Table of Contents
Context: APK fraud is one of the fastest-growing cybercrime threats in the country today.
Current Status of Cybercrime in India (2025) |
|
What is an APK (Android Package Kit)
- APK (Android Package Kit) is the installation file format for Android apps, similar to .exe files on Windows.
- It contains all the elements (code, resources, certificates, permissions) required to install and run an app on Android devices.
How is APK Misused in Cybercrime?
- Fraudsters build or source these apps to mimic the appearance and language of official portals, including government subsidy schemes like PM-Kisan, tax refund platforms, electricity boards, or banks asking for KYC updates.
- Distribution: Spread via WhatsApp, Telegram, SMS, or social media with urgent messages.
- Permissions Abuse: Once installed, the app requests multiple permissions (contacts, SMS, notifications, location, microphone).
Theft
- Intercepts banking OTPs.
- Accesses contacts, call logs, and location.
- Harvests and transmits data to external servers in encrypted form.
Exploitation
- Unauthorised money transfers.
- Premature closure of fixed deposits.
- Layered laundering of funds through mule accounts and conversion into cryptocurrency.
What are the Investigational Challenges Associated With It
- Advanced Evasion Techniques: Fraudulent APKs use encryption, hidden code, and minor rebranding to bypass detection.
- Cross-Border Operations: Servers and masterminds are often located abroad (U.S., U.K., China), limiting India’s jurisdiction.
- Complex Money Trails: Funds move through mule accounts, layered transactions, and cryptocurrency, making tracking difficult.
Organised Crime Networks: Developers, distributors, and handlers operate separately, diffusing accountability. - Delayed Reporting & Low Awareness: Victims often realise late, by which time funds are irretrievable.
Different Initiatives By Indian Government To Tackle Cybercrime |
|