TECH NEWS

Fake Porn Apps on Facebook and Instagram Can Hijack Your Phone and Empty Your Bank Account: How the Scam Works

A single tap on a Facebook or Instagram advertisement can be enough to lose control of an Android phone — and the money sitting in the bank accounts linked to it. The Ministry of Home Affairs has warned that fraudsters are dressing malware up as pornography apps, pushing them through social media ads, and then using the phone itself to steal OTPs, PINs and complete unauthorised transfers.

The alert comes from the National Cybercrime Threat Analytics Unit (NCTAU) under the Indian Cyber Crime Coordination Centre (I4C). In an advisory dated 26 August 2026, the unit said it had seen a rise in financial frauds carried out through malicious Android applications circulating under names such as Night Play, Reloop, Kyss, Vimo, Rivo, Nexo and Vixa, along with similar variants. The names look harmless. The payload is not.

How users are lured in

The campaign does not begin on the Google Play Store. It begins in the feed.

A user scrolling Facebook or Instagram sees an advertisement promising adult content, a dating-style experience, or unrestricted access to videos. The ad does not send the person to an official app listing. It redirects them to a separate website that displays pornographic material. Many of these sites use “.live” domains. On that page, a prompt appears: download an APK to continue watching or to unlock the full app.

An APK — Android Package Kit — is simply the file format used to install apps on Android. Play Store downloads go through Google’s screening. Sideloaded APKs from random websites do not. That is the first break in the victim’s defence.

People click because the pitch is designed for haste. The site looks like a content portal. The button looks like a normal install. There is no obvious warning that the file is malware.

What happens after the first install

Once the first app is on the phone, the attack usually moves in layers.

The application asks for permissions that let it install other software. It then presents a second package as an “update.” That second file rides on permissions already granted to the first app. At some point the user is asked to turn on Accessibility Services and other sensitive controls. If those are granted, the malware can run in the background and treat the phone as if the attacker were holding it.

Some variants also install a VPN. The VPN routes the device’s internet traffic through servers the attackers control. That can expose browsing, login sessions and other data moving off the phone. In several cases the app also blocks normal uninstallation from Settings, so the victim cannot simply delete it and walk away.

The chain described by investigators is short and repeatable: social media ad, malicious website, APK download, fake update, Accessibility and VPN permissions, device takeover, then unauthorised financial transactions.

Why Accessibility permission is the real weapon

Accessibility was built so genuine apps can help people who cannot tap a screen easily. In the wrong hands it becomes a remote control.

Once that permission is on, the malware can read what is displayed on the screen, press buttons, type text, capture one-time passwords and PINs, confirm UPI requests, and start fund transfers. Banking apps do not need to be “hacked” in the old sense. The attacker is operating the same interface the owner would use. OTPs that arrive by SMS can be read and entered before the victim notices. PINs typed on screen can be captured the same way.

That is why the advisory treats Accessibility as the critical failure point. An unknown app asking for it should be treated as a red flag, not a routine prompt.

The financial endgame is straightforward. After the device is under control, the operators can open banking or UPI apps, move money to mule accounts, and disappear. Some reports also note that the same access can expose contacts, messages, photos and files — useful for further blackmail or follow-up fraud.

Why the names keep changing

Night Play, Reloop, Kyss, Vimo, Rivo, Nexo and Vixa are the labels listed in the current advisory. They should not be treated as a complete blacklist. Similar campaigns reuse the same method under new titles as soon as the old ones are flagged. Trusting a name, an icon, or a slick landing page is not a security check. The only reliable test is the source of the install.

Meta has reportedly taken down some of the advertisements after the government raised the issue. That does not close the door. New ads and new domains can appear the same week.

What Android users should do now

The official advice is blunt.

Download apps only from the Google Play Store or other trusted stores. Do not install APK files from advertisements, unknown websites or forwarded links. Do not grant Accessibility access to any app you did not deliberately seek out and cannot verify. Keep Google Play Protect switched on and install Android security updates when they arrive. Periodically open the app list and remove anything you do not recognise.

Watch bank SMS alerts and UPI history. A small test debit is often the first sign that a device has been compromised. If a transaction looks wrong, call the bank immediately and then report the incident.

The government also repeats the usual but still necessary rules: do not share OTPs, PINs, passwords, CVV numbers or banking details with anyone. Do not act on panic calls that claim a KYC problem, a parcel hold, a reward, or a police case. Fraudsters routinely impersonate bank staff, courier agents, customer-care desks and government officers. Verify through official numbers you already have, not the number on the incoming call.

If the app is already on the phone

If a suspicious app will not uninstall through Settings, restart the device in Safe Mode and try again from the Apps menu. Before deleting it, revoke Accessibility access and any device-administrator rights it was given. If the app returns after a restart or cannot be removed at all, back up important files and consider a factory reset. A reset is disruptive. Leaving remote control on the device is worse.

How to report it

Victims should call the national cybercrime helpline 1930 and file a complaint on cybercrime.gov.in. For financial fraud, speed matters. Early reporting improves the chance that banks can mark a lien on the receiving account before the money is layered out. Keep screenshots of the ad, the website, the APK prompt, transaction IDs and any SMS trail. Those details help investigators even when the app name has already changed.

The same portal also lets people report suspect websites, numbers and social media links, which feeds the wider suspect repository used by banks and police.

The larger pattern

This campaign is not a novelty crime so much as a refined version of an old one: bait, sideload, over-permission, drain. Adult content is only the lure because it works. The same infrastructure — Meta ads, throwaway websites, APKs outside the Play Store, Accessibility abuse — can be wrapped around dating apps, video players, or “free” tools tomorrow.

The defence is unglamorous and still effective. Install from official stores. Treat extra permissions as a cost, not a formality. Check the app drawer. Watch the bank feed. Report fast. The MHA warning is not asking users to stop using smartphones. It is asking them not to hand the phone to a stranger because an advertisement promised something they were never going to get for free.

Click to rate this post!
[Total: 0 Average: 0]

About The Author

Leave a Reply

Discover more from NEWS NEST

Subscribe now to keep reading and get access to the full archive.

Continue reading

Verified by MonsterInsights