Skip to Content
Add Network with Us — Join Membership


Teen Learns Malware Development Through YouTube and AI Tools, Allegedly Creates 121 Fake APKs Used in ₹65 Crore Cyber Fraud

Surat Cyber Crime Police have arrested an 18-year-old accused of developing 121 malicious Android applications that impersonated banks, government services and consumer brands. Police claim the files were downloaded by 21,672 users and allegedly caused losses of approximately ₹65 crore to 2,928 victims.
July 21, 2026 by
Teen Learns Malware Development Through YouTube and AI Tools, Allegedly Creates 121 Fake APKs Used in ₹65 Crore Cyber Fraud
Administrator

The Surat Cyber Crime Police have uncovered an alleged large-scale Android malware operation involving fake mobile applications designed to steal banking credentials, one-time passwords and other sensitive information.

Police arrested Rohit Sakya, an 18-year-old resident of Kasganj in Uttar Pradesh, for allegedly developing 121 malicious Android Application Package files, commonly known as APKs.

According to investigators, these applications were supplied to cybercriminal groups associated with the Jamtara fraud network and used in banking and digital payment scams across India.

Police claim that the applications were downloaded by 21,672 users, of whom 2,928 allegedly suffered combined losses of approximately ₹65 crore. These figures are based on the ongoing police investigation and have not yet been tested before a court.

Accused Allegedly Learnt Malware Development Online

Investigators stated that Sakya had studied up to Class 11 and allegedly learnt how to create malware-infected APK files using:

  • YouTube tutorials
  • Online technical resources
  • Artificial intelligence-based tools
  • Readily available software-development platforms

Police allege that he subsequently converted this knowledge into a commercial malware-development service for organised cyber fraud groups.

The case highlights how online learning tools that have legitimate educational uses may also be misused to develop harmful software.

However, the use of AI tools alone does not establish that an AI platform created the malware autonomously. Investigators will need to determine which tools were used, how they were used and the extent of human involvement.

Malware Allegedly Sold Through Subscription Model

According to police, the accused did not necessarily operate the fraudulent bank transfers himself.

His alleged role was to develop fake applications and supply them to different cybercrime groups.

Investigators claim that he charged approximately ₹15,000 per APK and offered the malicious files through a monthly subscription-style arrangement.

Such a model is commonly described in cybersecurity as malware-as-a-service, where technical developers create malicious tools that are then rented or sold to other criminals who target victims.

This structure allows cybercrime networks to divide their operations among:

  • Malware developers
  • Message distributors
  • Call-centre operators
  • Mule-account providers
  • Cash withdrawal agents
  • Overseas handlers

Case Began With Fake PNB One Application

The investigation reportedly began after a Surat resident received and installed a fake version of the PNB One mobile banking application.

According to the complaint, the victim subsequently lost approximately ₹5 lakh from his bank account.

The complainant reportedly believed the application was connected with the genuine banking service because its appearance closely resembled the official app.

After receiving the complaint, Surat Cyber Crime Police began analysing the APK, its permissions, server connections and underlying digital infrastructure.

Digital Forensics Led Police to Developer

Investigators reportedly examined several forms of electronic evidence, including:

  • Application source files
  • Server logs
  • Internet Protocol addresses
  • Domain registration records
  • Hosting infrastructure
  • Payment transactions
  • Mobile-device identifiers
  • Communication records

The forensic analysis allegedly allowed investigators to trace the development and distribution of the malicious application to the accused.

Police later arrested Sakya from a hotel in Kanpur, where he had reportedly travelled for a personal meeting.

The circumstances of the arrest do not affect the legal merits of the allegations, which remain subject to evidence and judicial determination.

Fake Apps Impersonated Banks and Government Services

According to police, the 121 malicious APKs copied the appearance and branding of several well-known banks, government programmes and consumer-facing businesses.

The alleged fake applications included versions resembling:

  • PNB One
  • State Bank of India
  • Axis Bank
  • UCO Bank
  • American Express
  • PM-Kisan
  • Pension services
  • RTO challan services
  • BigBasket
  • DMart
  • Campa
  • Customer support applications

The applications were allegedly designed to appear genuine so that users would install them without recognising the security risk.

How Malicious APK Files Can Steal Information

An APK is the installation-file format used for Android applications.

APK files are not automatically malicious. Legitimate Android applications also use this format.

The danger arises when users install modified or fraudulent APKs received from unofficial sources such as WhatsApp, Telegram, SMS or unknown websites.

Once installed, a malicious application may request access to:

  • SMS messages
  • Contacts
  • Notifications
  • Accessibility services
  • Call records
  • Device storage
  • Screen-sharing functions
  • Banking applications

Cybercriminals may then intercept OTPs, monitor messages, capture login information or remotely control certain functions of the device.

In previous Jamtara-linked APK cases, Gujarat Police have described malicious files being circulated through WhatsApp and used to intercept messages and transfer money into mule accounts.

Permissions Can Give Fraudsters Extensive Control

Many victims install fake applications because they believe the file has been sent by a bank, government department, courier company or customer support representative.

