Skip to Content
Add Network with Us — Join Membership


18-Year-Old Arrested for Allegedly Creating 121 Fake Apps Used in ₹64.38 Crore Scam

Surat Cyber Crime Cell has arrested an 18-year-old accused of developing customised malicious applications that allegedly compromised thousands of mobile phones and enabled more than 54,000 fraudulent banking transactions across India.
July 22, 2026 by
18-Year-Old Arrested for Allegedly Creating 121 Fake Apps Used in ₹64.38 Crore Scam
Administrator

The Surat Cyber Crime Cell in Gujarat has uncovered an alleged large-scale mobile malware network following the arrest of 18-year-old Rohit Virendrasinh Shakya.

Police allege that the accused developed 121 malicious Android applications that closely resembled genuine applications operated by banks, government departments and private companies.

According to investigators, the fake applications were installed on 21,672 mobile phones, while 2,928 devices were fully compromised. The malware was allegedly linked to 54,094 fraudulent banking transactions involving approximately ₹64.38 crore.

The accused was arrested from a hotel in Kanpur, Uttar Pradesh. Two mobile phones and a laptop were reportedly seized and are undergoing detailed digital forensic examination.

The allegations remain under investigation, and the accused’s criminal liability has not been determined by a court.

Accused Allegedly Taught Himself Coding

According to police, Shakya had discontinued formal education after Class 11 but developed an interest in coding at a young age.

Investigators allege that he learnt application development using:

  • Online coding resources
  • Artificial intelligence tools
  • Telegram channels
  • Technical tutorials
  • Existing application templates

He allegedly used these resources to create mobile applications containing malware capable of stealing sensitive data from users’ devices.

The case demonstrates how easily available digital tools can potentially be misused by individuals with limited formal technical education.

However, the precise role played by AI tools will need to be established through forensic examination of the seized devices and development records.

Customised Malware Allegedly Supplied to Cybercrime Groups

Police allege that the accused was not directly involved in every fraudulent banking transaction.

Instead, he allegedly developed customised malware and supplied it to organised cybercrime syndicates operating in:

  • Jamtara in Jharkhand
  • Haryana
  • Rajasthan
  • Other parts of India

Investigators claim that the malware was provided under a subscription-based arrangement for approximately ₹15,000 per month.

The alleged service reportedly included software updates, maintenance and technical support.

This business model is commonly described as malware-as-a-service, where one group develops the harmful technology while other groups distribute it and carry out financial fraud.

Two Types of Applications Allegedly Developed

According to investigators, the accused allegedly created two connected types of mobile applications.

The first was referred to as the “victim app.”

This application was allegedly disguised as a genuine banking, government or commercial application and distributed to unsuspecting users.

The second was described as the “admin app.”

Police allege that the admin application enabled cybercriminals to remotely access information collected from compromised mobile phones.

The two-app structure allegedly allowed fraud operators to view victims’ sensitive data in real time and use it to conduct unauthorised financial transactions.

Victim App Imitated Trusted Services

The alleged victim applications were designed to closely resemble applications operated by well-known institutions.

According to police, the fake applications impersonated services associated with:

  • State Bank of India
  • Punjab National Bank
  • Axis Bank
  • UCO Bank
  • ICICI Bank
  • Union Bank of India
  • American Express
  • Aadhaar services
  • PM-Kisan
  • RTO challan portals
  • BigBasket
  • Other consumer brands

The objective was allegedly to persuade users that they were installing an authentic and trusted application.

The use of familiar names, icons and interface designs can make fraudulent applications difficult for ordinary users to identify.

Admin App Allegedly Provided Real-Time Access

Investigators claim that once the victim application was installed, the corresponding admin application allowed cybercriminals to access sensitive data remotely.

This allegedly included:

  • One-time passwords
  • Banking credentials
  • SMS messages
  • Mobile notifications
  • Personal information
  • Device-related data

Access to OTPs and banking alerts can allow criminals to complete transactions even when a bank uses two-factor authentication.

The malware may also enable fraudsters to monitor the victim’s device while keeping the malicious activity hidden in the background.

Investigation Began With ₹5 Lakh Fraud

The wider operation was reportedly uncovered after a Surat resident complained of losing ₹5 lakh in May 2026.

According to the complaint, the victim received a file named “PNB One.apk” through WhatsApp.

Believing that it was the official Punjab National Bank application, the individual reportedly downloaded and installed it.

Police allege that the malware immediately compromised the smartphone and allowed cybercriminals to obtain access to the victim’s banking information.

Approximately ₹5 lakh was subsequently transferred from the victim’s Prime Co-operative Bank account to another bank account.

Prompt Complaint Led to FIR

The victim reportedly contacted the National Cyber Crime Helpline at 1930 soon after discovering the unauthorised transaction.

An FIR was registered, and Surat Cyber Crime Cell began examining the digital trail connected with the APK file.

Investigators analysed:

  • The malicious application
  • Server connections
  • Hosting infrastructure
  • Domain records
  • Bank transactions
  • Mobile numbers
  • Device logs
  • Digital communications

The forensic trail eventually led police to the alleged developer.

121 Malicious Applications Identified

Digital forensic analysis allegedly revealed that the accused had developed 121 separate malicious APK files.

These applications were reportedly customised to impersonate different institutions and address different categories of potential victims.

Creating multiple versions may allow cybercriminals to target people through messages relating to:

  • Bank account verification
  • Government benefits
  • Pending traffic challans
  • Customer support
  • Delivery services
  • Agricultural subsidies
  • Account updates

Each application may use a different pretext while relying on the same underlying malware technology.

More Than 21,000 Phones Allegedly Installed Apps

Police claim that the fake applications were installed on 21,672 mobile phones across India.

