Overview
- Police in Ahmedabad, Mumbai and Delhi arrested suspects and seized devices and servers in connected probes that produced major arrests on Thursday and Friday this week.
- Investigators recovered hundreds of fake APK files, server credentials and a database of roughly 1.24 crore SMS records that investigators say link thousands of victims to the scheme.
- Authorities say developers sold malicious APK templates by subscription through Telegram bots for about Rs 12,000 a month and that dozens to hundreds of buyers used the tools to compromise phones.
- Once installed the APKs could read SMS and notifications, intercept one-time passwords and harvest banking details, enabling cash withdrawals through services such as SBI YONO Cash and purchases of electronics and gift cards to hide proceeds.
- The operation traces to the Jamtara/Giridih phishing belt and began in 2025; police warn the public not to install APK or ZIP files from unknown sources, to never share OTPs, and to report incidents to the cyber helpline 1930 as investigations continue.