The Ministry of Home Affairs (MHA) has issued a critical warning regarding fraudulent porn apps on social media that use malware to seize phone control and steal funds.
- Fraudulent ads on Facebook and Instagram are tricking users into downloading malicious apps.
- Downloading APK files from outside the Google Play Store poses a severe security risk.
- Granting 'Accessibility Permission' allows hackers full control over the device.
- High risk of unauthorized financial transactions and data theft.
Cyber criminals are evolving their tactics to exploit human curiosity and privacy. Recently, the I4C (Indian Cyber Crime Coordination Centre), operating under the Ministry of Home Affairs (MHA), flagged a dangerous trend where users are being lured by pornographic content advertisements on Facebook and Instagram.
These ads promote apps with names like ‘Night Play’, ‘Reloop’, ‘Kyss’, ‘Vimo’, ‘Rivo’, ‘Nexo’, and ‘Vixa’. Instead of directing users to the secure Google Play Store, these ads lead to suspicious websites where users are asked to download APK files—a primary delivery method for sophisticated mobile malware.
Why This Matters
BozokMedia analysis reveals that this is not a simple app installation but a calculated 'Social Engineering' attack. The critical point of failure occurs when a user grants 'Accessibility Permission'. This permission, designed for users with disabilities, allows the malware to 'read' the screen, intercept OTPs, and simulate clicks, effectively giving the attacker total control over the device and banking applications.
"The combination of third-party APKs and accessibility permissions creates a digital open door, allowing cybercriminals to bypass security layers and access financial data seamlessly."
Furthermore, these malicious apps often silently install a VPN (Virtual Private Network). This allows the attackers to route all the user's internet traffic through their own servers, enabling them to monitor every online activity, steal passwords, and compromise personal privacy without the user's knowledge.
| Feature | Official App (Play Store) | Fake APK App |
|---|---|---|
| Security Screening | Scanned by Google Play Protect | No screening, often contains malware |
| Permissions | Limited and necessary permissions | Excessive & sensitive (Accessibility) |
| Data Routing | Secure encrypted connection | Routed through suspicious VPN servers |
Cyber experts strongly advise against clicking on unknown links or downloading APKs from untrusted sources. Users should regularly audit their installed apps and immediately remove any software that appears suspicious or was installed without explicit intent.
Frequently Asked Questions
Q1: What should I do if I have already installed such an app?
A: Immediately disconnect from the internet, uninstall the app, and change all your banking and social media passwords. Report the incident at 1930.
Q2: Can my money be stolen just by downloading the app?
A: Downloading alone is a risk, but the actual theft usually happens after you grant sensitive permissions (like Accessibility), which allows the hacker to operate your bank app.