A four-member team from Chandigarh University has secured second place in the national CyberShield Hackathon for developing an agentic AI platform that automates parts of Android malware analysis, reverse engineering and risk scoring. The students won ₹3 lakh after competing against more than 3,000 registered teams in a competition organized by Bank of India with IIT Hyderabad.
Generative AI is increasingly being tested as a tool for cybersecurity teams facing a growing volume of malicious applications, malware samples and fraud attempts. A student team from Chandigarh University has now applied the technology to one of the more technically demanding areas of security operations: automated analysis of suspicious Android applications.
Team Fi, consisting of third-year Bachelor of Engineering students Danish Verma, Rahul Jaluthria, Varun Gupta and Avneet Kaur, finished second nationally in the CyberShield Hackathon organized by Bank of India in collaboration with IIT Hyderabad.
The team received a ₹3 lakh prize for developing an AI-powered cybersecurity platform focused on automated reverse engineering, static and dynamic analysis, and risk scoring of fraudulent Android application packages (APKs) and malware.
The project is notable because it goes beyond using a large language model as a simple analyst assistant. The students designed what they describe as an agentic AI infrastructure, in which autonomous agents coordinate different stages of the investigation workflow.
That distinction reflects a larger change in cybersecurity AI.
Traditional malware analysis can require security researchers to inspect application code, examine permissions and dependencies, execute suspicious files in controlled environments, analyze runtime behavior and correlate evidence before determining whether an application represents a threat. Much of that process remains specialized and labor-intensive.
An agentic architecture can potentially connect these stages into a single workflow.
According to Team Fi member Danish Verma, the team’s objective was to rethink the conventional automated-analysis pipeline by exploring how autonomous AI agents could coordinate different cybersecurity tasks. The resulting platform is designed to automate aspects of application security assessment, identify suspicious behavior, evaluate risk and produce information that security professionals can use during investigations.
The project was developed around the first problem statement at CyberShield, which specifically challenged participants to apply Generative AI to fraudulent mobile applications and malware.
The competition attracted more than 3,000 team registrations from universities and higher-education institutions across India. Seventy-two shortlisted teams, representing 232 participants, eventually presented solutions and prototypes at IIT Hyderabad. Nine teams advanced to the final round for the first problem statement.
Team Fi represented the Centre for Privacy and Security in Emerging Technologies (CPSET) at Chandigarh University’s Apex Institute of Technology’s Computer Science Engineering department.
The final evaluation brought together judges and experts from organizations including EY, C-DAC, McKinsey, Bank of India and IIT Hyderabad.
The project’s focus is particularly relevant to India’s expanding digital-payment and mobile-app ecosystem. Android applications have become a major attack surface for financial fraud, credential theft and social-engineering campaigns. Malicious or modified APKs can be used to harvest sensitive information, intercept authentication codes, abuse accessibility permissions or deliver additional malware.
Automating the first stages of investigation could therefore help security teams handle larger volumes of suspicious applications.
The challenge, however, is that AI-assisted malware analysis has to balance automation with evidence quality. A system that incorrectly labels a legitimate application as malicious can create operational and reputational problems, while failing to identify a sophisticated threat can have more serious consequences.
Team Fi says its platform therefore emphasizes an evidence-driven approach rather than relying solely on AI-generated conclusions.
That model is increasingly important as cybersecurity organizations experiment with AI agents. Security vendors are deploying AI for alert triage, threat detection, security operations center workflows, vulnerability analysis and incident response. The emerging goal is not simply to generate summaries, but to allow AI systems to execute sequences of investigative tasks while keeping humans involved in consequential decisions.
For mobile-security teams, the same architecture could eventually connect APK ingestion, code analysis, sandbox execution, behavioral observation, threat intelligence and risk scoring.
It also illustrates an important trend in enterprise AI development: domain-specific agentic systems can be more useful than general-purpose chatbots when the underlying workflow contains clearly defined steps, specialized tools and large volumes of structured and unstructured evidence.
The Chandigarh University project is still a competition prototype rather than a production cybersecurity platform, so its real-world performance, false-positive rate and scalability would need to be independently evaluated before enterprise deployment.
But the hackathon result demonstrates how quickly AI-agent concepts are moving into technical education and applied cybersecurity research.
Chandigarh University says it established the CPSET Lab to strengthen research and practical learning in cybersecurity, privacy and emerging technologies. The university is also promoting industry-oriented cybersecurity education through its collaboration with IBM.
The institution cited National Cyber Crime Reporting Portal data showing approximately 28 lakh cyber-fraud complaints in 2025 involving ₹22,931 crore. Those figures underscore the scale of the problem, although complaint volumes should not be interpreted as equivalent to independently verified incidents or financial losses in every case.
For banks and financial institutions, the relevance of projects like Team Fi’s extends beyond hackathons. Fraud prevention increasingly requires systems that can inspect digital artifacts quickly, correlate signals across multiple sources and prioritize threats for human investigators.
That is precisely where agentic AI could become more significant.
Rather than replacing malware researchers, the more practical near-term role is likely to be acting as a cybersecurity force multiplier: performing repetitive analysis, gathering evidence, identifying suspicious patterns and preparing findings so specialists can spend more time on complex investigations.
The CyberShield result offers a small but useful demonstration of that direction. The next stage will be determining whether these academic prototypes can evolve into secure, explainable and measurable systems capable of operating against adversarial threats in production environments.
As attackers increasingly automate their own operations, the ability to automate defensive analysis may become less of an advantage and more of a requirement.
Market Landscape
AI-assisted cybersecurity is shifting from conventional machine-learning detection toward agentic security operations, where AI systems can perform multi-step investigation and response tasks.
For mobile security, Generative AI can potentially accelerate reverse engineering, code interpretation, malware classification, behavioral analysis and analyst reporting. However, production deployment requires strong sandboxing, access controls, model governance, explainability and human approval mechanisms.
The competitive landscape includes cybersecurity platforms from Microsoft, Google, Palo Alto Networks, CrowdStrike and others that are incorporating AI into security operations. Specialized malware-analysis and mobile-security vendors are also increasingly using automation to reduce analyst workload.
The differentiator for emerging systems will be their ability to combine autonomous reasoning with reliable evidence, rather than simply generating plausible security explanations.
Top Insights
- Agentic AI enters malware analysis: Team Fi used autonomous AI agents to coordinate reverse engineering, application analysis and risk-scoring tasks for suspicious Android applications.
- Cybersecurity is becoming an agentic workflow: AI is moving beyond detection and summarization toward multi-step investigation involving specialized tools, evidence and analyst oversight.
- Mobile applications remain a major attack surface: Automated APK analysis could help security teams process growing volumes of suspicious applications more efficiently.
- Evidence matters as much as automation: AI-generated cybersecurity conclusions require traceable evidence and human validation because false positives and missed threats carry significant operational costs.
- Student projects mirror enterprise AI trends: The hackathon demonstrates how agentic AI architectures are moving rapidly from research environments into applied cybersecurity education.
Power Tomorrow’s Intelligence — Build It with TechEdgeAI












