The warning was issued by the National Cybercrime Threat Analytics Unit (NCTAU), a unit under the Union Home Ministry's Indian Cyber Crime Coordination Centre (I4C).

Home Ministry Warns of Malicious Android Applications Promoted Through Facebook and Instagram; Users Risk Device Takeover and Unauthorised Transactions

Meta has removed several advertisements from its platforms after the Centre flagged a growing cyber-fraud threat involving malicious Android applications disguised as pornography apps.

The warning was issued by the National Cybercrime Threat Analytics Unit (NCTAU), a unit under the Union Home Ministry's Indian Cyber Crime Coordination Centre (I4C).

According to the advisory, cybercriminals are using advertisements on Facebook and Instagram to direct users to websites that encourage them to download malicious Android applications. Once installed, these applications can seek sensitive permissions and potentially gain extensive control over the user's device.

The campaign is particularly concerning because access to a compromised smartphone can potentially be used to facilitate financial fraud, unauthorised transactions and theft of sensitive information.

Meta Acts After Government Flags Malicious Advertisements

Meta removed several advertisements after the Centre highlighted the threat.

The development underlines the growing challenge for social-media platforms, where advertisements can serve as an entry point for malicious campaigns.

Cybercriminals can use seemingly legitimate advertisements to redirect users to external websites, where they are encouraged to download applications that are not available through official app stores.

The government's warning therefore extends beyond the applications themselves to the entire chain of advertisement, website, download and device compromise.

Centre Warns of Rising Financial Fraud Risk

The NCTAU has warned about a rise in financial fraud associated with malicious Android applications that are presented as pornography-related apps.

The advisory identified applications operating under names including:

  • Night Play

  • Reloop

  • Kyss

  • Vimo

  • Rivo

  • Nexo

  • Vixa

The government has also warned that similar variants may use different names.

The names of applications can change quickly, meaning users should not assume that an app is safe simply because it does not appear on the list.

How the Scam Starts

The fraud campaign relies heavily on social engineering.

Instead of approaching victims directly with a conventional phishing message, attackers use advertisements designed to attract attention and encourage users to visit an external website.

The process can broadly work as follows:

Social-media advertisement → external website → APK download → fake update → sensitive permissions → device control → possible financial fraud

Each stage is designed to move the user closer to giving the malicious application greater access to the smartphone.

Step 1: User Sees a Malicious Advertisement

The first stage begins with an advertisement appearing on a social-media platform.

The advertisement may use provocative or misleading content to persuade the user to click.

Because the advertisement appears within a familiar platform, users may incorrectly assume that the destination is trustworthy.

Step 2: Advertisement Redirects User to a Website

After clicking, users may be redirected to an external website.

The website can be designed to look like a legitimate content platform and may encourage visitors to install an application to access or continue viewing content.

The NCTAU advisory said many of the websites associated with the campaign use “.live” domains.

Step 3: User Is Asked to Download an APK

The website then encourages the user to download an Android APK.

An APK is an Android application installation package.

Downloading an APK from an unknown website is significantly riskier than installing an application from a trusted application store because the application has not necessarily gone through the same distribution and security controls.

The NCTAU has therefore specifically advised users not to download APK files from advertisements, suspicious websites or unknown links.

Step 4: A Fake Update Installs Additional Malware

The initial application may subsequently display a message claiming that an update is required.

The user is then encouraged to install another package.

This secondary installation can introduce additional malicious components to the device.

The first application may already have obtained permissions that make it easier for the second package to be installed or operated.

Step 5: Attackers Seek Accessibility Permissions

One of the most important stages of the attack involves Accessibility permissions.

Accessibility features are legitimate Android functions designed to help users interact with their devices.

However, when such access is granted to an unknown application, it can potentially provide the application with extensive capabilities to interact with the device.

This is why the government has warned users against granting Accessibility access to applications they do not recognise or trust.

Step 6: Malware Can Attempt to Control the Device

Once sensitive permissions are granted, the malicious application may continue running in the background.

The advisory warns that such applications can potentially gain control over parts of the device and interfere with normal operations.

This creates a much greater security risk than simply having an unwanted application installed.

Some Malicious Apps May Install a VPN

The NCTAU has also warned that some of these applications may install a Virtual Private Network (VPN).

