Fake porn apps on Facebook, Instagram target Android users: Govt warning

Share:
Audio Loading voice…
Fake porn apps on Facebook, Instagram target Android users: Govt warning

Synopsis

India's nodal cybercrime unit has named seven specific fake porn apps — promoted via Facebook and Instagram ads — that can seize full control of an Android device, install a rogue VPN, and drain bank accounts. The advisory is a rare instance of the government naming individual malicious apps by name, signalling the scale of the threat.

Key Takeaways

The NCTAU under the Union Home Ministry's I4C issued an advisory on 31 August warning of fake porn apps targeting Android users.
Named apps include 'Night Play' , 'Reloop' , 'Kyss' , 'Vimo' , 'Rivo' , 'Nexo' , and 'Vixa' , distributed via .live domain websites.
The apps are promoted through pornography-related ads on Facebook and Instagram and distributed as APK files outside the Google Play Store.
Once installed, the malware can request Accessibility permissions , install a rogue VPN , and execute unauthorised financial transactions .
Users unable to remove the app are advised to use Safe Mode or perform a factory reset after backing up data.

The National Cybercrime Threat Analytics Unit (NCTAU), operating under the Indian Cyber Crime Coordination Centre (I4C) of the Union Home Ministry, has issued a formal advisory warning Android users about a surge in financial fraud linked to malicious applications disguised as pornography apps and promoted via advertisements on Facebook and Instagram. The alert was issued on 31 August from New Delhi.

Apps Identified in the Advisory

The NCTAU has named several specific applications as part of the threat landscape, including 'Night Play', 'Reloop', 'Kyss', 'Vimo', 'Rivo', 'Nexo', and 'Vixa', along with similar variants. These apps are not available on the official Google Play Store and are instead distributed through third-party websites, predominantly using .live domains.

How the Fraud Operates

According to the advisory, the attack chain begins with a pornography-related advertisement on Facebook or Instagram. Clicking on the ad redirects the user to a website hosting explicit content, where they are prompted to download an Android Package Kit (APK) file — a sideloaded application bypassing official app store security checks.

Once installed, the initial application may prompt users to download a secondary package disguised as an update, exploiting permissions already granted by the first install. The malware then requests Accessibility permissions and other sensitive device access. Once these are approved, attackers gain extensive control over the device, enabling it to operate covertly in the background.

Notably, some variants also install a virtual private network (VPN), routing the victim's internet traffic through attacker-controlled servers — potentially exposing all transmitted data to interception and misuse. Certain variants are also designed to resist uninstallation through standard device settings, making removal significantly harder for affected users.

The end result of a successful attack can include device takeover and unauthorised financial transactions, including through UPI and linked bank accounts.

Government's Safety Recommendations

The NCTAU has urged users to download applications exclusively from the Google Play Store or other verified app stores, and to avoid clicking on APK download links from advertisements, websites, or unknown sources. Users are also advised never to grant Accessibility permissions to unfamiliar applications.

Additional precautions recommended include keeping Google Play Protect enabled, installing the latest Android security updates, and regularly monitoring bank accounts and UPI transaction histories. Users should also periodically audit installed apps and remove any they do not recognise.

What to Do If Already Infected

For users unable to uninstall a suspicious app through normal settings, the advisory recommends restarting the device in Safe Mode and navigating to the Apps section in Settings to attempt removal. Users can also disable the app's Accessibility access and revoke administrator privileges via the device's security settings before uninstalling.

If the application persists or reappears after a restart, the NCTAU advises backing up critical data and performing a factory reset of the device. Users can report cybercrime incidents at the national helpline or through the official cybercrime portal.

Point of View

Organised campaign rather than a generic threat. What the advisory does not address is how these ads passed Facebook and Instagram's own moderation systems, a question the government has so far left to the platforms. With UPI now embedded in daily financial life for hundreds of millions of Indians, a malware strain that targets Accessibility permissions is effectively targeting the payments layer of the economy. The absence of any mention of enforcement action against the ad networks hosting these promotions is a gap that deserves scrutiny.
NationPress
31 Aug 2026

Frequently Asked Questions

What are the fake porn apps the government has warned about?
The NCTAU has identified seven apps — 'Night Play', 'Reloop', 'Kyss', 'Vimo', 'Rivo', 'Nexo', and 'Vixa' — along with similar variants, as malicious Android applications. These apps are disguised as pornography platforms and are used to gain unauthorised access to users' devices and finances.
How do these fake apps reach Android users?
The apps are promoted through pornography-related advertisements on Facebook and Instagram. Clicking on these ads redirects users to websites — mostly on .live domains — where they are prompted to download an APK file outside the Google Play Store, bypassing standard security checks.
What can these malicious apps do once installed?
Once installed, the apps request Accessibility and other sensitive permissions. If granted, they can take over the device, operate in the background, install a rogue VPN to intercept internet traffic, and ultimately carry out unauthorised financial transactions including through UPI-linked bank accounts.
How can users protect themselves from these fake apps?
Users should only download apps from the Google Play Store, never click on APK links in ads or on unknown websites, and avoid granting Accessibility permissions to unfamiliar applications. Keeping Google Play Protect enabled and monitoring bank and UPI transactions regularly are also advised.
What should users do if they have already installed one of these apps?
Users should restart their device in Safe Mode and attempt to uninstall the app via Settings. If that fails, they should revoke the app's Accessibility access and administrator privileges. If the app still cannot be removed, the NCTAU recommends backing up data and performing a factory reset.
Nation Press
The Trail

Connected Dots

Tracing the thread behind this story — newest first.

8 Dots
  1. Latest 1 week ago
  2. 1 month ago
  3. 1 month ago
  4. 2 months ago
  5. 2 months ago
  6. 3 months ago
  7. 3 months ago
  8. 4 months ago
Google Prefer NP
On Google