An 18-year-old was arrested by Surat Cyber Crime Police for allegedly developing 121 fake APKs linked to a ₹65 crore cyber fraud that targeted banking and digital payment users across India.

Teen Learns Malware Development Through YouTube and AI Tools, Allegedly Creates 121 Fake APKs Used in ₹65 Crore Cyber Fraud

The420.in Staff
4 Min Read

Surat, Gujarat: The Surat Cyber Crime Police have uncovered a large Android malware operation and arrested an 18-year-old from Uttar Pradesh for allegedly developing 121 malicious Android Application Package (APK) files that were supplied to the Jamtara cyber fraud network and used in banking and digital payment scams across India. According to investigators, the fake applications were downloaded by 21,672 users, while 2,928 victims allegedly lost a combined ₹65 crore after installing them.

Police identified the accused as Rohit Sakya (18), a resident of Kasganj, Uttar Pradesh, who had completed education up to Class 11. Investigators alleged that he learnt to create malware-infected APK files through YouTube tutorials and artificial intelligence (AI)-based tools before selling them to cybercriminals on a monthly subscription model, charging ₹15,000 per APK.

The investigation began after a Surat resident downloaded a fake PNB One mobile application and allegedly lost ₹5 lakh from his bank account. Acting on the complaint, the Surat Cyber Crime Police conducted digital forensic analysis, examined server logs, domain records and other electronic evidence, eventually tracing the developer of the malicious application.

India’s Largest Cybercrime Conference Nears: FutureCrime Summit 2026 Set for 6–7 August at Bharat Mandapam

During the investigation, police arrested the accused from a hotel in Kanpur, where he had reportedly gone to meet his girlfriend. Investigators alleged that Sakya’s role was to develop the fake applications, while different cyber fraud groups used them to target victims across the country. The role of other suspects and members of the Jamtara cybercrime network remains under investigation.

According to police, the 121 malicious APKs impersonated several well-known banks, government schemes and popular consumer brands. These included fake versions of PNB One, SBI, Axis Bank, UCO Bank, American Express, BigBasket, DMart, PM-Kisan, Pension, RTO Challan, Campa, and Customer Support applications. The fake apps were designed to closely resemble genuine applications in order to persuade users to install them. Once installed, they allegedly enabled cybercriminals to access sensitive information, including banking credentials, one-time passwords (OTPs) and other personal data stored on victims’ mobile devices.

Renowned cybercrime expert and former IPS officer Prof. Triveni Singh said cybercriminals are increasingly relying on fake mobile applications, rather than only phishing links, to gain access to victims’ financial information. He advised users to download banking, government and financial service applications only from official app stores or authorised sources and warned against installing APK files received through WhatsApp, Telegram, SMS or other unofficial links.

FCRF Launches Certified AI-Powered SOC Analyst Program to Train the Next Generation of Cyber Defence Professionals

Cybersecurity experts noted that while AI tools and online learning platforms have legitimate educational and professional uses, they can also be misused to develop malicious software. The case highlights the growing need for stronger cyber awareness, secure app installation practices and enhanced digital hygiene among smartphone users.

The Surat Cyber Crime Police said forensic examination of seized digital devices, online payment records, server infrastructure and other electronic evidence is continuing. Investigators are also examining the distribution network, hosting infrastructure and financial transactions linked to the fake APK ecosystem to identify other individuals and organised cybercrime groups involved. Police said further arrests and legal action may follow based on the findings of the ongoing investigation.

Stay Connected