Fake porn apps on Facebook, Instagram target Android users: Govt warning
Synopsis
Key Takeaways
The National Cybercrime Threat Analytics Unit (NCTAU), operating under the Indian Cyber Crime Coordination Centre (I4C) of the Union Home Ministry, has issued a formal advisory warning Android users about a surge in financial fraud linked to malicious applications disguised as pornography apps and promoted via advertisements on Facebook and Instagram. The alert was issued on 31 August from New Delhi.
Apps Identified in the Advisory
The NCTAU has named several specific applications as part of the threat landscape, including 'Night Play', 'Reloop', 'Kyss', 'Vimo', 'Rivo', 'Nexo', and 'Vixa', along with similar variants. These apps are not available on the official Google Play Store and are instead distributed through third-party websites, predominantly using .live domains.
How the Fraud Operates
According to the advisory, the attack chain begins with a pornography-related advertisement on Facebook or Instagram. Clicking on the ad redirects the user to a website hosting explicit content, where they are prompted to download an Android Package Kit (APK) file — a sideloaded application bypassing official app store security checks.
Once installed, the initial application may prompt users to download a secondary package disguised as an update, exploiting permissions already granted by the first install. The malware then requests Accessibility permissions and other sensitive device access. Once these are approved, attackers gain extensive control over the device, enabling it to operate covertly in the background.
Notably, some variants also install a virtual private network (VPN), routing the victim's internet traffic through attacker-controlled servers — potentially exposing all transmitted data to interception and misuse. Certain variants are also designed to resist uninstallation through standard device settings, making removal significantly harder for affected users.
The end result of a successful attack can include device takeover and unauthorised financial transactions, including through UPI and linked bank accounts.
Government's Safety Recommendations
The NCTAU has urged users to download applications exclusively from the Google Play Store or other verified app stores, and to avoid clicking on APK download links from advertisements, websites, or unknown sources. Users are also advised never to grant Accessibility permissions to unfamiliar applications.
Additional precautions recommended include keeping Google Play Protect enabled, installing the latest Android security updates, and regularly monitoring bank accounts and UPI transaction histories. Users should also periodically audit installed apps and remove any they do not recognise.
What to Do If Already Infected
For users unable to uninstall a suspicious app through normal settings, the advisory recommends restarting the device in Safe Mode and navigating to the Apps section in Settings to attempt removal. Users can also disable the app's Accessibility access and revoke administrator privileges via the device's security settings before uninstalling.
If the application persists or reappears after a restart, the NCTAU advises backing up critical data and performing a factory reset of the device. Users can report cybercrime incidents at the national helpline or through the official cybercrime portal.