switched on the following day. By then, nearly ₹2 lakh had allegedly been siphoned from his account.

Cyber officials said the method exploits motorists’ fear of penalties. An apparently official traffic notice creates urgency, while the APK serves as the route through which criminals can potentially access sensitive information on the victim’s device.

Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise

How Is It Similar to the Green Gas APK Scam?

Investigators said the method mirrors the “Green Gas” APK scam, in which fraudsters circulated malware-laden files through WhatsApp while pretending to provide gas meter updates.

In another case described in the report, Hariprasad Yadav, a resident of Sarojini Nagar, allegedly lost ₹4.31 lakh to fraudsters posing as Green Gas officials.

Yadav received a message on September 21 claiming his Green Gas bill was pending and warning that his supply would be disconnected if the dues were not cleared. The message carried a contact number, which he called.

The caller introduced himself as Sandeep Mishra and discussed the purported bill payment. Another caller later allegedly asked Yadav to make a payment using his debit card.

He was initially instructed to pay ₹13, but the transaction reportedly failed. Four unauthorised transactions of ₹1.99 lakh, ₹1.34 lakh, ₹68,823 and ₹30,125 were subsequently made from his account.

Yadav discovered the fraud after checking his bank account and immediately informed the bank, which blocked the account.

Click Here to Read More About Gas APK Scam

What Are Police Warning Residents About?

The Crime Branch, under its Operation Digital Kavach awareness campaign, has advised people not to install APK files received through WhatsApp, SMS or social media.

ADCP (Crime) Kiran Yadav said cybercriminals were changing their tactics and increasingly using convincing, official-looking messages to trap victims.

Police have warned that an unexpected message claiming an unpaid challan or other pending payment should not be trusted merely because it appears official. Opening an APK received from an unknown or unverified source can expose information stored on the phone.

What Should Victims Do After Suspected Cyber Fraud?

Officials have urged residents to immediately report suspicious activity or cyber fraud through the national cybercrime helpline 1930.

The cases also show how an apparently minor event can precede a larger loss. In Uttam’s case, investigators said a ₹2 transaction appeared before nearly ₹2 lakh was siphoned away, while the Green Gas case involved an attempted small payment before several unauthorised transactions followed.

The420 Insight

A traffic challan or utility bill message can appear routine, but an unsolicited APK attachment should be treated with caution. Police have specifically advised people not to install APK files received through WhatsApp, SMS or social media. Anyone noticing suspicious transactions or suspected cyber fraud should report it immediately on 1930.

About the author — Ayesha Aayat writes on cybercrime, digital safety, and emerging online threats. Her work focuses on public awareness, legal clarity, and technology-driven risks.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected