spot_img
spot_img

336 Fake APKs Linked to Rs 125 Crore Cyber Fraud; Gujarat Police Arrest Four Jamtara Gang Members

Surat/Patna, August 11, 2026 (Yes Punjab News)

The Surat City Cyber Crime Cell has arrested four alleged members of a Jamtara-based cyber fraud network after tracing a fake “PNB One.APK” application used to siphon Rs 5 lakh from a victim. The investigation has so far uncovered 336 malicious APK files linked to 31,174 installations, 5,613 compromised devices and suspected cyber fraud transactions worth Rs 125.39 crore across the country.

The arrests followed a technical investigation into a fraud reported in May, in which the victim received the fake “PNB One.APK” file through WhatsApp. After installing it, the application allegedly enabled the accused to access the mobile phone and transfer Rs 5 lakh from the victim’s bank account.

An FIR was registered at the Surat Cyber Crime Police Station under Sections 318(4), 336(2), 338, 336(3), 340(2), 61(2) and 3(5) of the Bharatiya Nyaya Sanhita, 2023, along with Sections 66(c) and 66(d) of the Information Technology Act.

Additional Commissioner of Police (Crime) Karanraj Vaghela said the investigation initially focused on identifying the developer behind the malicious APK. Technical analysis led police to Uttar Pradesh, where they had earlier arrested Rohit of Kasganj district, allegedly the main developer supplying customised fake APKs to cyber criminals.

According to Vaghela, Rohit developed applications impersonating banks such as SBI, Punjab National Bank, Axis Bank, HDFC Bank and UCO Bank, besides creating files in the names of hospitals, RTO challans and customer support services.

Police said analysis of Rohit’s laptop and mobile phone showed that he had developed and supplied more than 121 APK files, with data indicating links to around Rs 64.38 crore in cyber fraud.

His interrogation and further technical investigation led the Surat team to a network operating from Jamtara in Jharkhand. Police travelled around 1,970 km to Jamtara and launched searches in remote areas.

During surveillance, investigators allegedly traced the movement of Jahur Ansari alias Chand, who was travelling by train. Police followed him from Jamtara to Deoghar and then Patna before locating the suspects at a hotel. The entire operation involved travel of around 2,456 km.

The four arrested accused have been identified as Jahur Ansari alias Chand, 35, of Jamtara; Rajan Kumar, 19, of Aurangabad, Bihar; Adityaraj alias Aman, 19, of Rohtas, Bihar; and Sameer alias Shaktiman, 28, of Jamtara.

Police described Chand as a key link in the network and an alleged buyer and distributor of malicious APK files. Investigators said he purchased around 1,248 APK files with source code from developers for approximately Rs 8,000 each and allegedly sold them to members of the Jamtara network for around Rs 10,000 apiece. The fake PNB One application involved in the Surat case was also allegedly supplied by him.

Rajan and Adityaraj allegedly developed and modified APK files after learning the process from the developer arrested earlier in Kanpur. Adityaraj allegedly altered application designs and prepared files with source code, while Sameer allegedly worked as a technical supplier and distribution partner.

The investigation indicates that the network functioned as a supply chain, with developers supplying APK files to intermediaries who distributed them to cyber criminals. The applications were allegedly created in the names of banks, government schemes, RTO challans, customer support services and hospitals and circulated through WhatsApp and Telegram.

Once installed, the fake applications could allegedly provide access to SMS messages, contacts, call logs, photographs and banking information. The stolen financial information was then allegedly used to transfer money to mule bank accounts and mule credit cards before the proceeds were converted into cash and moved through multiple accounts.

Analysis of the 336 APK files linked to the arrested accused showed 31,174 installations. Police found evidence that 5,613 devices had been accessed, with 1,06,643 debit transactions involving Rs 1,25,39,48,187, or approximately Rs 125.39 crore.

The individual analysis of APKs linked to Chand included 59 fake RTO challan applications associated with 11,056 installations and transactions totalling around Rs 42.32 crore; 49 SBI-related files linked to 5,303 installations and around Rs 31.15 crore; and 37 PNB-related files associated with 2,548 installations and approximately Rs 10.77 crore.

The investigation also covered fake applications using the names of Axis Bank, Bandhan Bank, HDFC Bank, YONO, UCO Bank, PM-Kisan, Punjab & Sind Bank, City Union Bank, Canara Bank, Union Bank, customer support services and hospitals.

Vaghela said investigators had so far analysed only 336 of the approximately 1,248 APK files allegedly linked to Chand. The cyber cell has recovered six mobile phones and one laptop from the four accused.

Police said the suspects left Jamtara after learning through Surat City Police’s social media accounts about Rohit’s arrest and remained on the move before being traced to Patna.

Further investigation is underway to establish the financial trail and identify other members of the alleged network.

Police have advised people against installing APK files received through unknown WhatsApp messages, SMS or other links and urged users to download applications only from official Google Play Store or App Store platforms. People have also been cautioned against sharing banking credentials, ATM or card details, UPI PINs, net-banking passwords and OTPs.

Anyone facing cyber fraud has been advised to immediately contact the national cybercrime helpline at 1930 or report the incident through the National Cyber Crime Reporting Portal.

YesPunjab Logo
YesPunjab has a WhatsApp Channel
Follow it for the latest updates and headlines.

Stay Connected

219,202FansLike
109,267FollowersFollow

Popular - Latest

spot_img
spot_img

Ajj Da Hukamnama

showbiz

SPORTS & GAMES

BUSINESS

transfers & postings

OPINIONS