NEW DELHI: The National Cybercrime Threat Analytics Unit (NCTAU) has warned of a rise in financial frauds involving malicious Android applications disguised as pornography apps and promoted through Facebook and Instagram advertisements.
The apps, which include Night Play, Reloop, Kyss, Vimo, Rivo, Nexo and Vixa, redirect users from social-media advertisements to websites offering pornographic content, where they are prompted to download an Android APK outside the Google Play Store.
In an August 26 advisory, NCTAU, a threat mapping wing of the home ministry under the Indian Cyber Crime Coordination Centre (I4C), said the malicious applications can request permissions that allow them to install additional applications and abuse Android’s Accessibility feature to take control of the device, potentially resulting in financial fraud.
Some variants can also install a VPN that routes internet traffic through attacker-controlled servers.
The attack begins with a malicious advertisement, primarily on Facebook or Instagram, which redirects the user to a phishing website.
According to the advisory, the domains used by these websites majorly belong to the “.live” domain and are designed to persuade users to download and install the APK from outside the Google Play Store.
The initial application can then download a secondary package disguised as an app update, using permissions obtained by the first application. This allows the attackers to deepen their control over the compromised device.
The biggest risk comes from the abuse of accessibility permission. Once enabled by the user, the malicious application can gain control of the device and continue running in the background.
The advisory says such control can be used to facilitate financial fraud and unauthorised transactions.
NCTAU has also warned that some of the applications install a VPN, allowing attackers to route all internet traffic through their own servers.
This could compromise data transmitted from the device and potentially expose it to malicious or criminal use.
The advisory’s graphic illustrates the complete fraud chain — from a user clicking on a malicious social-media advertisement and downloading the APK to granting accessibility access, allowing the malware to take control of the device and ultimately enabling financial fraud.
NCTAU has urged users to install applications only from Google Play Store or other trusted app stores and specifically warned against downloading APK files through advertisements, websites or suspicious links. Users should not grant accessibility permission to unknown applications and should regularly review installed apps for unfamiliar software.
Users should also keep Google Play Protect enabled, ensure their Android devices are updated and regularly check bank accounts and UPI transactions for suspicious activity.
For devices already compromised, NCTAU recommends restarting the phone in Safe Mode and uninstalling the suspicious application. If that fails, users should disable its accessibility access and remove any device administrator privileges. If the application cannot be removed or returns after a restart, the agency recommends backing up important data and performing a factory reset.
The agency has asked users to report fraudulent applications or scam incidents immediately through 1930 or cybercrime.gov.in.









