The National Cybercrime Threat Analytics Unit (NCTAU) has flagged a rise in financial frauds involving malicious Android applications disguised as pornography apps. These apps are being promoted through advertisements on Facebook and Instagram.
Advisory Issued
The unit, operating under the Ministry of Home Affairs’s Indian Cyber Crime Coordination Centre (I4C), issued an advisory urging citizens to remain alert to online fraud. Users are advised to follow basic digital safety practices when using phones, banking apps, and social media platforms.
Malicious Applications Identified
The applications, circulated under names such as ‘Night Play’, ‘Reloop’, ‘Kyss’, ‘Vimo’, ‘Rivo’, ‘Nexo’, and ‘Vixa’, are designed to lure users into downloading malware that can compromise personal and financial information.
““These applications are primarily distributed through advertisements on Facebook and Instagram, which redirect to websites serving pornographic content, where the user is prompted to download the APK,” the advisory stated.
APK, or Android Package Kit, is the file format that Android devices use to distribute and install mobile applications.
Risks After Installation
After installation, the app requests permissions that allow it to install additional applications. By abusing accessibility permission, it can take control of the users’ device, potentially leading to financial fraud. Some apps may also install a VPN (virtual private network), which could be used to route internet traffic related to malicious activities.







