A severe warning has been issued for Android smartphone users regarding a widespread and dangerous cyber fraud scheme. The National Cybercrime Threat Analytics Unit operating under the Ministry of Home Affairs has sounded the alarm over malicious applications being heavily promoted on platforms like Facebook and Instagram under the guise of pornography apps. According to official findings, downloading these unauthorized applications puts users at a critical risk of having their banking credentials and other sensitive personal information stolen by cybercriminals.
The Trap Begins Through Social Media Advertisements
The National Cybercrime Threat Analytics Unit identified several suspicious applications in its advisory TAU/ADV/018 released on August 26. The identified malicious names include Night Play, Reloop, Kyss, Vimo, Rivo, Nexo, and Vixa. These apps are aggressively marketed through advertisements appearing on Meta platforms such as Facebook and Instagram. When an unsuspecting user clicks on these promotional ads, they are typically redirected to external websites that prompt them to download an APK file. These websites frequently utilize a.live domain structure. The primary danger stems from the fact that these APK files are downloaded entirely outside the official Google Play Store ecosystem.
Malware Can Gain Complete Control Over Your Device
Once the application is successfully installed on the device, it often masquerades as a system update and proceeds to download an additional secondary package. Following this, the application requests accessibility permissions from the user. If the user grants this authorization, cybercriminals gain the remote capability to view the phone screen, simulate screen taps, and execute various unauthorized actions. This capability is exploited to harvest one-time passwords, security PINs, and other confidential financial data, enabling unauthorized monetary transactions without the owner's knowledge.
Certain iterations of this malware can also install a VPN directly onto the affected phone, forcing all internet traffic to route through servers controlled by the attackers. In some instances, the malicious software is designed to actively block users from uninstalling it through conventional methods. Authorities strongly advise downloading applications exclusively from the Google Play Store or other trusted app repositories. Users must strictly refrain from installing apps via APK links received through Facebook, Instagram, SMS messages, or unknown websites, and should never grant accessibility permissions to untrusted applications.
How to Protect Your Device and Data
To safeguard against these sophisticated threats, users should keep Google Play Protect constantly enabled and ensure their Android operating system and device software are updated regularly. It is equally important to monitor bank accounts and UPI transaction histories closely for any unauthorized activity. If a suspicious application has been installed and refuses to delete through normal procedures, restarting the phone in Safe Mode and navigating to Settings and Apps allows the user to remove it. Should the malware persist, performing a Factory Reset remains the final viable option to restore device security.



















