The Gujarat Cyber Crime Cell detained an 18-year-old developer from Uttar Pradesh for allegedly creating and supplying fake banking applications and malware-laden APK files to cybercriminals across the country. Identified as Rohit Virender Singh Shakya, the accused was arrested on Monday.

Investigation revealed the accused, only a Class 11 pass, used artificial intelligence and Telegram to develop sophisticated tools that were allegedly used in large-scale cyber fraud operations.

Detailed investigation revealed that the accused began creating malicious APK files at the age of 16 with the help of AI tools and Telegram. These applications could easily compromise mobile phones and steal sensitive information. It was found that several cybercrime gangs operating from Jamtara in Jharkhand as well as those groups in Haryana and Rajasthan were allegedly sourcing the virus-infected application from him.

The network surfaced following the investigation of a cyber fraud case registered in Surat in May 2026. The victim, as per reports, received an APK file on WhatsApp that closely resembled the official Punjab National Bank’s PNB One application. Believing it to be genuine, the victim downloaded and installed the app. Following the installation, the victim’s phone was compromised and a transaction of rupees five lakh was initiated from his account in Prime Cooperative Bank to an account in Union Bank.

Following the complaint, an investigation was launched which unearthed the syndicate, eventually leading to the mastermind behind the operation. A team of cybercrime officers and IT experts conducted a raid at a hotel in Karpur and arrested the accused. Belongings of the accused like the laptop, mobile phone, and other digital devices were also seized.

As the probe deepened, the investigators discovered that the accused developed two types of applications. The first one which was to be installed on the victim’s device and the second which functioned as an admin application. Through the admin application, cybercriminals could reportedly view OTPs, banking details, and other sensitive information from the victim’s banking in real time.

The investigation also revealed the business model behind the operation, in which the accused charged Rs 15,000 for the initial payment, initial deployment of the software, and an additional Rs15,000 per month for continued services. The bank applications that the accused mimicee were of PNB, SBI, Axis Bank, UCO Bank, BigBasket, American Express and RTO challan services.Efforts to nab the other involved in the syndicate is underway.