Fake PNB APK trail leads to 4 Jamtara cyber fraud suspects


Daijiworld Media Network - Surat/Patna

Surat/Patna, Aug 11: The Surat City Cyber Crime Cell has arrested four alleged members of a Jamtara-based cyber fraud network from a hotel in Patna after tracing a fake ‘PNB One.APK’ file used to siphon Rs 5 lakh from a local victim.

The investigation has so far uncovered 336 malicious APK files linked to 31,174 installations, 5,613 compromised devices and cyber fraud amounting to Rs 125.39 crore across the country.

The arrests followed a technical investigation into a complaint regarding a Rs 5 lakh fraud reported in May. According to police, the victim received a fake ‘PNB One.APK’ file through WhatsApp.

After the application was installed, the accused allegedly gained access to the victim’s phone and transferred Rs 5 lakh from the bank account without the victim’s knowledge.

An FIR was registered at the Surat Cyber Crime Police Station under Sections 318(4), 336(2), 338, 336(3), 340(2), 61(2) and 3(5) of the Bharatiya Nyaya Sanhita, 2023, and Sections 66(c) and 66(d) of the Information Technology Act.

Additional Commissioner of Police (Crime) Karanraj Vaghela said the investigation initially focused on tracing the developer of the APK file.

Technical analysis led police to Uttar Pradesh, where they had earlier arrested Rohit, a resident of Kasganj district, who was allegedly the main developer supplying fake APK files to cyber criminals.

“Rohit was a developer who prepared APK files according to the demands of different cyber criminals. Whether it was SBI, Punjab National Bank, Axis Bank, HDFC Bank or UCO Bank, or names such as hospitals, RTO challans and customer support, he developed files designed to mislead victims and allow cyber criminals to access their accounts,” Vaghela said.

Police said analysis of Rohit’s laptop and mobile phone indicated that he had developed and supplied more than 121 APK files, with data linked to around Rs 64.38 crore in cyber fraud.

His interrogation and subsequent technical analysis led investigators to a gang operating from Jamtara in Jharkhand. The Surat cyber cell team travelled around 1,970 km to Jamtara and began searches in remote areas.

During the operation, technical surveillance indicated that the alleged main accused, Jahur Ansari alias Chand, was travelling by train.

Police followed him from Jamtara to Deoghar and then to Patna, travelling by road and train, before locating the suspects at a hotel in Patna. The entire operation involved a journey of about 2,456 km.

The four arrested accused were identified as Jahur Ansari alias Chand, 35, of Jamtara; Rajan Kumar, 19, of Aurangabad, Bihar; Adityaraj alias Aman, 19, of Rohtas, Bihar; and Sameer alias Shaktiman, 28, of Jamtara.

Police described Chand as a key link in the network and an alleged buyer and distributor of APK files.

Investigators said he had purchased about 1,248 APK files with source code from developers, paying around Rs 8,000 per file, and sold them to members of the Jamtara network for around Rs 10,000 each.

The fake ‘PNB One.APK’ involved in the Surat case was also allegedly supplied by Chand.

Rajan and Adityaraj were allegedly involved in developing and modifying APK files. Police said they had learnt the process from the previously arrested developer in Kanpur and subsequently supplied files to Chand.

Adityaraj allegedly edited and changed the designs of APK files and received payments for preparing files with source code. Sameer was allegedly involved as a technical supplier and distribution partner, providing source codes and helping distribute the APK files.

The investigation found that the network operated as a “supply chain”, with developers allegedly selling APK files to intermediaries, who then distributed them to cyber criminals.

Police said the files were created in the names of banks, government schemes, RTO challans, customer support services and hospitals, among others, and circulated through WhatsApp and Telegram.

Once installed, the fake applications could provide access to a victim’s SMS messages, contacts, call logs, photo gallery and banking information.

The stolen banking details were allegedly used to transfer money into mule bank accounts and mule credit cards. The proceeds were then allegedly converted into cash and moved through other accounts to conceal the trail.

Analysis of the 336 APK files linked to the arrested accused showed that the applications had been installed on 31,174 mobile devices.

Police found evidence that 5,613 devices had been accessed, with 1,06,643 debit transactions involving a total of Rs 1,25,39,48,187, or about Rs 125.39 crore.

The individual analysis of APK files linked to Chand included 59 RTO Challan files, associated with 11,056 installations and fraud transactions totalling about Rs 42.32 crore; 49 SBI files, linked to 5,303 installations and about Rs 31.15 crore; and 37 PNB files, associated with 2,548 installations and about Rs 10.77 crore.

The analysis also covered fake applications using the names of Axis Bank, Bandhan Bank, HDFC Bank, YONO, UCO Bank, PM-Kisan, Punjab & Sind Bank, City Union Bank, Canara Bank, Union Bank, customer support services, hospitals and other services.

Vaghela said the technical team had so far analysed only 336 of the approximately 1,248 APK files linked to Chand.

“From these 336 APK files, we have found that links were sent to around 31,000 people. After their mobile data and banking information were accessed, around bank transactions were carried out, involving cyber fraud of Rs 125 crore,” he said.

According to police, Chand and other members of the network allegedly moved proceeds from victims’ accounts to mule accounts and mule credit cards before cashing them out.

Police said the suspects had left Jamtara after learning through Surat City Police’s social media accounts that Rohit, the alleged developer, had been arrested.

The four then remained on the move before being traced to Patna. Six mobile phones and one laptop were seized from the accused.

Further investigation is under way into the financial links and other members of the network.

Police have advised people not to install APK files received through unknown WhatsApp messages, SMS or other links and to download applications only from the official Google Play Store or App Store.

They have also warned people against sharing banking credentials, ATM or card details, UPI PINs, net-banking passwords or OTPs.

Victims of cyber fraud have been advised to immediately call the national cybercrime helpline 1930 or report the incident through the National Cyber Crime Reporting Portal.

  

Top Stories


Leave a Comment

Title: Fake PNB APK trail leads to 4 Jamtara cyber fraud suspects



You have 2000 characters left.

Disclaimer:

Please write your correct name and email address. Kindly do not post any personal, abusive, defamatory, infringing, obscene, indecent, discriminatory or unlawful or similar comments. Daijiworld.com will not be responsible for any defamatory message posted under this article.

Please note that sending false messages to insult, defame, intimidate, mislead or deceive people or to intentionally cause public disorder is punishable under law. It is obligatory on Daijiworld to provide the IP address and other details of senders of such comments, to the authority concerned upon request.

Hence, sending offensive comments using daijiworld will be purely at your own risk, and in no way will Daijiworld.com be held responsible.