Gujarat Police Bust Jamtara Cybercrime Network, 3 Arrested

Ahmedabad (IANS): The Ahmedabad Cyber Crime Branch arrested three members of a Jharkhand-based cyber fraud network. The suspects allegedly created and distributed malicious Android application package (APK) files, which allowed criminals across the country to gain unauthorized access to mobile phones and steal money from bank accounts.

The arrests include the developer of the APK files, Purnanand alias Mukesh Tiwari, 28, of Giridih district in Jharkhand. The Cyber Crime Branch, with assistance from the Railway Protection Force, apprehended Tiwari from a moving train near Kishanganj. Police also arrested two other accused individuals, whom they identified as Vikas Das, 33, and Sitaram Nakul Mandal, 26.

The Victim’s Complaint

Senior officials supervised the case investigation after Naresh Sabnani, a resident of Ahmedabad’s Hansol area, lodged a complaint. According to police, Sabnani received a WhatsApp message from scammers impersonating Sabarmati Gas Limited. The message warned that the company would disconnect his gas connection unless he updated a pending bill. The text directed him to contact a supposed bill update officer and download an application named “Sabarmati Gas Bill Update.apk”.

Police stated that the complainant downloaded the APK file and subsequently lost Rs 6,68,914 from his HDFC Bank account through a series of fraudulent transactions. Following the incident, the complainant registered a report with the 1930 Cyber Helpline and the Cyber Crime Police Station. Authorities registered the complaint under Sections 319(2), 318(4), 61(2)(A), and 54 of the Bharatiya Nyaya Sanhita, 2023, alongside Sections 66(C), 66(D), 43, and 66 of the Information Technology Act.

Developing the Scam

Addressing a press conference, Dr. Sinha said: “After downloading the APK file, the hackers breached the complainant’s phone and withdrew Rs 6.68 lakh from his account. During the investigation, we achieved significant success by arresting one of the main accused, who developed the APK file. Along with him, we arrested two other suspects. All three hail from the Giridih-Jamtara belt of Jharkhand.”

Investigators noted that technical analysis and intelligence gathering led them to Tiwari. He allegedly developed malicious APK files and operated a Telegram bot to market and distribute the software to cybercriminals.

“The main accused developed APK files and Telegram bots. We have exposed how criminals misused these bots during the investigation,” Sinha said.

Police revealed that the Telegram bot contained options including “Download APK File”, “Replace APK”, “View My APKs”, “Purchase New APKs”, and “Renew Existing APKs”. Users could purchase templates impersonating trusted services such as SBI KYC, SBI Rewards, Bank of India, Bank of Baroda, Indian Overseas Bank, Union Bank, Yes Bank, Central Bank of India, City Union Bank, Axis Bank, Federal Bank, IndusInd Bank, Saraswat Bank, RTO e-challans, BSES bill updates, and Mahavitran electricity services.

Investigators found that Tiwari had created APK files impersonating at least 18 banks. Police also recovered APK files linked to customer support services, RTO e-challan systems, and other entities from devices they seized during the investigation.

“He sold these APK files for Rs 12,000 per month. On average, he maintained between 300 and 400 clients every month. Through these subscriptions, he earned approximately Rs 40 lakh to Rs 50 lakh per month,” Sinha said.

Distributing and Laundering the Money

Police stated that Vikas Das acted as a supplier who distributed the APK files to buyers. He allegedly received payments through SBI’s YONO Cash facility, which allows cardless ATM withdrawals. Investigators found that buyers shared YONO Cash details—including OTPs and transaction codes—allowing Das to withdraw cash from SBI ATMs.

“Vikas Das withdrew the money, kept a commission of Rs 3,000, and personally handed over the remaining amount to Purnanand Tiwari in Mumbai,” Sinha said.

Meanwhile, investigators revealed that Sitaram Mandal supplied APK files to other fraudsters and arranged the debit and credit card details used to receive and move fraud proceeds.

Police also uncovered what they described as a new exploitation of SBI’s YONO Cash service.

“The fraudsters exploited the YONO Cash facility, which allows ATM withdrawals without a physical card. Even if the account belonged to someone in Assam or Guwahati, the criminals could withdraw money in Surat. We arrested the accused when they arrived to make such withdrawals,” Sinha said.

