Malicious APKs Stored on VPS, Techie Arrested

www.news4hackers.com-malicious-apks-stored-on-vps-techie-arrested-malicious-apks-stored-on-vps-techie-arrested

Mumbai Police have arrested a web developer from Haryana for allegedly enabling cybercriminals by providing a virtual private server to host harmful Android apps.

Arrest and Investigation Details

The accused, a web developer from Haryana, was detained at Taloja Prison. The case involves a scheme where malicious software was distributed via a remote server, resulting in financial losses for victims.

The Scam Unveiled

A senior citizen from Cuffe Parade fell victim to a fraudulent gas bill update scam in July. A 75-year-old homemaker received a call from someone claiming to represent Mahanagar Gas Ltd. The caller alleged an unrecorded payment and requested a ₹3 fee. The victim complied, clicked on an SMS link, and installed a malicious app. Shortly after, ₹17.4 lakh was withdrawn from her bank account.

Investigation and Server Tracing

The victim reported the incident to the Cyber Crime Helpline 1930 and Azad Maidan police. Authorities analyzed the malicious APK file and traced it to a virtual private server managed by the accused. The server, located in Haryana, was provided without KYC verification. Investigators found 25,200–26,000 files, many linked to fraudulent apps. The accused is suspected of knowing about the illicit activities.

Server Function and Malware Distribution

The server acted as a centralized repository for malware, used by cybercriminals to deploy apps that extract sensitive data from mobile devices. The accused remains detained, while investigators continue analyzing the server and tracing the fraud network.

Cybersecurity experts advise against clicking unsolicited links or downloading APK files from unknown sources, especially when prompted by requests for small payments or urgent account updates.

Conclusion and Cybersecurity Advice

The incident underscores the risks of unsecured remote servers and the importance of user vigilance. Authorities emphasize the need for stricter KYC processes for server providers and public awareness about phishing scams.



About Author

en_USEnglish