Investigators further identified 2,928 devices that were allegedly fully compromised.

A full compromise may mean that the malware obtained the permissions necessary to access messages, OTPs, notifications or other sensitive information.

Authorities will need to determine how many users suffered actual financial losses and how many devices were exposed without resulting in completed transactions.

The number of affected victims may increase as forensic analysis continues.

More Than 54,000 Fraudulent Transactions Detected

According to investigators, the compromised devices were connected with 54,094 allegedly fraudulent banking transactions.

The combined value of these transactions is estimated at approximately ₹64.38 crore.

The figure is based on the ongoing police investigation and may change as authorities reconcile:

  • Victim complaints
  • Bank transaction records
  • Beneficiary accounts
  • Reversed or blocked transactions
  • Duplicate reports
  • Transfers linked to other fraud networks

Investigators are likely to examine whether the entire alleged amount was successfully withdrawn or whether any funds were frozen or recovered.

Fake RTO Challan Apps Accounted for Most Cases

Police reportedly found that fraudulent RTO challan payment applications accounted for the largest number of cases.

Fake applications resembling SBI and PNB services were also allegedly used extensively.

RTO challan scams can be particularly effective because victims may receive urgent messages claiming that:

  • A traffic fine is unpaid
  • A vehicle registration will be suspended
  • Immediate payment is required
  • Legal action may follow
  • A discounted settlement is available

The victim may then be directed to download an APK file rather than visiting an official government portal.

Malware Allegedly Distributed Through Telegram

Investigators allege that the malicious applications were supplied to cybercrime groups through Telegram.

Telegram and similar communication platforms can be used legitimately, but their private channels and file-sharing features may also be misused to distribute:

  • Malware files
  • Stolen information
  • Fraud scripts
  • Mule-account details
  • Technical instructions
  • Software updates

Police are examining the channels, usernames and communications allegedly used to distribute the applications.

The investigation may identify additional developers, purchasers and administrators connected with the network.

Subscription Model Included Technical Support

According to police, the alleged malware service extended beyond the one-time sale of an application.

Cybercrime groups reportedly received:

  • Customised applications
  • Periodic updates
  • Maintenance support
  • Technical assistance
  • New versions targeting additional institutions

Such an arrangement could allow even individuals without advanced technical skills to conduct sophisticated cyber fraud.

By separating development, distribution and financial operations, organised networks can expand their attacks across multiple states.

Seized Devices Under Forensic Examination

Police seized two mobile phones and a laptop from the accused at the time of his arrest.

Digital forensic experts are expected to examine the devices for:

  • Source code
  • Application-building tools
  • Customer lists
  • Telegram communications
  • Payment records
  • Server credentials
  • Malware control panels
  • Data collected from victims
  • Links with cybercrime syndicates

Deleted files and communications may also be recovered where technically possible.

The findings could help authorities identify the full scale of the alleged network.

AI Tools Can Lower Technical Barriers

The case highlights concerns about the misuse of artificial intelligence-assisted development tools.

AI tools can help legitimate users learn programming, identify software errors and develop useful applications.

However, the same tools may be misused to:

  • Generate malicious code
  • Modify existing malware
  • Create convincing fake interfaces
  • Automate technical tasks
  • Translate fraud messages
  • Avoid basic detection systems

The involvement of AI does not remove human responsibility. Investigators must establish how the tools were used and whether the accused knowingly developed applications intended for fraudulent activity.

Never Install APK Files Received Through Messages

Cybercrime experts advise users to avoid installing APK files received through:

  • WhatsApp
  • Telegram
  • SMS
  • Email attachments
  • Social media messages
  • Unknown websites

Banking and government applications should be downloaded only from authorised app stores or verified official websites.

A bank, government department or police agency will generally not require a user to install an application received as a direct message attachment.

Review Application Permissions Carefully

Users should carefully review permissions requested by any mobile application.

Particular caution is required when an unfamiliar application asks for access to:

  • SMS messages
  • Notifications
  • Accessibility services
  • Contacts
  • Call records
  • Device administration
  • Screen-sharing features

An RTO challan, courier or customer-support application should not normally require unrestricted access to OTPs or banking notifications.

Excessive permissions are a major indication that an application may be unsafe.

Immediate Action After Suspicious Installation

Anyone who has installed a suspicious APK should immediately:

  • Disconnect the device from the internet
  • Contact their bank
  • Temporarily block digital banking access
  • Change passwords from another secure device
  • Revoke the application’s permissions
  • Preserve screenshots and messages
  • Report the incident through 1930
  • Submit a complaint on the official cybercrime portal

Quick reporting improves the possibility of identifying beneficiary accounts and freezing transferred funds before they are withdrawn or moved further.

Wider Cybercrime Network Under Investigation

Surat Cyber Crime Cell is examining whether additional cybercrime groups across India purchased or used the alleged malware.

Authorities are also attempting to identify:

  • APK distributors
  • Telegram channel administrators
  • Fraud callers
  • Mule-account operators
  • Cash withdrawal agents
  • Server and hosting providers
  • Other malware developers

Further arrests may follow if forensic evidence establishes the involvement of additional individuals.

All allegations remain subject to investigation, due process and judicial determination.

Shunyatax Global Insight

The Surat investigation demonstrates how cybercrime has evolved into a specialised commercial ecosystem. A malware developer, distributor, fraud caller, mule-account provider and fund-withdrawal operator may all perform separate roles while participating in the same criminal network.

Banks, government departments and consumer companies should continuously monitor fake applications using their names and establish rapid reporting and takedown systems. Users should disable installation from unknown sources and remember that an APK file received through a message can provide criminals access not only to a bank account, but also to OTPs, personal data and the victim’s broader digital identity.

in News
Share this post
Archive