Surat Police arrested a 43-year-old man after tracing part of a ₹6.31 lakh malicious-APK fraud through credit cards to an alleged Jamtara-linked network.

Malicious APK Drains Lakhs; Surat Police Trace Money to Jamtara-Linked Network

The420 Web Correspondent
8 Min Read

A seemingly ordinary APK file allegedly gave cybercriminals access to a victim’s phone and helped them siphon more than ₹6.31 lakh through eight unauthorised transactions, leading Surat Police to arrest a 43-year-old man accused of helping convert part of the stolen money into cash.

The arrested accused has been identified as Din Mohammad Sheikh, a resident of Bhestan in Surat who originally belongs to Muzaffarnagar district in Uttar Pradesh.

Police say Sheikh was not necessarily the person who sent the malicious application or operated the front-end scam. His alleged role came later in the financial chain.

Investigators claim ₹2,28,226.68 of the victim’s stolen money was routed through his Axis Bank and Canara Bank credit cards. Sheikh allegedly kept 10% as commission and passed the remaining amount to an absconding co-accused.

Algoritha Security Launches ‘Make in India’ Cyber Lab for Educational Institutions

One APK File, Eight Transactions and ₹6.31 Lakh Gone

The investigation began after the victim allegedly received and installed an APK file on his Android phone.

Police say the malicious application enabled the fraudsters to access sensitive information on the device and subsequently conduct around eight transactions without the victim’s knowledge.

The total loss was ₹6,31,414.68.

After discovering the fraud, the complainant contacted the National Cyber Crime Helpline at 1930, following which Surat Cyber Crime Cell began tracing the technical and financial trail.

An FIR was registered under several provisions of the Bharatiya Nyaya Sanhita, including cheating and forgery-related sections, along with Section 66D of the Information Technology Act, which deals with cheating by personation using a computer or communication device.

The investigation then moved from the compromised phone to the destination of the stolen money.

That trail allegedly led officers to Sheikh.

What Is an APK and How Can a Fake One Steal Money?

APK stands for Android Package Kit.

It is the file format used to install applications on Android phones. Genuine Android apps also use APK files, so an APK is not automatically dangerous.

The problem starts when criminals send a modified or malicious APK outside trusted app stores.

A victim may receive a file labelled as a bank KYC update, traffic challan, insurance document, electricity bill or government service app. Once installed, the application can seek powerful permissions that a normal document should never need.

Depending on the malware, those permissions may allow it to read SMS messages, display fake login screens, capture information or remotely interact with the device.

That can expose banking alerts and OTPs.

In the Surat case, police allege that the malicious application helped the attackers obtain enough access to carry out the unauthorised bank transactions.

The key safety distinction is important: not every APK is malware, but an unsolicited APK sent over WhatsApp, SMS or social media should be treated as highly suspicious.

Credit Cards Allegedly Became a Money-Laundering Tool

The unusual feature of this case is how part of the stolen money was allegedly processed.

Police say Sheikh provided his Axis Bank and Canara Bank credit cards so that around ₹2.28 lakh could be routed through card-bill settlements.

The mechanism appears designed to convert digital fraud proceeds into money that can be redistributed.

Sheikh allegedly retained around 10% as commission.

The remaining amount was allegedly passed to an absconding accused, after which money was deposited through cash deposit machines into personal bank accounts connected, according to police, with a Jamtara-based cybercrime network.

That makes Sheikh’s alleged role similar to a money mule.

A money mule is someone who allows bank accounts, cards or other financial instruments to be used for receiving, moving or converting criminal proceeds.

The mule may not carry out the original scam.

But by helping move the money away from the victim and towards the main operators, the person becomes an important link in the laundering chain.

Surat Has Already Uncovered a Much Larger APK Ecosystem

The arrest comes only weeks after Surat Police uncovered another major malicious-APK network.

In August, police arrested four alleged members of a Jamtara-linked gang after an investigation into a fake “PNB One.APK” used in an earlier ₹5 lakh fraud.

That probe eventually uncovered 336 malicious APK files, more than 31,000 installations, 5,613 compromised devices and fraud valued at around ₹125.39 crore across the country.

A related Surat investigation in July had also led to the arrest of an 18-year-old accused of developing malicious Android applications.

Police alleged that 121 APKs developed by him had been installed on more than 21,000 phones. Investigators linked the compromised devices to over 54,000 fraudulent banking transactions worth about ₹64.38 crore.

Those figures show why APK scams are no longer just isolated cases of someone clicking the wrong file.

Police increasingly describe an organised ecosystem in which one person develops malware, another distributes it, others control compromised phones, and separate money mules move the stolen funds.

Why Calling 1930 Quickly Can Matter

The victim in the present case contacted the cybercrime helpline after discovering the unauthorised transactions.

Speed matters because financial cybercrime investigations often become a race against the movement of money.

India’s Citizen Financial Cyber Fraud Reporting and Management System links law enforcement agencies and financial institutions so suspicious funds can potentially be intercepted before criminals move them through multiple accounts.

The Union Home Ministry said that, by June 30, 2026, more than ₹11,158 crore had been saved across over 32.8 lakh complaints through the system. The 1930 helpline is part of that mechanism.

Whether any portion of the ₹6.31 lakh in the Surat case can ultimately be recovered has not yet been disclosed.

Police are still searching for the main accused believed to be connected with Jamtara and are examining credit-card transactions, cash deposits and bank accounts to identify other members of the network.

The allegation against Sheikh has not yet been established in court.

What this means for you: Never install an APK received unexpectedly through WhatsApp, SMS or social media, even if the message mentions KYC, a traffic challan, insurance or a government service. If money leaves your account without permission, immediately call 1930 and report the fraud before the funds are moved through additional accounts.

https://www.linkedin.com/company/policetechnology/

Stay Connected