Cybercrime Unit Warns of Malicious Porn Apps Targeting Android Users

India's cybercrime agencies have raised alarms over a surge in financial fraud linked to malicious Android applications disguised as pornography apps and promoted through advertisements on Facebook and Instagram. The National Cybercrime Threat Analytics Unit (NCTAU), a threat-mapping wing of the home ministry under the Indian Cyber Crime Coordination Centre (I4C), issued an advisory on August 26 detailing the modus operandi of these apps, which include names like Night Play, Reloop, Kyss, Vimo, Rivo, Nexo, and Vixa.

According to the advisory, the attack begins with a malicious advertisement on social media platforms that redirects users to websites offering pornographic content. These sites, which often use live" domains, prompt users to download an Android Package Kit (APK) from outside the Google Play Store. Once installed, the apps request sensitive permissions, including Accessibility access, which can be abused to take control of the device. The Cybercrime Unit has warned that attackers can read on-screen information, click buttons, and enter sensitive details such as OTPs and PINs, potentially confirming transactions and initiating fund transfers.

"After installation, the app requests permissions that allow it to install additional applications and by abusing accessibility permissions, take control of the users' device, which results in financial fraud," a senior official explained, as reported by ThePrint. The initial app can also download a secondary package disguised as an app update, deepening the attackers' control. In some variants, the malware installs a VPN that routes all internet traffic through attacker-controlled servers, potentially exposing transmitted data to misuse. The apps may also prevent uninstallation through the phone's regular settings, making them difficult to remove.

Safety Recommendations for Users

The advisory urges users to download applications only from the Google Play Store or other trusted app stores and to avoid downloading APK files from advertisements, websites, or suspicious links. Users are advised not to grant Accessibility permissions to unfamiliar applications and to regularly check installed apps, keep Google Play Protect enabled, and update the Android operating system. Monitoring bank accounts and UPI transactions for suspicious activity is also recommended.

For devices suspected to be compromised, the advisory recommends restarting the phone in Safe Mode and uninstalling suspicious applications. If the app persists, users may need to disable Accessibility access and remove device administrator privileges that may have been granted to the malicious apps. Should the app still resist removal or return after a restart, users are advised to back up important data and perform a factory reset.

Reporting and Further Action

The NCTAU has asked users to report fraudulent applications or scam incidents by calling 1930 or visiting the official cybercrime reporting website, as mentioned in multiple advisories. ThePrint noted that it has reached out to a Meta representative for comment on the matter, and that its report would be updated upon response.

Authorities have been alerted to keep a close watch on these apps, with the NCTAU observing a rise in financial fraud perpetrated through such malicious applications. The advisory serves as a reminder of the risks associated with sideloading apps from unverified sources and the importance of exercising caution with permissions requested by any application.