The Ministry of Home Affairs has warned that malware-laced apps promoted as adult content can seize total control of smartphones and facilitate unauthorized financial transactions.
- Malicious APKs are being promoted via Facebook and Instagram ads under the guise of pornographic content.
- Granting 'Accessibility Permission' allows hackers complete device control and silent monitoring.
- High-risk apps identified include Night Play, Reloop, Kyss, Vimo, Rivo, Nexo, and Vixa.
The Indian Cyber Crime Coordination Centre (I4C), under the Ministry of Home Affairs (MHA), has issued a critical advisory regarding a surge in cyber fraud. Criminals are leveraging the lure of adult content to trick users into downloading malicious APK files from unofficial sources, bypassing the security protocols of official app stores like Google Play.
The advisory specifically names several dangerous applications, including Night Play, Reloop, Kyss, Vimo, Rivo, Nexo, and Vixa. These apps are designed to operate silently in the background, capturing personal data and monitoring internet traffic while the user remains unaware of the breach.
Why This Matters
BozokMedia analysis shows that this is not a simple hacking attempt but a sophisticated social engineering campaign. By exploiting human curiosity, attackers trick users into granting 'Accessibility Permissions.' This specific permission is the 'skeleton key' for hackers, allowing them to read screen content, intercept OTPs, and manipulate device functions without user interaction.
"The transition from technical hacking to social engineering means the user is now the weakest link in the security chain."
Furthermore, the MHA warns that these apps often install covert VPN services. This diverts the user's entire internet traffic through servers controlled by the attackers, enabling a 'Man-in-the-Middle' attack where passwords and sensitive credentials can be harvested in real-time.
The ultimate goal of these campaigns is often financial theft. Once the device is fully compromised, attackers can facilitate unauthorized banking transactions, draining digital wallets and bank accounts through seamless access to payment gateways.
Frequently Asked Questions
Q1: What should I do if I suspect my device has been compromised?
Immediately contact the national cybercrime helpline at 1930 or report the incident via the official portal at cybercrime.gov.in.
Q2: How can I protect my phone from such malware?
Avoid clicking on suspicious social media ads, never download APKs from unknown websites, and strictly avoid granting 'Accessibility Permissions' to untrusted apps.