Ahmedabad Cyber Crime Busts Jamtara APK Fraud Gang, Mastermind Arrested From Moving Train

Contents

Published July 1, 2026 · 6 min read · Gujarat / Jharkhand

A malicious app, a nationwide network of victims, and a mastermind finally caught mid-journey on a train from Kolkata — the Ahmedabad Cyber Crime Cell’s latest bust reads like a thriller, but it exposes something more important: how India’s most infamous cybercrime hub has evolved from phone-call scams to full-blown malware operations.

3Accused arrested

28Mastermind’s age

Kolkata → SrirampurArrest location

Pan-IndiaVictim spread

What Happened

The Ahmedabad Cyber Crime Cell has busted an alleged inter-state fraud syndicate based out of Jamtara, arresting three accused — including the man police describe as the mastermind. The gang allegedly developed malicious Android application package (APK) files designed to steal victims’ banking credentials and siphon money out of their accounts, with victims reported across multiple states in India.

The mastermind, identified as Purnanand alias Mukesh Tiwari (28), was arrested in dramatic fashion — not from a hideout or safehouse, but from aboard a moving train travelling from Kolkata toward Srirampur. Ahmedabad Cyber Crime officers coordinated with the Railway Protection Force (RPF) to make the arrest while the train was still in motion, suggesting Tiwari may have been attempting to relocate or evade capture when he was intercepted.

Why Jamtara, Again?

Jamtara, a small district in Jharkhand, has become almost synonymous with organized phone-based fraud in India over the past several years — so much so that it inspired a Netflix series of the same name. What this case shows is that the region’s fraud economy hasn’t disappeared; it has evolved. Where earlier Jamtara-linked scams relied heavily on cold calls and social engineering over the phone, this case involves the deployment of malicious software — a more technically sophisticated and more scalable method of stealing money.

This shift matters. A phone-based scam needs one fraudster actively working one victim in real time. An APK-based scam can be distributed to thousands of potential victims simultaneously, with the malware doing the credential-stealing work automatically once installed — turning what used to be a labor-intensive con into something closer to an industrial operation.

How APK Fraud Typically Works

  1. Distribution: Victims are sent a link — often via SMS, WhatsApp, or a phishing call — urging them to download an app, frequently disguised as a courier tracking tool, a bank utility, KYC update tool, or government service app.
  2. Installation: Because the file is a direct APK rather than something from the Play Store, it can request broad device permissions that legitimate apps would rarely need — including reading SMS messages, which is critical for intercepting OTPs.
  3. Credential harvesting: Once installed, the app can silently capture banking credentials entered on legitimate banking apps, or present convincing fake login screens designed to look identical to real banking interfaces.
  4. OTP interception: With SMS-reading permissions granted, the malware can intercept one-time passwords sent by banks, allowing fraudsters to authorize transactions without the victim’s knowledge.
  5. Money movement: Stolen funds are typically moved rapidly through layers of mule accounts before victims even realize the theft has occurred, making recovery difficult.

The train arrest isn’t just a dramatic detail — it reflects how mobile and difficult to pin down cybercrime masterminds have become, often operating across multiple states with no fixed base.

Why This Case Matters

This bust is significant for a few reasons beyond the immediate arrests. First, it confirms that Jamtara-linked networks are actively investing in malware development, not just relying on legacy social engineering tactics — a sign that India’s cybercrime hubs are professionalizing rather than being stamped out by years of enforcement attention.

Second, the inter-state nature of the operation — a Jharkhand-based network with victims spread across India, a mastermind intercepted between West Bengal towns, and the case ultimately broken by a Gujarat cyber cell — illustrates just how geographically distributed modern cyber fraud investigations have to be. No single state police force can meaningfully tackle these networks in isolation; cases like this depend on inter-state coordination and intelligence sharing.

Third, the successful arrest of the alleged mastermind — often the hardest person to catch in these networks, since they typically stay several layers removed from on-ground operatives and mule account holders — represents a real disruption to the gang’s operating capacity, not just a symbolic win.

The bigger pattern: This case fits into a broader trend visible across recent cybercrime enforcement — Indian cyber cells increasingly chasing masterminds and infrastructure (APK developers, mule account networks, fake app distributors) rather than only prosecuting the low-level operators who make the calls or send the messages.

How to Protect Yourself From APK-Based Fraud

  • Never install an app from a link sent via SMS, WhatsApp, or email — only download apps from the official Google Play Store or Apple App Store.
  • Be suspicious of any app requesting permission to read your SMS messages or notifications, especially apps unrelated to messaging.
  • Disable “install from unknown sources” in your phone’s settings unless you specifically need it for a trusted purpose.
  • If you’ve already installed a suspicious APK, uninstall it immediately, change your banking passwords, and contact your bank to flag your account.
  • Report suspected fraud immediately to the national Cyber Crime helpline (1930) or via cybercrime.gov.in.

Based on public statements from the Ahmedabad Cyber Crime Cell. This report is for informational purposes; details may be updated as the investigation progresses.


Picture of Adarsh Singhal & Associates
Adarsh Singhal & Associates

Leave a Reply

Your email address will not be published. Required fields are marked *