Jharkhand Police arrested 14 accused in Deoghar and Jamtara for allegedly using fake APK files, bank impersonation and utility-payment lures to target victims.

Jharkhand Police Arrest 14 in Deoghar-Jamtara Cyber Fraud Crackdown Using Fake APK Files

The420 Web Correspondent
6 Min Read

Police have arrested 14 alleged cyber fraudsters in separate operations across Jharkhand’s Deoghar and Jamtara districts, uncovering networks accused of using malicious APK files to gain access to victims’ phones and steal sensitive information.

The accused allegedly posed as bank officials, customer-care representatives and government employees. Across the two operations, police seized 28 mobile phones, 31 SIM cards, nine ATM cards, a cheque book and ₹2.2 lakh in cash.

Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise

Fake government schemes used to push malicious apps

Ten accused were arrested from the Patharddah outpost area in Deoghar during a raid conducted on Friday.

Police recovered 15 mobile phones, 18 SIM cards and an ATM card. Cyber DSP Kailash Prasad Mahato said the accused allegedly impersonated representatives of e-commerce companies and digital payment platforms.

Investigators say victims were sent APK files disguised as documents or applications linked to PM-Kisan benefits, electricity bills and RTO challans.

In other instances, the accused allegedly called people pretending to be bank officials and claimed their debit or credit cards had been blocked. Victims were then offered help with reactivation, creating an opportunity to obtain financial information or persuade them to install malicious software.

Police said four of those arrested had previously faced cybercrime cases.

The latest raid closely resembles another Deoghar operation in August. Police then arrested 10 people accused of using fake customer-care identities and APK files linked to PM-Kisan, electricity bills and traffic challans. Investigators said seized devices showed links to complaints filed across several states.

Jamtara gang allegedly targeted gas customers

A separate police operation in neighbouring Jamtara led to the arrest of four accused from Dudhni under Karmatanr police station and Sonbad under Jamtara police station.

Police recovered 13 phones, 13 SIM cards, eight ATM cards, a cheque book and ₹2.2 lakh in cash from the accused.

Investigators allege that this group targeted customers of Haryana City Gas and Adani Gas.

Victims were allegedly sent fake APK files after being told that they needed to update or pay their gas bills. Once installed, the applications could potentially expose information stored on the phone or provide criminals with permissions that could later be misused for financial fraud.

Police also searched another suspect’s residence and said evidence and cash linked to alleged cybercrime were recovered.

The seized phones, SIM cards and financial records are now being examined to identify transactions, bank accounts, associates and additional victims.

How a fake APK can take over your phone

An APK, or Android Package Kit, is the file format used to install applications on Android devices.

An APK itself is not dangerous. Legitimate Android applications also use the format. The danger begins when criminals convince users to install an APK received through WhatsApp, SMS, Telegram or an unknown website instead of a trusted app store.

A malicious APK may request permissions to read SMS messages, access notifications, view files or interact with other parts of the device.

That can expose OTPs, banking alerts and other sensitive information.

The method described by Jharkhand police closely matches a threat that India’s Computer Emergency Response Team, CERT-In, warned about in March.

CERT-In said criminals were distributing Android malware using messages claiming that an RTO or e-Challan had been generated. Files carried names such as “RTO Challan.apk”, “RTO E Challan.apk” and “MParivahan.apk”.

Once installed, the malware could steal sensitive financial information and facilitate unauthorised transactions, according to the advisory.

Jamtara continues to see repeated fraud networks

Jamtara has long been associated with organised phone and online fraud, but recent cases show that the techniques continue to evolve.

Only a week earlier, Jamtara police arrested five accused who allegedly sent fake PhonePe cashback messages and used APK files to obtain victims’ credit-card information. Eleven phones and 13 SIM cards were seized in that operation.

The repeated use of fake APKs shows how social engineering remains central to these scams.

The technology does not infect a phone by magic. The criminal first has to persuade the victim that the file is connected to something believable — a government benefit, unpaid bill, bank problem or cashback offer.

That is why familiar names such as PM-Kisan, RTO, banks and utility companies are repeatedly used as bait.

What this means for you: Never install an APK received through WhatsApp, SMS or an unknown link, even if the message mentions a government scheme, bank or utility bill. If money has already been lost, contact your bank immediately and report the fraud through 1930 or the National Cyber Crime Reporting Portal.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected