A 61-year-old fruit trader in Ahmedabad lost ₹5,67,700 after clicking a fraudulent SMS link that installed a malicious APK file on his smartphone.

  • Modus Operandi: Fraudulent SMS regarding traffic challan payment containing a malicious link.
  • Loss: ₹5,67,700 stolen from a 61-year-old businessman's bank account.
  • Technical Method: Installation of a fake APK file disguised as 'mParivahan'.
  • Police Action: FIR registered by Ahmedabad Cyber Cell under BNS and IT Act.

In a chilling instance of digital robbery, a 61-year-old fruit trader in Ahmedabad has fallen victim to highly sophisticated cyber criminals. Harish Rohra, a resident of the Makarpura area, lost a staggering sum of ₹5,67,700 after falling for a deceptive SMS regarding an unpaid traffic challan. This incident highlights the growing danger of malware-based phishing attacks in India.

The Anatomy of the Scam

The ordeal began on August 22, when Mr. Rohra received a text message from an unknown number. The message claimed that his vehicle had a pending traffic violation and provided a link for immediate payment. Unaware of the danger, the victim clicked the link, which triggered the download of a suspicious APK file on his mobile device. Although the file was disguised as the official 'mParivahan' app, it was actually a malicious piece of software designed to hijack his device.

Why This Matters

BozokMedia analysis shows that cybercriminals are increasingly moving away from simple phishing to 'Malware Injection' via APK files. Unlike standard links that steal credentials, these malicious apps can grant attackers remote access to the device, allowing them to intercept OTPs, read messages, and control banking applications in real-time without the user's knowledge.

A single click on an unverified link can turn your smartphone into a gateway for criminals to drain your entire life savings.

The theft did not occur immediately. The victim only realized the gravity of the situation on September 2, when he began receiving multiple alerts regarding unauthorized transactions from his bank account. Upon visiting the bank, he discovered that his savings had been systematically wiped out.

Investigation and Technical Details

The Ahmedabad Cyber Cell conducted a technical forensic analysis of the downloaded file. The investigation revealed that the APK package was named 'com.transport.gov.in', a clever attempt to mimic an official government domain to evade suspicion. The police have registered an FIR under various sections of the Bharatiya Nyaya Sanhita (BNS) and the Information Technology (IT) Act.

Historical Background: The Rise of APK Malware

Historically, cyber fraud in India primarily relied on 'Vishing' (voice phishing) and 'Smishing' (SMS phishing). However, there has been a massive shift towards 'Malware-as-a-Service,' where attackers use sophisticated APK files to bypass traditional two-factor authentication by reading SMS-based OTPs directly from the infected device.

Did You Know?: Official government agencies and traffic departments will never ask you to download an APK file via a direct link in an SMS.

Frequently Asked Questions

1. What should I do if I accidentally click a suspicious link?
Immediately turn off your internet connection, run a reputable antivirus scan, and monitor your bank accounts for any unusual activity.

2. How can I protect my smartphone from such attacks?
Never download apps from third-party links. Always use official stores like Google Play Store or Apple App Store, and keep your mobile OS updated.