
The National Cybercrime Threat Analytics Unit (NCTAU) has observed a rise in financial fraud perpetrated through malicious Android applications masquerading as pornography apps, circulated through Facebook and Instagram ads operating under the names "Night Play", "Reloop", "Kyss", “Vimo”, “Rivo”, “Nexo”, “Vixa” and other similar variants.
These applications are primarily distributed through advertisements on Facebook and Instagram, which redirect to websites serving pornographic content, where the user is prompted to download the APK.
After installation, the app requests permissions that allow it to install additional applications and, by abusing accessibility permission, take control of the user’s device, which may result in financial fraud. Some apps also install a VPN, which may be used to route internet traffic pertaining to malicious/criminal activity.
The app may prevent users from uninstalling it through the device settings.
Modus operandi of fraud through malicious sideloaded pornographic Android apps
MODUS OPERANDI
Distribution: The malicious application is distributed through pornographic content-related advertisements or links, mainly on Facebook and Instagram. These ads redirect to phishing websites.
Redirection: Ads redirect to phishing websites serving pornographic content. Domains of the website mainly belong to “.live”. Users are persuaded to download and install the APK from sources outside the Google Play Store.
App Update: A secondary package gets downloaded and installed on the pretext of an app update, based on permissions abused by the first, initial app.
Abuse of Accessibility Permission for device takeover: After installation, the application asks users to grant Accessibility and other sensitive permissions. Once enabled, the malware gains control of the device and continues to run in the background.
VPN Installation: Some apps may also install a VPN on the device, thereby routing all internet traffic through attacker-controlled servers. This compromises users' transmitted data, which may subsequently be exploited for malicious or criminal activities.
Unauthorized Transactions: Since the malware has the ability to take over the compromised device, installing such apps may lead to financial fraud.
PRECAUTIONS AND SAFETY RECOMMENDATIONS
STEPS TO UNINSTALL
METHOD 1: SAFE MODE REBOOT
Step 1: Start Your Phone in Safe Mode: Press and hold the Power button. Press and hold Power Off until the Safe Mode option appears. Click OK or Restart in Safe Mode. Wait for the phone to restart. "Safe Mode" will appear at the bottom of the screen.
Step 2: Uninstall the App: Open Settings. Go to Apps. Select the suspicious application. Tap Uninstall. Remove any other unknown or related applications.
Step 3: Restart Normally: Restart the phone. The device will exit Safe Mode automatically.
ANOTHER METHOD
Step 1: Restore the Default Home Screen (If required): Open Settings. Go to Apps → Default Apps → Home App. Select your phone's original launcher (System Launcher, One UI Home, Pixel Launcher, etc.).
Step 2: Disable Accessibility Access: Open Settings. Tap Accessibility. Open Installed Services or Downloaded Apps. Select the suspicious application. Turn Accessibility Off.
Step 3: Remove Administrator Access: Open Settings. Go to Security or Security & Privacy. Open Device Admin Apps or Device Administrators. If the suspicious app is enabled, select it.
*Tap Deactivate or Turn Off.
*Verify the Device: Open Settings > Apps. Confirm that the suspicious application has been removed. If the app cannot be removed or returns after restarting, back up your important data and perform a Factory Reset.
Report any fraudulent applications or any scam incident immediately on 1930 or www.cybercrime.gov.in