An 18-year-old Class 11 dropout allegedly used AI tools and YouTube tutorials to build 121 fake banking apps, enabling a ₹65 crore fraud network across India.

School Dropout Used AI, YouTube to Build Malware Empire Worth ₹65 Crore

The420 Web Correspondent
5 Min Read

In a quiet hotel room in Kanpur, Uttar Pradesh, law enforcement officers recently arrested an eighteen-year-old Class 11 dropout who had assembled one of India’s most sophisticated cybercrime operations. Operating under the radar, Rohit Virendrasinh Shakya allegedly leveraged artificial intelligence tools and self-taught software engineering skills to craft more than 120 malicious mobile applications. These cloned programs, which impersonated leading national banks and government portals, enabled cybercrime syndicates across multiple states to siphon off more than Rs 64 crore from unsuspecting victims.

The Architecture of a Malware-as-a-Service Enterprise

Investigators from the Surat City Cyber Crime Cell revealed that the suspect did not operate as a solitary hacker executing individual bank heists. Instead, Shakya established an enterprise model known in digital security circles as Malware-as-a-Service. By the age of sixteen, he had learned advanced programming through online video tutorials and generative AI tools, allowing him to construct dual-layered Android Application Packages (APKs).

The operation relied on a coordinated two-part software architecture. Unsuspecting users were lured into installing a counterfeit “victim application” disguised as authentic software from institutions like the State Bank of India, Punjab National Bank, Axis Bank, and official regional transport office portals. Simultaneously, an administrative app provided cybercriminals with real-time remote access to compromised devices, capturing One-Time Passwords (OTPs), personal identification numbers, and banking credentials without triggering security warnings.

Shakya monetised his software by distributing these malicious applications to established crime syndicates in Jamtara, Rajasthan, and Haryana through encrypted channels on Telegram. Charging a monthly subscription fee of approximately Rs 15,000 per customised application, he offered continuous technical support, server maintenance, and code updates designed to evade routine security patches.

Unravelling the Multi-State Digital Trail

The national network began unravelling in May when a resident of Surat reported losing Rs 5 lakh after receiving a malicious file via WhatsApp. Believing the attachment to be an official mobile banking update for PNB One, the victim installed the application, granting remote control to external operatives who drained his savings within hours. Prompt action through the national cybercrime helpline 1930 allowed forensic investigators to trace the digital signature of the APK file back to server infrastructure managed from Uttar Pradesh.

Subsequent digital forensic analysis uncovered the scale of the breach. Across India, the suspect’s fake applications had been installed on over 21,600 mobile devices, with nearly 3,000 smartphones suffering total system compromises. Police estimates indicate that these infected endpoints facilitated more than 54,000 fraudulent transactions totaling Rs 64.38 crore.

Disguised government portals, particularly fake RTO challan payment platforms, accounted for the highest volume of compromises, exploiting citizens’ compliance habits to gain device access. When law enforcement personnel raided the hotel in Kanpur, they seized two smartphones and a laptop containing source code and client registries, cementing the teenager’s role as a primary technical architect for regional cyber syndicates.

The Expanding Frontier of Generative Cyber Threats

This case highlights a concerning evolution in South Asia’s cybercrime ecosystem, where generative artificial intelligence lowers the technical barrier to entry for novice coders. Historically, sophisticated banking Trojans required extensive software development expertise and financial backing. Today, accessible AI coding assistants allow single individuals to rapidly iterate malware that convincingly replicates legitimate corporate and government interfaces.

Cybersecurity analysts emphasize that traditional phishing methods are increasingly giving way to AI-driven identity and credential harvesting. The widespread distribution of unverified APK files outside official application repositories remains a critical vulnerability across India’s rapidly expanding smartphone user base.

Central and state law enforcement agencies are intensifying public awareness campaigns, advising citizens to avoid installing software attachments received through messaging platforms like WhatsApp or Telegram. As digital forensics teams continue auditing the seized hardware, authorities anticipate further arrests among the regional syndicates that purchased and deployed these AI-crafted tools.

Stay Connected