VPN technology itself is legitimate and widely used for privacy and secure connectivity.

However, a malicious VPN controlled by an attacker could potentially route internet traffic through infrastructure controlled by the attacker.

This creates additional risks involving the user's data and online activity.

Malware May Resist Uninstallation

Another concerning feature highlighted by the advisory is that some malicious applications may attempt to prevent users from uninstalling them through normal device settings.

This can make it harder for victims to regain control of their smartphones.

Users who find that an unfamiliar application cannot be removed normally should treat the situation as a potential security incident rather than continuing to use the device for banking or other sensitive activities.

How the Attack Can Lead to Financial Fraud

The biggest concern is the potential transition from malware infection to financial loss.

A compromised smartphone may contain access to banking applications, payment applications, email accounts, authentication messages and other sensitive information.

If attackers gain sufficient control, they may attempt to interfere with financial activity or obtain information that can assist in unauthorised transactions.

The government's advisory therefore connects the entire attack chain to the possibility of financial fraud.

Why Banking and UPI Users Need to Be Extra Careful

India's financial ecosystem has become increasingly smartphone-driven.

Consumers now use their mobile phones for:

  • UPI payments

  • Mobile banking

  • Stock-market investments

  • Mutual fund transactions

  • Insurance

  • Credit-card management

  • Digital wallets

  • Online shopping

A compromised smartphone can therefore expose a much larger range of sensitive activities than it could in the past.

Users should treat smartphone security as an important part of protecting their finances.

Social Media Does Not Guarantee App Safety

One of the important lessons from the incident is that users should not assume that an advertisement is safe simply because it appears on a well-known social-media platform.

Social-media platforms host enormous volumes of advertisements, and malicious campaigns can attempt to exploit the advertising ecosystem.

Users should independently assess the destination website and application before downloading anything.

Government Advises Users to Download Apps Only From Trusted Sources

The NCTAU has advised users to install applications only from Google Play Store or other trusted app stores.

Users should avoid downloading applications from:

  • Social-media advertisements

  • Unknown websites

  • Pop-up windows

  • Suspicious messages

  • Unverified links

  • Third-party APK websites

If an application is not available through a trusted store and the user is being pressured to install it immediately, that should be treated as a warning sign.

Never Grant Accessibility Access Without a Clear Reason

Users should also carefully review requests for Accessibility permissions.

An unfamiliar entertainment or content application generally should not require extensive control over the device.

If an application requests Accessibility access without an obvious and legitimate reason, users should decline the request and consider uninstalling the application.

Keep Google Play Protect Enabled

The government has advised users to keep Google Play Protect enabled.

Security features such as Play Protect can provide an additional layer of protection against potentially harmful applications.

However, users should not rely entirely on automated protection.

Safe downloading behaviour remains essential because malicious applications can use social engineering to convince users to bypass warnings or manually install software.

Keep Android Devices Updated

Users should also install legitimate operating-system and security updates as they become available.

Software updates frequently include security fixes designed to address vulnerabilities that could otherwise be exploited by attackers.

Keeping smartphones updated is particularly important for devices used for banking, investment and payment services.

Regularly Monitor Bank and UPI Transactions

The NCTAU has advised users to regularly check their bank accounts and UPI transactions.

Consumers should look for:

  • Unknown payments

  • Unauthorised UPI transactions

  • Unexpected account activity

  • Suspicious changes to account settings

  • Unfamiliar beneficiaries

  • Unusual SMS or notification activity

Any suspicious financial activity should be reported immediately.

What to Do If a Suspicious App Is Already Installed

Users who believe they have installed one of these applications should avoid continuing to use the compromised device for sensitive transactions until the application has been removed and the device secured.

The NCTAU has recommended several steps.

Restart the Phone in Safe Mode

If the application refuses to uninstall normally, users can restart the Android device in Safe Mode.

Safe Mode limits the operation of third-party applications and can make it easier to identify and remove suspicious software.

Remove the Suspicious Application

Users should navigate to the device's application settings, identify the suspicious application and uninstall it.

After removal, the device can be restarted normally.

Remove Accessibility Permissions

Users should check whether the suspicious application has been given Accessibility access.

If so, the permission should be disabled.

