Meta has scrubbed dozens of explicit advertisements from Facebook and Instagram after the Indian government flagged a dangerous malware campaign targeting bank accounts. The scam used adult-themed apps to steal sensitive financial credentials from Android users.
- Meta removed dozens of explicit ads on Facebook and Instagram after warnings from the Indian government.
- Malicious Android apps masquerading as adult content were used to steal banking PINs and OTPs.
- India faced nearly $2.4 billion in cyber-fraud losses in 2025, driving urgent regulatory action.
In a swift response to security alarms raised by the Indian government, Meta has removed dozens of advertisements across its flagship platforms, Facebook and Instagram. These ads were reportedly employing a deceptive strategy, using sexually explicit content and thumbnails to lure unsuspecting users into downloading malicious Android applications.
The government's investigation revealed a sophisticated pattern where ads operating under names like "Night Play" and "Kyss" redirected users to phishing websites. Once installed, these applications—which masqueraded as pornography apps—could secretly access a user's phone data, capture one-time passwords (OTPs), and steal bank PINs, allowing scammers to drain accounts without the owner's knowledge.
Why This Matters
BozokMedia analysis shows that this incident highlights a critical vulnerability in the ad-vetting processes of Big Tech giants. Despite strict policies against adult nudity and deceptive practices, the persistence of these ads suggests a gap between corporate policy and algorithmic enforcement. As India continues its digital payments boom, the stakes for cybersecurity have never been higher.
The weaponization of adult content to deliver financial malware represents a calculated psychological exploit that bypasses traditional user caution.
The scale of the threat is underscored by recent data showing that India recorded nearly $2.4 billion in cyber-fraud losses in 2025. This surge in financial crime has led the Indian government to take a more aggressive stance against technology platforms. This is not an isolated incident; recently, the government also compelled Google to shut down hundreds of accounts on its Firebase platform that were being used to impersonate major banking institutions.
Interestingly, reports indicate a conflict between Meta's public safety stance and its internal revenue projections. Last year, it was reported that Meta internally projected that scam and banned goods advertising could generate approximately 10% of its 2024 revenue, amounting to roughly $16 billion, raising questions about the incentive structures within the company's ad ecosystem.
The technical mechanism of the scam involved bypassing official app stores. For instance, one active ad led users to download a file named "Movexa.apk" directly. By avoiding the Google Play Store's security screenings, the malware could operate undetected on the device, granting attackers full access to the victim's financial life.
Frequently Asked Questions
Q1: How did these malicious ads work?
They used explicit thumbnails to attract clicks, leading users to phishing sites where they were prompted to download an APK file masquerading as a video app.
Q2: What information can these malware apps steal?
They can access stored phone data, intercept SMS for OTPs, and capture bank PINs to facilitate unauthorized fund transfers.