New Delhi, Aug 31 : The National Cybercrime Threat Analytics Unit (NCTAU), operating under the Union home ministry's Indian Cyber Crime Coordination Centre (I4C), has warned users about a rise in financial fraud involving malicious Android applications disguised as pornography apps and promoted through advertisements on Facebook and Instagram.
In an advisory issued by the I4C, the agency identified several apps, including “Night Play”, “Reloop”, “Kyss”, “Vimo”, “Rivo”, “Nexo” and “Vixa”, along with similar variants, as part of the threat.
According to the advisory, the malicious applications are primarily promoted through pornography-related advertisements or links on Facebook and Instagram.
Users clicking on these advertisements are redirected to websites hosting pornographic content, where they are prompted to download an Android Package Kit (APK) from outside the Google Play Store.
The websites involved are largely associated with “.live” domains, the advisory said. After the initial application is installed, users may be prompted to download a secondary package disguised as an app update. This process can exploit permissions obtained or abused by the first application.
The malware subsequently seeks Accessibility and other sensitive permissions from the user. Once these permissions are granted, the malicious application can obtain extensive control over the device and continue operating in the background.
The NCTAU also warned that some variants may install a virtual private network (VPN), allowing attackers to route a user's internet traffic through servers under their control. This could expose transmitted data to misuse and facilitate further malicious activity.
The advisory noted that some of these applications may also prevent users from uninstalling them through normal device settings.
The suspected modus operandi begins with a social media advertisement, followed by redirection to a malicious website and APK installation.
This can lead to VPN installation in some cases, requests for Accessibility permissions, device takeover and eventually unauthorised financial transactions.
To protect themselves, users have been advised to download applications only from the Google Play Store or other trusted app stores.
The NCTAU has specifically cautioned against downloading APK files through advertisements, websites or suspicious links and urged users not to grant Accessibility permissions to unfamiliar applications.
The agency has also recommended that users regularly review applications installed on their Android devices and remove those they do not recognise.
Keeping Google Play Protect enabled, installing the latest Android security updates and regularly checking bank accounts and UPI transactions are among the other precautions advised by the agency.
For users who are unable to uninstall a suspicious application normally, the NCTAU has recommended restarting the device in Safe Mode and then navigating to the Apps section in Settings to remove the application.
Users can also disable the app's Accessibility access and revoke administrator privileges through the device's security settings before attempting to uninstall it.
If the application cannot be removed or reappears after a restart, the advisory recommends backing up important data and carrying out a factory reset of the device.
Fake porn apps on Facebook, Instagram used to target android users: Govt