Mumbai Police arrested an Indore developer accused of creating 2,805 malicious Android apps used by cybercrime gangs, with suspected fraud exposure exceeding ₹150 crore.

Mumbai Police Arrest Indore Developer Linked to 2,805 Malicious Android Apps

The420 Web Correspondent
9 Min Read

Mumbai Police have arrested a 36-year-old software developer from Indore who allegedly created thousands of malicious Android applications and sold them to cybercrime gangs operating across India.

The accused, identified as Pankaj Avhdesh Gupta, allegedly developed 2,805 APK files disguised as services such as senior citizen cards, life certificates, pension verification, traffic challans and credit-card updates.

Police suspect cybercriminals using those apps may have cheated victims of more than ₹150 crore nationwide.

The Crime Branch’s Property Cell traced Gupta while investigating a separate case in which a 72-year-old Byculla resident allegedly lost ₹5.62 lakh after installing a malicious application sent through WhatsApp.

FCRF Launches CP-FRM to Build India’s Next Generation of Fraud Risk Professionals

Senior Citizen Scam Led Police to Developer

The investigation began after the Byculla victim was contacted on August 13 by a fraudster allegedly posing as a senior Bank of India manager.

The caller offered to help him obtain a senior citizen card and sent an Android file named “Senior Citizen Card Verification.apk” through WhatsApp.

Police allege the victim was persuaded to install the application and enter personal and debit-card information.

₹5.62 lakh was subsequently siphoned from his account.

Byculla Police initially registered the case before the investigation was transferred to the Mumbai Crime Branch Property Cell.

Technical analysis of the application eventually led investigators to Gupta in Madhya Pradesh.

Police Say 2,805 Malicious APKs Were Sold

During the investigation, police allegedly found that Gupta had created and supplied 2,805 APK files to cybercrime groups.

The files were designed to appear connected with legitimate services that people might reasonably trust.

These included applications related to pension cards, life certificates, senior citizen services, traffic challans and credit-card updates.

An APK is the file format used to install applications on Android devices.

APK files are not inherently dangerous. Legitimate Android apps are distributed using the same format.

The risk arises when criminals disguise malicious software as a genuine service and persuade victims to install it outside a trusted app store.

Malware Could Capture Sensitive Information

Police say the applications were designed to facilitate financial fraud.

Fraudsters would contact victims by phone or message and create a believable reason to install the app, such as completing a bank verification, downloading a pension document or checking a traffic challan.

Once installed, malicious apps can seek access to sensitive device permissions.

Depending on their design and the permissions granted, such software may potentially capture information entered by the user, monitor notifications or assist criminals in obtaining banking credentials.

The exact capabilities of the 2,805 APKs seized or identified in this case are still being technically examined.

Developer Allegedly Worked as Technical Service Provider

India Today reported that Gupta initially offered conventional website and app-development services.

Police allege that after coming into contact with a cybercriminal, he began presenting himself as an APK developer and later built relationships with fraud groups across the country.

Investigators describe him as a technical service provider rather than someone who necessarily contacted each victim himself.

That distinction makes the case significant.

Cybercrime operations increasingly function like businesses, with different people responsible for phishing calls, malware development, mule accounts, server infrastructure and money laundering.

Police allege Gupta occupied the software-development layer of that ecosystem.

Server Infrastructure Was Also Allegedly Arranged

Investigators say Gupta did not merely create the applications.

He had also allegedly rented server infrastructure used in connection with the operation.

Servers can be important in malicious-app operations because stolen information may need to be transmitted from infected devices to infrastructure controlled by the attackers.

Police are now examining the server arrangements and attempting to identify the cybercrime gangs that purchased the applications.

9,673 Victims Linked During Investigation

The Times of India reports that police analysis linked the malicious APK ecosystem to at least 9,673 people across India.

Cybercrime complaints from 1,074 victims were registered through the 1930 helpline, including 143 complaints from Maharashtra and 36 from Mumbai.

Police have so far identified 88 cases across India connected with the applications, including eight in Maharashtra and five in Mumbai.

The investigation remains ongoing, so those numbers may rise.

₹15.75 Crore Identified, ₹150 Crore Suspected

One of the most important distinctions in the case concerns the size of the alleged fraud.

Police have identified losses of approximately ₹15.75 crore through complaints and transactions currently linked to the applications.

However, investigators suspect the total fraud committed using Gupta’s malicious APKs may exceed ₹150 crore once additional cases and financial trails are identified.

The ₹150 crore figure is therefore an investigative estimate.

It does not mean police have already traced ₹150 crore directly to Gupta or that he personally earned that amount.

India Today also stressed that the figure represents fraud allegedly committed using the apps, rather than income received by the developer.

Police Seize Digital Devices From Indore Office

Mumbai Crime Branch officers raided Gupta’s office in Indore during the investigation.

Police seized a pen drive, CPU, three hard disks, a Wi-Fi router and three mobile phones.

These devices are now being examined for source code, customer lists, communications, payment records and links to other alleged cybercrime operators.

The investigation may also help identify who commissioned particular apps and which fraud groups used them against victims.

Developer Allegedly Tried to Leave Little Digital Footprint

Police say Gupta took steps to conceal his identity and reduce the digital trail connecting him to the malicious applications.

Despite those precautions, investigators were able to trace him through technical evidence associated with one APK.

That technical trail may now become crucial in mapping the wider distribution network.

Investigators are expected to compare app signatures, server records and communication logs across complaints filed in different states.

Fake Government and Banking Apps Remain Major Threat

The alleged applications used familiar public services precisely because such names can create trust.

A person receiving a traffic-challan file, pension verification app or senior citizen card application may assume the software comes from a government department, bank or authorised service provider.

Fraudsters exploit that trust.

Users should therefore avoid installing APK files received through WhatsApp, SMS or unknown links unless the file has been independently verified.

Government and banking services should normally be accessed through official websites or applications downloaded from trusted app stores.

Investigation Now Focuses on Cybercrime Buyers

Police are questioning Gupta to identify the gangs and individuals who allegedly purchased the malicious applications.

That could turn the case into a wider investigation of cybercrime infrastructure rather than one developer.

Each buyer could potentially connect investigators to separate fraud campaigns, bank accounts and victim lists across different states.

Gupta has not been convicted, and the allegations remain subject to investigation and court proceedings.

What this means for you

Never install an Android APK sent through WhatsApp or SMS simply because it is labelled as a bank update, pension certificate, traffic challan or government service. Verify the service independently through the official website or app store, because a convincing file name does not prove an application is genuine.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected