Cyber Crime
Fake Form 16 and Credit Card Calls Are Turning Into Dangerous APK Scams
Cybercriminals have once again allegedly used APK files as a tool to carry out online fraud. In two separate incidents in Noida, elderly victims were allegedly lured with offers of assistance in obtaining a credit card and accessing Income Tax Form 16 information before being persuaded to download APK files. Soon after the files were downloaded, a total of ₹17 lakh was transferred from their bank accounts. Both victims approached the Cyber Crime Police Station on Friday and filed complaints. Police are now examining the bank accounts, mobile numbers and transaction trails linked to the alleged fraud.
The first case involves a textile businessman from Sector 61. On May 18, 2025, Rajesh allegedly received a phone call from a person claiming to be a bank employee. The caller offered to help him obtain a credit card from home and told him that the application process could be completed online. During the conversation, the caller allegedly sent Rajesh an APK file, claiming it was required to complete the application.
Rajesh followed the instructions and downloaded the APK file. The caller subsequently told him that his credit card application had been successfully completed and that the card would be delivered shortly. However, the following day, ₹8 lakh was transferred from Rajesh’s bank account. He realised that he had allegedly fallen victim to a cyber fraud after noticing the unauthorised transactions.
The second case involves Hemant, a retired railway employee living in Sector 107. He had searched online for information related to Income Tax Form 16. On July 3, he allegedly received a call from a person who claimed that he could provide information and assistance regarding the form. The caller allegedly used this pretext to persuade Hemant to download an APK file.
After Hemant downloaded the file, ₹9 lakh was allegedly transferred from his bank account. He discovered the fraud after noticing the unauthorised withdrawal of funds. Following complaints from both victims, cybercrime investigators have begun examining the circumstances surrounding the two incidents.
APK, or Android Package Kit, is the file format used to install applications on Android devices. However, cybercriminals can misuse APK files to distribute malicious applications. Once installed, such applications may potentially allow criminals to access sensitive information, monitor device activity or manipulate victims into carrying out financial transactions.
Renowned cybercrime expert and former IPS officer Prof. Triveni Singh said cybercriminals are increasingly combining technology with social engineering to gain the trust of victims. Fraudsters often pose as bank employees, government officials or representatives of service providers and then persuade people to install APK files or other suspicious applications. He cautioned that downloading an application at the instruction of an unknown caller can expose users to serious financial and privacy risks.
In these two cases, the alleged fraudsters exploited different requirements of the victims. In one case, the lure involved a credit card, while in the other, the fraudsters used the victim’s search for Form 16 information. Such tactics allow criminals to create a sense of urgency and legitimacy before directing victims towards potentially malicious files.
Police are now tracing the mobile numbers used to contact the victims, the bank accounts that received the money and the subsequent movement of the funds. Investigators are also examining whether the ₹17 lakh was transferred to common accounts or moved through a connected network of mule accounts.
The possibility of a common cybercrime network is also being examined. If investigators find similarities between the mobile numbers, bank accounts, digital identifiers or transaction routes used in the two cases, they could help establish links between the incidents and identify additional members of the alleged network.
The investigation will also focus on the digital evidence available on the victims’ devices. Police may examine the APK files, installation records, communication history, mobile numbers and banking transactions to determine how the alleged fraud was executed and where the stolen money was ultimately transferred.
Cybersecurity experts advise people not to download APK files sent by unknown callers, even when the caller claims to represent a bank, the Income Tax Department or another government or financial institution. Information about such services should be obtained through official websites or verified channels. If a suspicious application is installed accidentally, users should immediately contact their bank, secure their accounts and report the incident to the cybercrime authorities.
Crime News
151 SIM Cards Linked to 212 Financial Fraud Complaints, Indore Police Launch Wider Probe
Police in Madhya Pradesh’s Indore have busted a cyber fraud network allegedly operating through the buying and selling of SIM cards. The investigation revealed that one SIM card was passed from its registered holder to several other people for money before eventually being used in cyber fraud. Police have arrested Rajesh Chaudhary, 42, in connection with the case and are searching for Bhagwandas alias Nana, Himanshu Junwal and Ashish Sharma.
How Did 151 SIM Cards Get Linked to 212 Fraud Complaints?
The case came to light during verification of suspicious data received from the Indian Cyber Crime Coordination Centre. Police found that 151 suspicious SIM cards linked to 49 point-of-sale holders and SIM-selling agents in the Indore urban area had been used in 212 financial fraud complaints registered across different states and cities.
Following the finding, investigators began examining the suspected numbers, their registered holders and the people involved in issuing and transferring the SIM cards.
During the investigation, one suspicious SIM was traced to Rohit Dalve, 27, a resident of Swarnbag Colony. During questioning, Dalve told investigators that he had issued the SIM on March 15, 2026, after completing the required document verification.
The SIM was issued in the name of Rajesh Chaudhary, 42, of Indore. Police subsequently questioned Chaudhary, leading investigators to uncover the chain through which the SIM allegedly changed hands.
How Did One SIM Pass Through Multiple Hands?
According to police, Chaudhary had obtained the SIM using his Aadhaar card but later handed it over to Bhagwandas alias Nana for ₹200.
Bhagwandas allegedly passed the SIM to Himanshu Junwal for financial gain and received around ₹500 in return. Investigators found that Junwal subsequently handed the same SIM to Ashish Sharma, who allegedly used the number for cyber fraud.
The investigation therefore revealed a chain in which the SIM moved from its registered holder to several individuals in exchange for money before reaching the alleged fraudster.
Such repeated transfers can make it difficult for investigators to immediately establish the identity of the person actually operating a SIM during a cybercrime.
How Were Victims Allegedly Trapped With Clothing and Franchise Offers?
Investigators found that the suspicious number was allegedly used to contact people with offers of jeans and pants at wholesale prices.
The accused allegedly collected money from customers but failed to supply the promised goods. In another method, victims were allegedly offered franchises for wholesale clothing businesses and asked to make payments.
The case was also linked to a complaint filed by Anil Kumar Gupta, a resident of Kheri district in Uttar Pradesh. According to the complaint, the accused allegedly offered him a franchise for a wholesale jeans and pants business.
They allegedly demanded ₹30,000 for the franchise and collected ₹10,000 from him as part of the deal. However, neither the promised franchise nor the goods were provided. Gupta subsequently filed a complaint on the National Cyber Crime Reporting Portal on May 27, 2026.
Who Has Been Arrested and Who Is Still Being Searched For?
Based on the complaint and findings from the investigation, MIG police registered a case and initiated further action.
Rajesh Chaudhary has been arrested, while Bhagwandas alias Nana, Himanshu Junwal and Ashish Sharma remain absconding.
Police are now examining the roles allegedly played by each person in obtaining, transferring and ultimately using the SIM card.
Is There a Bigger SIM Network Behind the Cyber Frauds?
Investigators are examining whether the 151 suspicious SIM cards linked to 212 financial fraud complaints were operated by a single organised network or were being used by multiple cybercrime groups.
Police are also looking into the wider network involved in the transfer and misuse of SIM cards, including the role of point-of-sale holders and SIM-selling agents linked to the suspicious numbers.
The case highlights the risks associated with SIM cards being obtained in one person’s name and subsequently handed over to others for money. Users should never sell, rent or hand over SIM cards registered in their name, as misuse of the number in cybercrime can bring the registered subscriber under investigation while making it harder for police to identify the actual fraudster.
AICybercrime
I4C Flags Fake Adult Apps That Could Turn Android Phones Into Fraud Tools
Cyber fraud is no longer limited to phone calls, messages or fraudulent links. The Indian Cyber Crime Coordination Centre (I4C) has warned Android users about malicious applications being promoted on social media platforms such as Facebook and Instagram by disguising them as adult-content apps.
Users who click on these advertisements are redirected to external websites and persuaded to download APK files from outside the Google Play Store. Once installed, the apps can seek sensitive permissions and attempt to gain access to the device and personal information.
Which Fake Apps Has I4C Flagged?
The I4C, which operates under the Ministry of Home Affairs, has flagged suspicious applications operating under names such as “Night Play”, “Reloop”, “Kyss”, “Vimo”, “Rivo”, “Nexo” and “Vixa”, among others.
These apps are reportedly promoted through social media advertisements offering users access to adult content. Clicking on the advertisements takes users to websites where they are instructed to download an application to view the content.
How Does the APK Fraud Begin?
The fraud begins when users are persuaded to install an APK file from an external website instead of downloading an application through the Google Play Store. After installation, the malicious application may request access to sensitive functions such as notifications, messages or other device features. The risk becomes particularly serious when users grant an unfamiliar application access to Android’s Accessibility Services.
Why Is Accessibility Permission So Dangerous?
Accessibility Services is designed primarily to assist people who have difficulty operating touchscreen devices. However, cybercriminals can misuse this functionality. According to cybersecurity experts, a malicious application with Accessibility access may be able to read information displayed on the screen, interact with other applications and potentially approve certain permission requests on behalf of the user.
This creates a direct threat to banking and digital payment information. Smartphones often contain banking applications, UPI accounts, one-time passwords (OTPs), private messages and other sensitive information. If a malicious application gains extensive control over such a device, attackers may potentially exploit that access to facilitate financial fraud.
Some variants of the malware may also download another package by disguising it as an application update. In certain cases, the malicious software may install a VPN and attempt to route internet traffic through servers controlled by attackers. Such activity can further compromise the security and privacy of an affected device.
What Warning Signs Should Android Users Watch For?
Cybersecurity experts have advised users to pay close attention to unusual activity after installing an unfamiliar application. A phone appearing to tap or interact on its own, an unfamiliar VPN icon appearing on the device, or an unknown application showing up under Accessibility settings could be warning signs of a possible compromise.
Experts have also warned that users may be more likely to trust advertisements appearing on familiar social media platforms. However, being redirected from a legitimate platform to an external website and then being asked to install an APK significantly increases the security risk. Cybercriminals are increasingly targeting users before a financial transaction takes place, using deceptive advertisements and applications to gain access to devices and sensitive information.
The I4C has advised Android users to download applications only from the Google Play Store or other trusted app stores. Users should avoid APK files received through advertisements, websites or suspicious links. They should also keep Google Play Protect enabled, regularly update their Android devices and periodically review the applications installed on their phones.
Users should immediately review and remove applications they do not recognise and avoid granting Accessibility access to unfamiliar applications. Particular caution is required when an application asks users to enable unusual permissions or follow instructions to bypass normal installation procedures.
Users should also regularly monitor their bank accounts and UPI transactions for unauthorised activity. If someone suspects that their device has been infected with malware or notices an unauthorised financial transaction, they should immediately contact their bank and report the incident through India’s cybercrime helpline at 1930.
The threat also extends beyond personal smartphones. Employees may use the same devices for work email, banking and personal activities, potentially exposing organisational information to malicious applications. Companies should therefore consider restricting app installation from external sources on devices that access sensitive corporate data and maintain a response plan for suspected compromises.
The latest warning highlights a simple but critical cybersecurity rule: users should never install an unfamiliar application merely because an online advertisement promises free or exclusive content. Downloading apps from trusted sources and carefully reviewing requested permissions can significantly reduce the risk of handing control of a smartphone to cybercriminals.
Cyber Crime
FutureCrime Summit Panel Explores Planning and Management of Cybersecurity Laboratories
As cybercrime becomes increasingly sophisticated, the ability to investigate and preserve digital evidence depends heavily on specialised infrastructure. This challenge was a key focus at the FutureCrime Summit 2026, where experts examined how organizations can plan, establish and manage effective cybersecurity and digital-forensics laboratories.
