2 days ago
India Warns of Fake Porn Apps Stealing Android Banking Details
Some online ads pretend to offer adult videos but actually promote dangerous phone apps.
These apps can be downloaded as APK files instead of through an official app store.
After installation, they may ask for powerful permissions that let them control parts of an Android phone.
They may also install more software or send the phone’s internet traffic through another server.
This could help criminals steal passwords, one-time codes or banking information.
The Indian government says people should not download apps from suspicious ads or websites.
People should use trusted app stores, keep their phones updated and check their bank transactions.
Anyone who loses money should report it quickly to 1930 or cybercrime.gov.in.
India’s National Cybercrime Threat Analytics Unit warned about malicious Android apps disguised as pornography apps.
The apps are promoted through Facebook and Instagram ads that redirect users to websites offering APK downloads outside official app stores.
Named apps include Night Play, Reloop, Kyss, Vimo, Rivo, Nexo and Vixa, along with similar variants.
The malware may abuse accessibility permissions, install additional software, resist removal and enable unauthorized financial transactions.
Users should avoid suspicious APKs, protect banking credentials, report fraud to 1930 or cybercrime.gov.in, and use Safe Mode or a factory reset if necessary.
- Who
- India’s National Cybercrime Threat Analytics Unit, operating under the Indian Cyber Crime Coordination Centre and Ministry of Home Affairs, warned Android users about the apps.
- What
- Malicious Android applications disguised as pornography apps are being used to facilitate financial fraud and potentially steal banking information.
- Where
- The apps were promoted through Facebook and Instagram advertisements and linked to websites, including sites with “.live” domains.
- When
- The warning was issued after the unit observed a rise in these frauds; the articles do not provide a specific date.
- Why
- The apps may abuse accessibility permissions and other device access to obtain sensitive information, control phones and conduct unauthorized transactions.
Government and security warning
Platform response and reported ad activity
Nature of the threat
Government and security warning
Indian officials say malicious apps disguised as pornography apps can abuse phone permissions, compromise information and facilitate financial fraud.
Platform response and reported ad activity
Meta’s advertising policies prohibit adult sexual content and deceptive practices intended to scam users, according to the report.
Advertisements after the warning
Government and security warning
The government urged users not to click suspicious links or download APKs from advertisements and dubious websites.
Platform response and reported ad activity
Reuters reportedly found at least 39 related ads still active after the advisory, while Meta said it removed the flagged ads once they were reported.
Key facts
- Named apps
- Night Play, Reloop, Kyss, Vimo, Rivo, Nexo and Vixa
- Distribution method
- Facebook and Instagram advertisements redirect users to websites offering malicious APK files.
- Main risk
- The apps may expose personal and financial information and enable unauthorized bank or UPI transactions.
- Abused feature
- Android Accessibility permissions may allow harmful programs to control parts of a device.
- Additional capability
- Some apps may install a VPN that routes phone traffic through servers controlled by attackers.
- Reported platform action
- Reuters reported that Meta removed flagged ads after India raised the issue; it also found at least 39 such ads still active after the advisory was issued.
- Fraud reporting
- Victims can contact India’s cybercrime helpline at 1930 or use cybercrime.gov.in.
Quotes
NCTAU advisory
Advisory issued by India’s National Cybercrime Threat Analytics Unit
“After installation, the app requests permissions that allow it to install additional applications and by abusing accessibility permission, take control of the users’ device, which may result in financial fraud.”
indianexpress.com
“These applications are primarily distributed through advertisements on Facebook and Instagram, which redirect to websites serving pornographic content, where the user is prompted to download the APK.”
indianexpress.com








