The Satellite That Isn’t There: Inside the Fake Internet Scheme Quietly Hijacking Phones Across India
By: Javid Amin | 27 July 2026

There is a particular kind of confidence trick that works precisely because it promises to solve a problem everyone actually has. Millions of Indian households, especially outside major cities, genuinely struggle with slow, patchy, or non-existent broadband. So when an advertisement appears showing a satellite dish perched on a picture-perfect hillside home, promising internet “anywhere in India — from cities to villages,” with no fiber and no cable required, it doesn’t sound like a scam. It sounds like relief.
That is exactly the point.
Investigators, cybersecurity analysts, and consumer-protection observers who track India’s fast-evolving fraud economy say this campaign follows a pattern that has become disturbingly routine over the past two years: a legitimate-sounding service, a hook priced to feel harmless, and a single, quiet request buried in the fine print of the conversation — install this file.
Anatomy of a Manufactured Trust
The advertisement itself deserves closer scrutiny, because very little of it is accidental. Every element has been chosen to manufacture credibility in the space of a few seconds of scrolling.
The dish is rendered in gleaming, professional-grade CGI, mounted on a home that looks aspirational rather than average — signaling quality without a single verifiable claim. The typography borrows the visual grammar of genuine telecom marketing: bold yellow call-outs, a red “Special Limited-Time Offer” ribbon, a gift icon suggesting a bonus rather than a transaction. Four small trust icons — a speedometer, a globe, a gear, a shield — do the psychological work of reassurance: fast, wide-reaching, easy, safe. None of them are backed by a company name, a license number, or a customer-service record that can be independently checked.
Then comes the call to action, phrased with disarming ordinariness: send your state, city, and PIN code, and “our team will check your coverage options.” It reads like customer service. It functions as a lead-qualification funnel — the first checkpoint in a process engineered to separate curious browsers from committed targets.
This is not amateur work. It is a deliberate imitation of legitimate onboarding, built by people who understand exactly what a real ISP advertisement looks like, and have reproduced its surface without any of its substance underneath.
The Pivot: From Advertisement to Installation
Once a user responds, the interaction shifts from “advertisement” to “instruction,” and this is the moment the scheme reveals its true purpose. Instead of a sign-up form, a technician visit, or a KYC document request — all standard for actual internet service activation in India — the user is asked to download and install an APK file sent directly through a messaging app.
This single step is the entire scam. Everything before it was theatre designed to get here.
An APK, or Android Package Kit, is simply the file format Android uses to install software. There is nothing inherently malicious about the format itself — it’s how every legitimate Android app is packaged. The danger lies entirely in the distribution channel. Apps downloaded from the Google Play Store pass through automated and human review processes designed to catch malicious behavior before it reaches a single user. Apps sent directly as files through WhatsApp, SMS, or a chat thread skip that entire filter. The user becomes the only checkpoint — and by the time they’re asked to install it, they’ve already been primed to trust the source.
Once installed, the app typically requests a cluster of permissions that have nothing to do with browsing the internet: access to SMS messages, contacts, storage, and sometimes accessibility services that allow an app to observe and control what happens on-screen. Framed as “activation requirements,” these permissions are in fact the technical foundation for surveillance and theft.
The final instruction — take a screenshot and send it back — completes the manipulation. It has no functional purpose for “activating” an internet service. Its real function is behavioral compliance: getting the victim to complete a small, harmless-seeming action that confirms they’ve followed every instruction so far, making them more likely to comply with whatever comes next.
Why ₹199 Is Not an Accident
Every number in a well-run scam is chosen, not guessed. The advertised price — a free three-month trial followed by ₹199 a month — sits in a very specific psychological zone: low enough to feel like an impulse decision rather than a financial commitment, but not so low that it feels obviously fake to someone unfamiliar with telecom pricing.
Set against reality, the number collapses. Functioning satellite broadband requires a ground terminal, licensed spectrum access, and regulatory approval to operate as a telecom service provider in India — a status that remains tightly controlled by the Department of Telecommunications, with even large, internationally established satellite operators having faced years of regulatory review before being permitted to serve Indian customers. None of that infrastructure or paperwork is compatible with a ₹199 monthly fee activated through a chat message. The price isn’t a bargain. It’s bait sized to match the emotional register of the offer: cheap enough to say yes to before thinking too hard about why.
The Bigger Machine This Belongs To
What makes this scheme worth taking seriously isn’t its originality — it has almost none. It is a rebranded version of a fraud template that has already been used, with only cosmetic changes, across dozens of other disguises in India over the past three years: fake bank KYC updates, fraudulent electricity bill notices, counterfeit wedding invitations, phony traffic challan notices, and bogus reward-point redemption offers.
In every version, the mechanics are identical — a message designed to create either urgency or opportunity, a request to install a file outside official app stores, and a follow-up action to confirm compliance. Cybercrime investigations into similar APK networks have traced individual operations to tens of thousands of installations and financial losses running into tens of crores of rupees, often organized through interstate networks where app development, distribution, and cash withdrawal are handled by entirely separate groups — making individual scams like this one difficult to trace back to a single source, even when victims report losses.
The “satellite internet” version is notable mainly for its target demographic: rural and semi-urban households actively seeking better connectivity, a group that is both highly motivated to say yes and, in many cases, less exposed to prior warnings about APK-based fraud than urban banking customers who have already been targeted by years of similar bank-impersonation campaigns.
What Happens After the Screenshot
For victims who complete the installation and send the requested screenshot, outcomes generally fall into one of a few patterns documented in comparable cases:
- Silent data harvesting, where the app quietly collects contacts, messages, and files in the background without any visible consequence for weeks — used later for targeted follow-up scams or sold onward.
- Direct financial fraud, where intercepted SMS messages and one-time passwords are used to authorize unauthorized banking or UPI transactions.
- Escalation requests, where victims are later contacted about additional “activation charges,” “installation fees,” or “verification deposits” to unlock the promised service — payments that vanish along with the scammer.
- No service at all, in the simplest version of this fraud, where the “trial” was never real and the entire exchange existed solely to get the app installed.
A Field Guide to Recognizing the Pattern
The specific disguise will keep changing — next month it might be solar subsidies, cashback wallets, or a government scheme. The underlying structure rarely does. Four warning signs recur across nearly every version of this fraud:
- The pricing feels engineered, not researched. Real telecom or utility pricing accounts for infrastructure cost. A number that only seems designed to feel affordable is a signal, not a bargain.
- The install path avoids official app stores. Any request to sideload an APK file directly, rather than download through Google Play, should be treated as an immediate red flag — regardless of how official the sender appears.
- “Activation” requires proof rather than payment or documentation. Legitimate services verify identity through KYC, billing addresses, or account credentials — not screenshots sent to a chat thread.
- There is no verifiable company behind the offer. No licensing information, no traceable customer service number, no listing with regulatory bodies — just a WhatsApp thread and a slick graphic.
If You’ve Already Engaged With This Offer
Time matters more than panic here. If you’ve installed the APK, sent a screenshot, or shared personal details:
- Uninstall the application immediately, and avoid opening it again in the meantime.
- Disconnect the device from Wi-Fi and mobile data temporarily to limit further data transmission.
- Change passwords for banking, UPI, and email accounts from a separate, trusted device — not the potentially compromised phone.
- Review recent bank and UPI transaction history closely over the following weeks, not just the following days.
- Report the incident to India’s National Cybercrime Helpline (1930) or through cybercrime.gov.in, and retain screenshots of the original advertisement and conversation as evidence.
- Avoid forwarding the offer to friends or family before confirming it’s fraudulent, even with good intentions — sharing amplifies the same trap.
The Larger Warning
What this scheme really exposes isn’t a single fake advertisement — it’s how easily the visual language of legitimate business can be reverse-engineered by people with no legitimate business at all. A dish, a discount, a deadline, and a decent font are apparently all it takes to get past most people’s guard, at least long enough to get one file installed.
There is no licensed satellite internet provider in India offering activation through a sideloaded Android app and a screenshot. Until that changes — and it structurally cannot, given how tightly regulated telecom licensing is — any offer built around that mechanic should be treated as what it is: not a connectivity solution, but a collection mechanism, quietly designed to take far more than ₹199 a month.
This report is intended for public awareness and cybersecurity education. If you suspect you have been targeted by this or a similar scheme, contact India’s National Cybercrime Helpline at 1930 or file a report at cybercrime.gov.in without delay.

