An 18-year-old Class 11 dropout has emerged as the alleged mastermind behind a nationwide cyber fraud network that used artificial intelligence and Telegram to create fake banking and government mobile applications, helping cybercriminals siphon off over Rs 64 crore from victims across India.

The Surat City Cyber Crime Cell arrested Rohit Virendrasinh Shakya from a hotel in Kanpur, Uttar Pradesh, for allegedly developing malicious APK files that were supplied to cybercriminal gangs operating from Jharkhand's Jamtara, as well as networks in Haryana and Rajasthan.

Despite dropping out after Class 11, police said Shakya became an expert coder by the age of 16. Using AI tools and Telegram, he developed fake applications that closely mimicked genuine banking, government and private-sector apps.

He allegedly operated on a subscription model, supplying customised malware to cybercriminals for Rs 15,000 a month.

According to investigators, Shakya developed two sets of applications — a "victim app", which unsuspecting users installed on their phones, and an "admin app", which allowed fraudsters to remotely access OTPs, banking credentials and other sensitive information in real time.

The fake applications impersonated several trusted institutions and services, including SBI, PNB, Axis Bank, UCO Bank, ICICI Bank, Union Bank, BigBasket, American Express, Aadhaar services, PM Kisan and RTO challan payment portals.

HOW THE FRAUD CAME TO LIGHT

The investigation began after a Surat resident reported losing Rs 5 lakh in a cyber fraud in May this year.

Between May 15 and 18, the victim received a fake "PNB One.apk" file over WhatsApp. Believing it to be the official Punjab National Bank application, he installed it on his mobile phone.

The device was immediately compromised, allowing cybercriminals to access his banking details and transfer Rs 5 lakh from his Prime Co-operative Bank account to a Union Bank account.

The victim alerted the cyber helpline (1930), following which Surat Cyber Crime registered an FIR and launched an investigation.

WHAT POLICE UNEARTHED

The probe revealed what police described as a well-organised cybercrime ecosystem rather than an isolated fraud.

Digital forensic analysis found that Shakya had developed 121 malicious APK applications, which were installed on 21,672 mobile phones across the country.

Investigators found that 2,928 devices were fully compromised, resulting in 54,094 fraudulent banking transactions worth around Rs 64.38 crore.

Police said fake RTO challan applications accounted for the highest number of frauds, followed by fake SBI and PNB applications.

Investigators also found that the malicious APKs were distributed through Telegram to organised cybercrime syndicates, primarily in Jamtara, Haryana and Rajasthan, under a monthly subscription model that included regular updates and maintenance.

Surat Police have seized two mobile phones and a laptop from Shakya and launched a detailed digital forensic examination.

Investigators are now probing whether more cybercrime syndicates across the country were using his software and whether additional accused were involved in the network.

- Ends

Published By:

Aprameya Rao

Published On:

Jul 21, 2026 21:18 IST