< Back to all clusters
[TECHNOLOGY] · India · 9 sources

started · updated

India warns of malicious porn apps on Meta platforms used for financial fraud

The Indian Ministry of Home Affairs has issued an advisory warning Android users about fraudulent advertisements on Facebook and Instagram. These ads promote malicious applications disguised as pornography to lure users into downloading software from outside official app stores.

Identified suspicious applications include “Night Play”, “Kyss”, “Reloop”, “Vimo”, “Rivo”, “Nexo”, and “Vixa”. The malware typically directs users to phishing websites, often using “.live” domains, to download APK files. Once installed, these apps can request Accessibility permissions, allowing attackers to monitor screens, intercept one-time passwords (OTPs) and bank PINs, and perform unauthorized financial transactions.

Some versions of the malware may also install a VPN to route internet traffic through attacker-controlled servers or make the software difficult to uninstall. In response to government alerts, Meta has removed dozens of these advertisements. The advisory recommends that users only download apps from trusted stores like Google Play, avoid installing unknown APK files, and enable Google Play Protect to mitigate risks.

Entities

Google · Indian Cyber Crime Coordination Centre · Meta · Ministry of Home Affairs