A panel discussion and workshop titled “Planning, Setting Up, and Managing a Cybersecurity Laboratory” explored the practical requirements involved in developing laboratories that can support digital investigations, forensic analysis, incident response and professional training.
The session featured Ajay Sariyal, Technical Product Specialist at MSAB; Abhinav Saurabh of Forensic Care; Sub-Inspector Saurabh Haritesh of Delhi Police; and Priya Choudhary. Their combined perspectives highlighted the importance of aligning technology, investigative requirements, personnel and laboratory management.
Cyber Labs Must Be Designed Around Their Mission
Establishing a modern cybersecurity laboratory involves far more than purchasing computers and forensic software. The facility must be designed according to the type of work it is expected to perform.
Depending on its purpose, a laboratory may support mobile-device examinations, digital evidence analysis, malware investigations, network forensics, cybercrime response or specialist training.
Infrastructure planning can include forensic workstations, specialised tools, secure networks, controlled-access areas and reliable systems for storing digital evidence. Each component must contribute to a workflow that protects the integrity and reliability of investigations.
For law-enforcement agencies, these requirements become particularly important because laboratories may handle evidence connected to criminal cases. Proper documentation, controlled evidence handling and repeatable examination procedures are therefore essential.
Skilled Investigators Remain Critical
The panel also underscored a fundamental point: advanced technology is only as effective as the professionals using it.
Digital-forensics personnel need the expertise to acquire, preserve, examine and interpret evidence while maintaining appropriate investigative procedures. Continuous training is equally important because digital devices, operating systems, applications and cyberattack techniques change rapidly.
Ajay Sariyal’s experience in mobile-device forensics brought a technology-focused perspective to the discussion. The participation of Abhinav Saurabh from Forensic Care added a forensic-services dimension, while Sub-Inspector Saurabh Haritesh represented the operational challenges faced by police investigators.
Together, these perspectives highlighted the need for cybersecurity laboratories to combine specialised technology with practical investigative expertise.
Laboratory Management Does Not End After Setup
Another important issue raised by the session was the need for sustained management once a laboratory becomes operational.
Cybersecurity and forensic facilities require ongoing maintenance, software upgrades, licence management, equipment replacement, secure storage and access-control reviews. Documented procedures must also be updated as investigative techniques and technologies evolve.
Growing caseloads can create another challenge. Laboratories must develop efficient workflows for prioritising examinations and managing evidence backlogs without compromising forensic standards or the reliability of findings.
This makes laboratory development a continuing institutional responsibility rather than a one-time investment in technology.
A Foundation for Modern Cybercrime Investigations
The FutureCrime Summit session highlighted that an effective cybersecurity laboratory depends on the interaction of technology, trained personnel, secure processes and long-term management.
As digital evidence becomes increasingly important in criminal investigations, organizations need facilities capable of handling complex and diverse forms of electronic information. A well-planned laboratory can provide investigators with the controlled environment and specialist capabilities required to examine digital evidence effectively.
The broader takeaway from the discussion was that the success of a cyber-forensics facility should not be measured simply by the number of tools it contains. Its real value lies in how efficiently its technology, personnel and procedures work together to support reliable investigations.
-
Business3 years agoPot Odor Does Not Justify Probable Cause for Vehicle Searches, Minnesota Court Affirms
-
Business3 years agoNew Mexico cannabis operator fined, loses license for alleged BioTrack fraud
-
Business3 years agoAlabama to make another attempt Dec. 1 to award medical cannabis licenses
-
Business3 years agoWashington State Pays Out $9.4 Million in Refunds Relating to Drug Convictions
-
Business3 years agoMarijuana companies suing US attorney general in federal prohibition challenge
-
Business3 years agoLegal Marijuana Handed A Nothing Burger From NY State
-
Business3 years agoCan Cannabis Help Seasonal Depression
-
Blogs3 years agoCannabis Art Is Flourishing On Etsy
