Surat police uncover a sprawling cybercrime network involving fake Android package files, thousands of compromised devices, and a fraud worth over ₹125 crore, highlighting the dangers of malicious app distribution via WhatsApp and Telegram.
A WhatsApp message offering what looked like a bank app or a government service was enough to open the door to one of Gujarat’s biggest recent cybercrime investigations, according to Surat police. What began with a victim losing about ₹5 lakh has expanded into a wider case involving fake Android package kit files, thousands of compromised phones and alleged fraud running into more than ₹125 crore.
Police said the scam relied on malicious APK files disguised as legitimate apps for banks, RTO challans, customer support and public schemes. Once installed, the software could gain access to contacts, call logs, SMS messages and photos, giving attackers the information they needed to empty accounts and move the money through mule accounts and mule credit cards. Authorities say the files were spread mainly through WhatsApp and Telegram, making them appear routine and trustworthy.
The investigation first led officers to Kanpur, where they arrested 18-year-old Rohit Sakya, who was accused of building fake apps on demand. The Times of India reported that he had made 121 malicious APKs, which were downloaded by 21,672 users and sold to cybercriminals on a subscription basis. Bombay Samachar said investigators believe he supplied customised malware to criminal groups in several states, including Jamtara, Haryana and Rajasthan.
From there, police say the trail widened to a network in Jamtara and then to Bihar. Surat officers tracked a key suspect, Jahurul Ansari, also known as Chand, as he travelled by train and eventually detained him in Patna along with three others: Rajan Kumar, Adityaraj alias Aman and Sameer alias Shaktiman. According to police, Chand bought APK files and resold them to cyber fraud groups, while the others helped with development, design changes and distribution. The investigation has linked him to the sale of about 1,248 APK files.
The scale of the operation, police said, is striking. Officers said 336 APK files were found in the case data, installed on 31,174 devices, with access gained to 5,613 phones. They also cited 1,06,643 debit transactions linked to the network and estimated fraud of about ₹125.39 crore. RTO challan apps were said to be the most commonly used lure, with 59 such files reaching 11,056 devices and linked to transactions worth about ₹42.31 crore. Surat police have urged people to download apps only from official app stores and to ignore APK files sent through messages, even if they appear to come from banks, the government or transport authorities.
Disclaimer: This article is intended to inform and educate, not to recommend or endorse any financial product, investment or strategy. Please consider your own financial circumstances and seek professional advice where appropriate before making financial decisions.





