A Lucknow resident allegedly lost ₹2 lakh after opening a fake traffic-challan APK sent through WhatsApp, in a case where fraudsters are suspected to have retained access to his mobile phone for several days.
The victim, identified as Uttam of Chaudhary Tola in Aliganj, told police that he received the file from an unknown number on September 6. The sender claimed that a traffic challan had been issued in both their names and asked him to open the attached file to check the details.
An FIR has been registered at Aliganj police station, and the cyber cell is examining the APK, the sender’s number and the financial trail.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
Fake challan message appeared to come from another affected person
According to the complaint, the WhatsApp sender told Uttam that a challan notice contained both names.
That detail appears to have made the message more believable.
Uttam opened the APK file, after which his phone continued to function normally. He reportedly did not notice any immediate warning that the device may have been compromised.
The following day, however, ₹2 was deducted from one of his credit cards.
Because the amount was so small, he did not initially treat the transaction as suspicious.
Such low-value transactions are sometimes used by fraudsters to check whether a card or payment route is active before attempting a larger transaction, although police have not yet publicly established whether that was the purpose of the ₹2 deduction in this case.
Phone suddenly shut down before ₹2 lakh loss was discovered
The more serious problem emerged several days later.
On September 10, Uttam’s mobile phone suddenly switched off and did not restart despite repeated attempts.
He initially believed the device had developed a technical fault.
The phone reportedly restarted automatically the following day.
When Uttam checked it, he found four transaction messages indicating that a total of ₹2 lakh had been withdrawn from his account.
He then approached Aliganj police and reported the fraud.
Investigators are now examining how the transactions were authorised and whether the malicious application interfered with SMS alerts, notifications or other phone functions.
APK files can give attackers powerful permissions
APK stands for Android Package Kit, the file format used to install applications on Android devices.
APK files themselves are not malicious. Legitimate Android applications also use the format.
The risk arises when users install APKs received through WhatsApp, SMS or unfamiliar websites without knowing what the software contains.
Indian Bank has specifically warned about fake e-challan messages that direct users to install unofficial APKs. Such applications may request access to contacts, SMS messages, storage or other sensitive phone functions.
That access can potentially expose OTPs or help attackers interfere with banking activity.
Police will still need forensic evidence to determine precisely what the file installed on Uttam’s phone was capable of doing.
Similar challan APK frauds are spreading across Uttar Pradesh
The Lucknow complaint fits a wider pattern seen across Uttar Pradesh this month.
On September 20, Amar Ujala reported that several people in Budaun installed an APK disguised as an RTO challan file, after which money began leaving their accounts through UPI transactions. More than ₹20,000 was reported stolen across four victims.
A separate Varanasi case reported earlier this month involved a man who allegedly lost ₹8.50 lakh after downloading a fake e-challan APK.
In Sambhal, a political worker’s phone was allegedly compromised after he opened a fake e-challan link, with fraudsters then using his WhatsApp account to request money from his contacts.
These are separate cases, and there is currently no public evidence that they were operated by the same criminal group.
What they show is that fake traffic notices have become an increasingly common social-engineering lure.
Why traffic challans make convincing bait
Traffic challan scams work because the message creates both urgency and uncertainty.
A recipient may not immediately know whether a camera or traffic officer recorded a violation.
Fraudsters exploit that uncertainty by sending messages that appear to contain official notices, vehicle details or payment instructions.
The safest response is to verify any challan independently.
Indian Bank advises users to check traffic fines only through the official e-challan portal and warns that genuine traffic authorities do not require users to install APK files sent over WhatsApp.
Six-day timeline raises questions for investigators
One of the notable features of the Lucknow complaint is the time between the APK being opened and the larger unauthorised transactions being discovered.
Uttam allegedly opened the file on September 6, while his phone failed on September 10 and the ₹2 lakh loss became apparent after it restarted the next day.
Police will need to establish whether the device remained compromised throughout that period or whether access was used only at particular times.
Investigators may examine application logs, permissions, banking records, SMS data and network activity to reconstruct the sequence.
The four financial transactions will also be traced to determine which accounts received the money and whether they were subsequently transferred to other mule accounts.
Police trying to freeze and trace funds
The cyber cell is reportedly attempting to freeze the defrauded amount.
Speed is important because stolen money is often moved rapidly through multiple beneficiary accounts.
Investigators are also analysing the WhatsApp number used to send the file and the APK itself.
If the file contains command-and-control details or identifiable server addresses, those could help police connect the case to a broader malware network.
For now, however, the available information establishes only the victim’s complaint and the ongoing investigation.
The exact malware mechanism and the identities of the alleged fraudsters have not yet been publicly confirmed.
What this means for you: Never install a traffic-challan APK received through WhatsApp or SMS, even if the message contains your name or vehicle details. Verify any fine directly through the official e-challan portal and report suspicious financial activity immediately through your bank and 1930.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics