18-Year-Old Arrested for Creating 121 Fake Apps Used in ₹64.38 Crore Scam

The420.in Staff
4 Min Read

Gujarat’s Surat Cyber Crime Cell has uncovered an alleged AI-powered cyber fraud network with the arrest of 18-year-old Rohit Virendrasinh Shakya, who is accused of developing malicious mobile applications that were allegedly used in cyber frauds worth more than ₹64.38 crore across India. According to police, Shakya, who dropped out after Class 11, taught himself coding at a young age and used artificial intelligence (AI) tools and Telegram channels to create fake mobile applications that closely resembled those of banks, government departments and private companies.

Police arrested the accused from a hotel in Kanpur, Uttar Pradesh. Investigators allege that he supplied customised malware to organised cybercrime syndicates operating in Jamtara (Jharkhand), Haryana and Rajasthan under a subscription model, charging ₹15,000 per month. Two mobile phones and a laptop have been seized from his possession, and all devices are undergoing detailed digital forensic examination.

India’s Largest Cybercrime Conference Nears: FutureCrime Summit 2026 Set for 6–7 August at Bharat Mandapam

According to investigators, Shakya allegedly developed two different types of applications. The first, referred to as the “victim app,” was disguised as an authentic banking or government application and was designed to trick unsuspecting users into installing malware on their smartphones. The second, known as the “admin app,” allegedly enabled cybercriminals to remotely access one-time passwords (OTPs), banking credentials, text messages and other sensitive information in real time, allowing them to execute fraudulent financial transactions.

Police said the fake applications closely imitated several trusted institutions and services, including State Bank of India (SBI), Punjab National Bank (PNB), Axis Bank, UCO Bank, ICICI Bank, Union Bank, American Express, BigBasket, Aadhaar services, PM Kisan and RTO challan payment portals. The objective was to deceive victims into believing they were downloading legitimate applications while secretly installing malware capable of compromising their devices.

The investigation began in May 2026 after a Surat resident reported losing ₹5 lakh in a cyber fraud. According to the complaint, the victim received a file named “PNB One.apk” through WhatsApp and installed it believing it to be the official Punjab National Bank application. Police said the malware immediately compromised the device, enabling cybercriminals to gain access to the victim’s banking information and transfer ₹5 lakh from his Prime Co-operative Bank account to another bank account. The victim promptly reported the incident through the national cybercrime helpline 1930, leading to the registration of an FIR and a detailed investigation.

Digital forensic analysis subsequently revealed what investigators described as a highly organised cybercrime ecosystem. Police said the accused had allegedly developed 121 malicious APK applications, which were installed on 21,672 mobile phones across the country. Investigators found that 2,928 devices were fully compromised, resulting in 54,094 fraudulent banking transactions involving approximately ₹64.38 crore. Among the fake applications, fraudulent RTO challan payment apps accounted for the largest number of cases, followed by fake SBI and PNB applications.

Investigators further alleged that the malware was distributed through Telegram to organised cybercrime syndicates under a subscription-based model that included periodic software updates, maintenance and technical support. Police are now examining whether additional cybercrime groups across India were using the software and whether more individuals were involved in the alleged network.

Renowned cybercrime expert and former IPS officer Prof. Triveni Singh said AI-powered fake mobile applications have emerged as one of the most dangerous tools available to cybercriminals. He advised users to download banking and government applications only from official websites or authorised app stores and never install APK files received through WhatsApp, Telegram, SMS or social media platforms, warning that such files can compromise bank accounts, personal data and digital identities.

Stay Connected