Meta has purged dozens of Facebook and Instagram advertisements after the Indian government identified a sophisticated malware campaign using explicit content to steal banking credentials. The move comes amid a surge in cyber-fraud losses in India, totaling nearly $2.4 billion in 2025.
- Meta removed dozens of ads on Facebook and Instagram after India flagged malware scams.
- Scammers used sexually explicit content to lure users into downloading malicious APK files.
- India reported nearly $2.4 billion in cyber-fraud losses in 2025.
- The malware targeted banking credentials and OTPs to drain user accounts.
In a swift response to warnings from the Indian government, Meta has removed dozens of advertisements across its flagship platforms, Facebook and Instagram. The government flagged a dangerous pattern where ads utilized sexually explicit thumbnails and content to deceive users into downloading malicious Android applications, which were designed to compromise financial security.
According to government reports, these fraudulent ads operated under deceptive names such as “Night Play” and “Kyss”. These advertisements directed unsuspecting users to phishing websites that prompted the download of files like “Movexa.apk”. Because these files were hosted outside official app stores, they bypassed standard security protocols, allowing the malware to gain deep access to the device's operating system.
BozokMedia analysis shows that this incident highlights a critical vulnerability in Meta's ad-vetting process. Despite strict policies prohibiting adult nudity and deceptive practices, the fact that these ads remained active even after a government advisory suggests a systemic failure in real-time moderation. This is particularly alarming given that India is currently experiencing a digital-payments boom, making its massive user base a prime target for global cyber-syndicates.
The shift toward APK-based malware delivery via social ads represents a dangerous evolution in social engineering, bypassing the safety nets of the Google Play Store.
The scale of the problem is reflected in the staggering financial toll. India recorded nearly $2.4 billion in cyber-fraud losses in 2025 alone. This trend is not limited to Meta; the Indian government recently forced Google to shut down hundreds of accounts on its Firebase platform that were being used to impersonate major banking institutions.
Internal projections from within Meta, reported previously, suggested that scam and banned goods advertising could account for nearly 10% of the company's 2024 revenue—approximately $16 billion. This creates a perceived conflict of interest between profit margins and the rigorous enforcement of safety policies regarding deceptive advertising.
Q1: How did these scams work?
The scams used explicit ads to lure users to a website, where they were asked to download a third-party app (APK). Once installed, the app stole OTPs and banking PINs to transfer money.
Q2: What should users do to stay safe?
Users should never download apps from links in ads or third-party websites; always use the official Google Play Store or Apple App Store.