In an advisory, National Cybercrime Threat Analytics Unit (NCTAU) said that it has observed a rise in financial frauds perpetrated through malicious Android apps masquerading as pornography apps, circulated through Facebook and Instagram ads. As per the Ministry of Home Affairs advisory, these Android apps are operating under the names “Night Play”, “Reloop”, “Kyss”, “Vimo”, “Rivo”, “Nexo”, “Vixa” and other similar variants. The government has warned of malicious porn apps on Instagram and Facebook that can completely take over Android phones.
Step 1: Start Your Phone in Safe Mode: Press and hold the Power button.
Domains of the website majorly belong to “.live”. “Safe Mode” will appear at the bottom of the screen. These apps are primarily distributed through advertisements on Facebook and Instagram, which redirect to websites and apps showing pornographic content, where the user is prompted to download an APK file. After installation, the app requests permissions that allow it to install additional apps and by misusing accessibility permission, take control of the users’ device. Some apps also install a VPN, which may be used to route internet traffic pertaining to malicious/criminal activity. As per government warning, these apps can secretly access information stored on users’ phones, capture one-time passwords and bank PINs, and transfer money from accounts without the owner’s knowledge. Not just this, the apps also make it difficult for users to uninstall them through device’s normal settings. Redirection: Ads redirect to phishing websites serving pornographic content. Users are persuaded to download and install the APK from sources outside the Google Play Store. Abuse of Accessibility Permission for device takeover: After installation, the app asks users to grant Accessibility and other sensitive permissions. Once enabled, the malware gains control of the device and continues to run in the background. VPN Installation: Some apps may also install a VPN on the device, thereby routing all internet traffic through attacker-controlled servers. This compromises user’s transmitted data, which may subsequently be exploited for malicious or criminal activities. Unauthorized Transactions: Since the malware has the ability to take over the compromised device, installing such apps may lead to financial fraud. Press and hold Power Off until the Safe Mode option appears. Click OK or Restart in Safe Mode. Wait for the phone to restart. Verify the Device: Open Settings > Apps. Confirm that the suspicious application has been removed. If the app cannot be removed or returns after restarting, back up your important data and perform a Factory Reset.