Check Administrator Permissions

Users should also review device-administrator permissions.

If the suspicious application has obtained administrator access, that access should be removed before attempting to uninstall the application.

Factory Reset if the Malware Persists

If the application cannot be removed or returns after restarting the device, the government advisory recommends backing up important data and considering a factory reset.

A factory reset can remove persistent malicious applications, although users should make sure that important data is safely backed up before proceeding.

Report Financial Fraud Immediately

Victims of financial fraud should act quickly.

The government has asked users to report cybercrime incidents through the national helpline 1930 or the National Cybercrime Reporting Portal.

Early reporting is particularly important in cases involving unauthorised financial transactions, as rapid action can assist authorities and financial institutions in attempting to stop or trace fraudulent transfers.

What the Incident Means for Meta

The episode puts additional focus on the role of major digital platforms in preventing malicious advertisements.

Platforms such as Facebook and Instagram have become major channels through which businesses reach consumers.

At the same time, cybercriminals can attempt to exploit the same advertising infrastructure to distribute deceptive content.

The incident highlights the need for stronger advertising verification, rapid threat detection and cooperation between technology companies and government cybersecurity agencies.

Cybersecurity Becomes More Important as Digital Payments Grow

The threat comes at a time when India's digital economy is expanding rapidly.

Consumers increasingly depend on smartphones for financial and commercial activity.

This has created a growing attack surface for cybercriminals.

The risk is no longer limited to stealing passwords through conventional phishing. Attackers are increasingly attempting to compromise the device itself.

Once a device is compromised, the potential consequences can be significantly broader.

Implications for India's Cybersecurity Ecosystem

The latest warning also highlights the importance of cybersecurity across India's rapidly expanding digital economy.

There could be increasing demand for:

  • Mobile-device security

  • Cybersecurity software

  • Fraud detection

  • Digital identity protection

  • Secure payment infrastructure

  • Endpoint security

  • Threat intelligence

  • Security monitoring

For technology companies, financial institutions and digital platforms, preventing fraud is becoming increasingly important as consumers shift more financial activity online.

Key Warning Signs for Users

Users should be particularly cautious when an online advertisement or website:

  • Asks them to download an APK

  • Claims an application requires an immediate update

  • Requests Accessibility access

  • Requests unusually broad device permissions

  • Attempts to install another application

  • Prevents normal uninstallation

  • Prompts installation outside an official app store

  • Redirects repeatedly between unfamiliar websites

  • Asks for banking or payment information

Any combination of these signs should be treated seriously.

A Simple Rule: Don't Install What You Don't Trust

The safest approach for users is straightforward:

Do not install an application simply because an advertisement tells you to.

If an application is legitimate, users should look for it through a trusted app store and verify the developer, reviews and permissions before installation.

Users should also remember that attackers can change application names and websites quickly.

Therefore, the safest defence is not memorising a list of malicious app names but recognising the behaviour and warning signs associated with the scam.

Meta-Government Cooperation Will Be Critical

The removal of the flagged advertisements demonstrates the importance of cooperation between technology platforms and government cybersecurity agencies.

Cybercrime campaigns can move quickly across platforms, domains and applications.

Government threat intelligence can help platforms identify malicious campaigns, while platforms can use their scale and technical capabilities to remove fraudulent advertisements and restrict malicious accounts.

Greater coordination could help reduce the time between identifying a threat and preventing it from reaching additional users.

Market Outlook

The latest warning highlights a broader trend: cybersecurity is becoming increasingly important to India's financial and digital ecosystem.

As UPI, mobile banking, online investments and digital commerce continue to expand, smartphones are becoming critical gateways to consumers' financial lives. This is also increasing the incentive for criminals to target mobile devices through sophisticated social-engineering and malware campaigns.

For investors, the development reinforces the long-term importance of cybersecurity, digital fraud prevention, secure payments, identity protection and threat-intelligence technologies.

For consumers, the message is even more direct: never download an APK from a social-media advertisement or unfamiliar website, and never grant sensitive permissions to an unknown application.

If a device appears compromised or an unauthorised transaction occurs, users should act immediately and report the incident through 1930 or the National Cybercrime Reporting Portal.

Visitors : HTML Hit Counters