Malicious APK in Fake D-Mart Offer Drains Elderly Man’s Bank Account

A Grocery Deal That Ended In fraud: Senior Citizen Loses Lakhs Through Fake Discount Offers

The420 Web Desk
4 Min Read

Hyderabad:  A 75 year old resident of Habsiguda in Hyderabad lost ₹1.09 lakh to cyber fraudsters who tricked him through a fake D-Mart discount offer circulated on Facebook. The fraud came to light after the victim reported the matter to the city’s cybercrime police, prompting authorities to issue a warning against opening suspicious links or downloading unauthorised files received through messaging platforms.

Fake grocery offer on Facebook triggers the scam

According to the police, the senior citizen came across an online advertisement titled “groceries@298” on Facebook, claiming heavy discounts on D-Mart products. Tempted by the offer, he clicked on the post and filled in his contact details through an online form linked to the advertisement.

FCRF Launches Flagship Compliance Certification (GRCP) as India Faces a New Era of Digital Regulation

Soon after submitting the form, the man received a message on WhatsApp containing an APK file an Android application package that appeared to be part of the shopping offer. Believing it to be legitimate, he downloaded and opened the file.

Phone hacked after APK installation

The moment he accessed the file, the man’s mobile phone was compromised. According to investigators, the APK contained malicious software that allowed the fraudsters to gain remote access to his device and banking credentials. Within minutes, they withdrew ₹1.09 lakh from his account through multiple unauthorised transactions.

Police said the fraudsters used sophisticated phishing tools to bypass two-factor authentication and capture sensitive information stored in the victim’s device. The incident mirrors a rising trend of cybercriminals exploiting e-commerce brands and social media advertisements to target vulnerable users, particularly senior citizens.

Police issue public advisory on WhatsApp, APK scams

The Hyderabad Cybercrime Police have urged citizens to exercise caution while responding to online offers or promotional advertisements that appear on social media platforms. Officials stressed that no legitimate retailer or company sends APK files for discounts or rewards and that users should never download such files from unknown sources.

“Cybercriminals are increasingly disguising malware as promotional apps or reward links. People must avoid clicking or sharing such links and refrain from submitting banking details on unverified websites,” an officer from the cybercrime unit said.

Growing concern over social media-based financial frauds

Authorities noted that cyber frauds exploiting fake shopping offers have increased sharply across Telangana and other states, with many cases involving senior citizens and non-tech-savvy users. Criminals typically impersonate trusted retail brands, circulate fraudulent offers on Facebook or WhatsApp, and use APK files to gain control over victims’ devices.

The police have advised the public to verify all advertisements through official websites or mobile applications and to report suspicious activity immediately via the 1930 cybercrime helpline or the National Cybercrime Reporting Portal (www.cybercrime.gov.in).

Investigation underway, police trace digital trail

Officials said an investigation is underway to trace the digital footprint of the fraudsters, including the origin of the APK file and the bank accounts used for the illicit transfers. The Cybercrime Police are coordinating with service providers to block fraudulent domains and deactivate suspicious accounts linked to the scam.

Authorities reiterated that early reporting of such crimes increases the chances of recovering the stolen money through quick response mechanisms established between banks and law enforcement agencies.

Stay Connected