Mumbai Police’s DB Marg Police Station has dismantled a nationwide cyber fraud infrastructure following the arrest of a 26-year-old school teacher from Jharkhand who allegedly created and sold custom Android Application Package (APK) files to cybercrime syndicates across India. The malicious applications, disguised primarily as legitimate utility update files for Mahanagar Gas Limited (MGL), enabled fraudsters to infiltrate smartphones, hijack banking credentials, and execute thousands of illegal transactions totaling ₹63.69 crore. Police officials stated that the timely seizure of nearly 1,000 unreleased fake applications averted potential future financial frauds estimated to exceed ₹1,000 crore.
Fraudulent MGL KYC Update Lure and Technical Investigation
The accused, identified as S.K. Mandal, was apprehended in West Bengal on July 24 following a technical surveillance operation after evading law enforcement agencies. The investigation originated from a complaint filed by a Mumbai resident on July 3, who received a text message instructing him to download an attached APK file to complete an urgent MGL Know Your Customer (KYC) verification. Upon installing the application, the victim’s mobile banking credentials were compromised, resulting in an unauthorized withdrawal of ₹70,700. Police subsequently registered a criminal case under relevant provisions of the Bharatiya Nyaya Sanhita (BNS) and the Information Technology Act.
Digital forensic analysis traced the creation and distribution chain of the malicious software back to Mandal. Investigators established that the accused had developed and supplied 91 customized APK files to organized cybercrime networks operating across multiple states. These applications were deployed to target 2,993 victims, facilitating 9,192 fraudulent banking transactions that accumulated total financial losses of ₹63,69,68,174.
Disruption of Underground Cyber Supply Chain and Mass Seizures
During the raid and subsequent arrest, law enforcement officers recovered a vast cache of digital evidence and physical hardware, including 10 mobile phones, one laptop, seven SIM cards, four debit and credit cards, and confidential banking records belonging to nearly 37,200 bank customers. Crucially, investigators also seized 967 ready-to-deploy fake APK files that had not yet been distributed to cybercrime groups.
Police officials emphasized that seizing these uncirculated applications effectively neutralized a major supply node in the underground cybercrime ecosystem. By intercepting the software before it reached active fraud operators, authorities prevented a fresh wave of large-scale financial intrusions nationwide. Investigators are currently auditing the compromised banking data of the 37,200 individuals to determine how the information was initially sourced and to alert the respective financial institutions.
Expert Advisory on Safeguarding Against Malicious APK Attacks
Evaluating the rise of application-based financial crimes, renowned cybercrime expert and former IPS officer Prof. Triveni Singh warned that malicious APK files have become one of the most destructive tools used by modern cybercriminals. He explained that fraudsters routinely impersonate essential services—including utility providers, power companies, banking institutions, and telecom operators—to trick users into downloading unverified files outside official application ecosystems.
Once installed, these rogue applications grant remote administrative permissions to attackers, allowing them to read incoming One-Time Passwords (OTPs), capture keystrokes, harvest contact lists, and control mobile banking platforms without the user’s knowledge. Prof. Singh advised citizens to never click on links embedded in SMS or instant messages urging the installation of software files, emphasizing that legitimate applications should only be downloaded from verified platforms such as the Google Play Store or Apple App Store. Law enforcement agencies are continuing their investigation to map Mandal’s buyer network and identify all regional syndicates that purchased his malicious software.
