Mumbai Police have arrested a web developer from Haryana for allegedly providing a virtual private server to cybercriminals who used it to store malicious Android application files and target unsuspecting users. The accused was taken into custody from Taloja Prison.
What Is a Virtual Private Server?
A Virtual Private Server, or VPS, is a virtual server that provides users with dedicated computing resources such as an operating system, processing power and storage. It can be used to host websites, applications and files remotely. In this case, police alleged that the VPS was used to store malicious APK files that were later sent to potential victims.
How Was the VPS Allegedly Used?
Police said the accused, identified as MUMBAI, allegedly provided a virtual private server, or VPS, to cyber scammers for a fee. A VPS functions as a server with its own operating system, CPU and storage, allowing users to maintain a dedicated space for deploying applications or websites.
Investigators said scammers used the server to store malicious APK files. These files were subsequently sent to unsuspecting victims and allegedly used to steal confidential data from their mobile phones.

How Did the Case Come to Light?
The investigation began after a senior citizen from Cuffe Parade was allegedly cheated of ₹17 lakh in a gas bill update scam.
In July, a 75-year-old homemaker from Cuffe Parade received a call over WhatsApp from a person identifying himself as a Mahanagar Gas Ltd employee. She was allegedly told that her previous bill payment had not been updated in the system.
The caller then asked her to pay ₹3. The elderly woman fell for the con and clicked on a link sent through SMS.
What Happened After She Clicked the Link?
The link contained a malicious APK file that allegedly gave the scammer access to her phone. Shortly afterwards, the woman received a text alert from her bank informing her that ₹17.4 lakh had been debited from her account.
She then lodged a complaint with the Cyber Crime Helpline 1930 and approached Azad Maidan police.
How Did Police Trace the Server?
During the investigation, conducted under the supervision of DCP Rajiv Jha, police carried out a technical analysis of the malicious APK file.
Investigators found that the accused in Haryana had allegedly provided a VPS to individuals without carrying out a KYC process. Police said the server contained multiple folders with a total of around 25,200 to 26,000 files.
What Did Police Find on the VPS?
According to the investigation, the files stored on the server were linked to malicious applications. Police suspect that the accused was aware of the fraudulent activity taking place through the VPS.
The investigation is examining how the server was allegedly used by cybercriminals and the extent of its role in facilitating the malicious applications.
What Happens Next in the Investigation?
The accused is currently lodged at Taloja Prison, and cyber investigators are analysing the data recovered during the investigation.
Police are also examining the wider network and trying to determine how the malicious files stored on the server were being used in cyber fraud operations.
What You Need to Know
The case shows how malicious APK files hosted on remote servers can be used to gain access to a victim’s phone and steal financial information.
Users should avoid clicking unknown links or installing APK files sent through calls, messages or WhatsApp, especially when someone asks for a small payment or claims an urgent account update.
About the author — Ayesha Aayat writes on cybercrime, digital safety, and emerging online threats. Her work focuses on public awareness, legal clarity, and technology-driven risks.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics