

The government warned Android users about malicious apps disguised as pornography applications and promoted through advertisements on Facebook and Instagram. According to an advisory from the National Cybercrime Threat Analytics Unit (NCTAU), financial frauds involving such malicious Android apps are on the rise.
The advisory issued by the Ministry of Home Affairs said these apps can take complete control of an Android phone, potentially allowing attackers to access sensitive information and carry out financial transactions without the user’s knowledge.
The malicious applications identified by authorities include ‘Night Play’, ‘Reloop’, ‘Kyss’, ‘Vimo’, ‘Rivo’, ‘Nexo’, ‘Vixa’ and other similar variants.
These apps are primarily circulated through advertisements on Facebook and Instagram. The advertisements redirect users to websites displaying pornographic content, where they are prompted to download an APK file.
After installation, the apps request permissions that allow them to install additional applications. They also misuse Accessibility permissions to gain control of the device.
According to the government warning, some of these apps can secretly access information stored on users’ phones, capture one-time passwords and bank PINs, and transfer money from accounts without the owner’s knowledge. The apps can also make themselves difficult to uninstall through the phone’s normal settings.
Also Read: Tim Cook Warns iPhone Users About Facebook Tracking Across Apps
The malicious apps are distributed mainly through pornographic-content advertisements or links on Facebook and Instagram. These ads redirect users to phishing websites, with domains that mainly end in ‘.live’.
Users are then persuaded to download APK files from sources outside the Google Play Store. A secondary package may subsequently be downloaded and installed under the pretext of an app update.
The malware then asks users to grant Accessibility and other sensitive permissions. Once these permissions are enabled, it can take control of the device and continue running in the background.
Some apps may also install a VPN, routing internet traffic through attacker-controlled servers. This can compromise transmitted data, which may subsequently be exploited for malicious or criminal activities.
The government said that since the malware can take over compromised devices, installing such applications may lead to financial fraud.
The advisory recommends restarting the affected phone in Safe Mode, then uninstalling the suspicious application via Settings> Apps. Users should also remove other unknown or related applications before restarting the device normally.
If required, users should restore the default home screen, restrict Accessibility access for the suspicious application, and remove its administrator access under Security or Security & Privacy settings.
Authorities also advise users to verify that the suspicious app has been removed. If the application cannot be removed or returns after restarting, users should back up important data and perform a factory reset.