Beware of Porn Apps: MHA Warns of Malicious Android Apps Targeting Users for Financial Fraud
Beware of Porn Apps: MHA Warns of Malicious Android Apps Targeting Users for Financial Fraud
Cybercrime unit flags apps circulated through Facebook, Instagram; warns users against sideloading APKs and granting Accessibility permissions
New Delhi, Aug 31: The Ministry of Home Affairs (MHA) has issued an advisory warning Android users about a growing financial fraud threat involving malicious applications disguised as pornographic apps and circulated through social media advertisements.
The National Cybercrime Threat Analytics Unit (NCTAU) under the Indian Cyber Crime Coordination Centre (I4C), of Ministry of Home Affairs (MHA), a copy of which lies with news agency JKNS stated that, it has observed a rise in financial frauds involving malicious Android applications operating under names including “Night Play”, “Reloop”, “Kyss”, “Vimo”, “Rivo”, “Nexo” and “Vixa”, among other similar variants.
According to the advisory, the applications are primarily promoted through advertisements on Facebook and Instagram. Users clicking such advertisements are redirected to websites displaying pornographic content and are subsequently persuaded to download an APK file from outside the Google Play Store.
The cybercrime unit warned that once installed, the malicious application may request sensitive permissions that can enable it to install additional applications and potentially take control of the device.
A major concern highlighted in the advisory is the misuse of Android’s Accessibility permission. Once granted, the malware can operate in the background and gain extensive control over the compromised device, potentially enabling attackers to facilitate unauthorised financial transactions.
The advisory said some of these applications may also download a secondary package by disguising it as an application update. The additional package may exploit permissions already granted to the initial application.
🎓 Explore Jobs by Qualification
Explore the latest job opportunities in J&K and across India based on your educational qualification.
In another reported tactic, some malicious applications may install a VPN on the device. This could route internet traffic through attacker-controlled servers, potentially exposing users’ transmitted data to further misuse.
The NCTAU cautioned that the ability of such malware to take control of a compromised device could ultimately be exploited to conduct financial fraud.
The cybercrime unit has advised users to install applications only from the Google Play Store or other trusted application stores and avoid downloading APK files received through advertisements, websites or suspicious links.
Users have also been specifically advised not to grant Accessibility permission to unknown applications, regularly review installed applications and remove those they do not recognise.
The advisory further recommends keeping Google Play Protect enabled, ensuring Android devices are updated and regularly checking bank accounts and UPI transactions for any unauthorised activity.
How to remove suspicious applications
The advisory outlines steps for users who suspect that a malicious application has been installed on their device.
Users can first restart their Android phone in Safe Mode by pressing and holding the Power button and then pressing and holding the Power Off option until the Safe Mode option appears. After entering Safe Mode, users can go to Settings > Apps, select the suspicious application and uninstall it, along with any other unknown or related applications.
The phone can then be restarted normally to exit Safe Mode.
If the application interferes with the device’s normal operation, users have also been advised to restore the default home-screen launcher, disable Accessibility access for the suspicious application and remove any Device Administrator privileges granted to it.
Users can check Settings > Accessibility > Installed Services or Downloaded Apps to disable Accessibility access. They can also check Security or Security & Privacy settings for Device Admin Apps or Device Administrators and deactivate suspicious applications.
Afterwards, users should verify under Settings > Apps that the suspicious application has been completely removed.
The advisory cautioned that if an application cannot be removed or returns after restarting the device, users should back up important data and consider performing a factory reset.
The MHA cybercrime unit has urged citizens to immediately report fraudulent applications or cyber-fraud incidents through the national helpline 1930 or the official cybercrime reporting portal www.cybercrime.gov.in. (JKNS)