Criminal Backgrounds

According to investigators, all three accused belonged to the same region and knew each other personally. Tiwari allegedly began developing APK fraud tools in August 2025 after previously involving himself in electricity bill scams. Police noted that authorities had earlier arrested him twice in cybercrime cases related to electricity bill fraud.

“The main accused previously participated in electricity bill scams in the Jamtara belt and police had arrested him twice. He began the APK fraud operation in 2025,” Sinha said.

Investigators stated that Das and Mandal also carried criminal records. Before entering APK-based fraud, they allegedly participated in OTP fraud operations. Police noted that Mandal previously worked as a caller who contacted victims and deceptively obtained their OTPs.

“All three have histories linked to cyber fraud. Before entering APK fraud, the other accused engaged in OTP fraud,” Sinha said.

According to police records, authorities in Prayagraj, Uttar Pradesh, want Das for two cybercrime cases. Meanwhile, police in Giridih district, Jharkhand, have named Tiwari and Mandal in multiple cybercrime cases involving cheating, forgery, criminal conspiracy, and offenses under the Information Technology Act.

How the Malware Works

Investigators stated that the fraudsters disguised the malicious applications as legitimate services, including gas bill updates, bank KYC verification, credit card applications, customer support systems, electricity bill services, government schemes, e-challans, and even wedding invitations.

“An APK file can disguise itself as a wedding invitation, an RTO notice, a bank service, or any other trusted service. The identifying feature is the ‘.apk’ extension. If you receive such a file through WhatsApp, social media, or text messages from an unknown source, never download it,” Sinha warned.

Police explained that once a user installs the applications, the software gains unauthorized access to SMS messages, contacts, call logs, notifications, and banking credentials. The tool enables fraudsters to intercept OTPs, steal user IDs and passwords, remotely monitor devices, and conduct unauthorized banking transactions. Investigators also found that the APK files could spread automatically from one victim to another.

“After the software compromises a device, it automatically forwards the APK file to all WhatsApp and Telegram groups associated with that user. If another recipient downloads it, the system repeats the same process. It functions like a chain reaction and can reach thousands of people within a short period,” Sinha said.

The Arrest and Next Steps

During the investigation, police recovered APK files impersonating Bank of India, DBS India, customer support services, and other organizations. They also seized information relating to domains, servers, email accounts, and the technical infrastructure the suspects used to operate the fraud network.

The main accused fled towards Kolkata after learning that police teams had reached Mumbai in search of him. Authorities ultimately caught him in transit.

“When our team reached Mumbai, he realized we were there and fled towards Kolkata. With assistance from the Railway Protection Force, officers identified him by a tattoo on his hand and arrested him from a moving train. We recovered no cash, but we seized devices containing crucial evidence,” Sinha said.

The Ahmedabad Cyber Crime Branch has so far linked the gang to 12 complaints registered through the National Cyber Crime Reporting Portal and five FIRs registered in Ahmedabad. The complaints involve alleged fraud totaling nearly Rs 70 lakh, with individual losses ranging from approximately Rs 5.19 lakh to Rs 15 lakh.

Sinha stated that investigators believe cybercriminals used the gang’s APK files across multiple states, and police are continuing their efforts to determine the full scale of the operation.

“We cannot say that this is the only mastermind behind APK fraud in the country, but he is one of the masterminds. His arrest will make an impact and help raise awareness of APK fraud. This marks the first time authorities have arrested these accused individuals specifically in connection with APK-based fraud,” she said.

She urged the public to install applications only from official app stores, avoid downloading APK files from unknown sources, never share OTPs or banking credentials, and immediately contact the cybercrime helpline or report the matter to the nearest police station if they accidentally download a suspicious file.

“Even if someone downloads an APK file by mistake, they should immediately report it by calling 1930 or approaching the nearest police station,” Sinha added.

 

Advertisements

🌐 Stay Connected with Avenue Mail

Get the latest news and breaking updates delivered instantly to your feed.

🟢Join our WhatsApp Group: Click here to join

🔵Follow us on Facebook: Click here to follow


📢 Avenue Mail: Your trusted source for real-time news.


Leave a Reply

Stay Connected

5,000FansLike
2,000FollowersFollow
8,000FollowersFollow
- Advertisement -

Latest Articles