During installation, the application may ask the user to approve several permissions.

Victims frequently approve these requests without reviewing them carefully.

Once accessibility or notification access is granted, the malware may be able to:

  • Read incoming OTPs
  • Observe banking alerts
  • Capture screen content
  • Redirect users to false login pages
  • Hide notifications
  • Collect personal data
  • Facilitate unauthorised transactions

The application may continue operating in the background even after the user closes it.

Alleged Connection With Jamtara Network

Police claim that the accused supplied the APKs to cybercriminals linked with the Jamtara fraud network.

Jamtara has become widely associated with organised phishing, impersonation and banking fraud operations, although not every person or cybercrime case from the region is connected.

Investigators are examining whether the accused dealt with one central group or supplied malware to multiple independent networks.

The role of other developers, distributors, handlers and account operators remains under investigation.

Thousands of Downloads Under Examination

According to police data cited in current reporting, the malicious applications were downloaded by 21,672 users, while 2,928 people allegedly lost money.

Investigators will need to determine:

  • How many downloads resulted in actual installation
  • Which devices granted sensitive permissions
  • How many users suffered attempted fraud
  • Whether all reported losses were caused by the same malware
  • Whether additional victims have not yet filed complaints

The total alleged loss of ₹65 crore may change as investigators reconcile banking records and complaints from different states.

Financial Trail and Hosting Network Being Traced

Police are conducting forensic examinations of seized devices, payment records and online infrastructure allegedly used in the operation.

The investigation is expected to focus on:

  • Payments made to the malware developer
  • Cryptocurrency or digital-wallet transactions
  • Bank accounts used to collect subscription fees
  • Servers hosting stolen data
  • Domains used to distribute fake applications
  • Communication between developers and fraud groups
  • Mule accounts receiving stolen funds

Authorities may also seek assistance from banks, telecom providers, hosting companies and overseas platforms.

AI Tools Create New Enforcement Challenge

The case has renewed concerns about the misuse of generative AI and automated coding tools.

AI-assisted development can help legitimate programmers identify errors, create prototypes and learn new technical skills.

The same capabilities may also allow individuals with limited formal training to create or modify malicious code more quickly.

The central regulatory challenge is not the existence of AI tools but how criminals use them to:

  • Automate phishing content
  • Modify malware code
  • Create convincing fake interfaces
  • Generate fraudulent documents
  • Scale attacks across languages
  • Avoid conventional detection systems

Developers and technology platforms may increasingly face pressure to strengthen misuse detection and restrict assistance that clearly facilitates malware creation.

Users Should Avoid APKs Shared Through Messages

Cybercrime experts advise users to install banking, government and financial applications only from official app stores or verified institutional websites.

Users should never install APK files received through:

  • WhatsApp
  • Telegram
  • SMS
  • Social media messages
  • Unverified email attachments
  • Unknown download links

Even when the sender claims to represent a bank, police department, courier service or government office, the user should independently contact the institution through its official website or customer-care number.

Warning Signs of a Fake Application

A mobile application should be treated with caution when:

  • It is unavailable on an official app store
  • The sender creates urgency or threatens penalties
  • It asks for extensive accessibility permissions
  • The file name contains spelling errors
  • The app requests banking or card information
  • It asks users to share OTPs or PINs
  • It disables security settings
  • It is sent through a personal mobile number

Users should also verify the official developer name, number of downloads, reviews and privacy details before installing an application.

Immediate Steps After Installing a Suspicious APK

A person who has installed a suspicious application should immediately:

  • Disconnect the device from mobile data and Wi-Fi
  • Contact the concerned bank
  • Block or temporarily freeze relevant accounts
  • Change banking and email passwords using another secure device
  • Revoke suspicious application permissions
  • Uninstall the application
  • Report the incident through the official cybercrime reporting system
  • Preserve screenshots, messages and payment records

Where the device appears remotely controlled, professional examination or a secure factory reset may be necessary after preserving evidence.

Investigation May Lead to Further Arrests

Surat Cyber Crime Police are continuing to examine the distribution network, server infrastructure and financial transactions connected with the alleged APK ecosystem.

Investigators are also attempting to identify:

  • Persons who purchased the malware
  • Jamtara-based operators
  • Overseas handlers
  • Mule-account providers
  • Message distributors
  • Other technical developers

Further arrests and legal action may follow if additional evidence is discovered.

The accused is entitled to due process, and the allegations will require proof before the competent court.

Shunyatax Global Insight

This case illustrates the industrialisation of cybercrime. The person creating malware, the group contacting victims and the account holder receiving stolen money may all be different participants connected through subscription fees and commissions. Investigations must therefore trace the entire ecosystem rather than focusing only on the person who initiated the fraudulent transaction.

Banks, businesses and government departments should actively monitor fake applications impersonating their brands and establish rapid takedown procedures. Smartphone users should disable installation from unknown sources and avoid treating an APK received through a message as an ordinary document. In mobile banking fraud, a single installation permission can expose OTPs, personal information and financial accounts.

in News
Share this post
Archive