New Delhi, Aug 2026 : The National Cybercrime Threat Analytics Unit (NCTAU), functioning under the Union Home Ministry’s Indian Cyber Crime Coordination Centre (I4C), has warned Android users about a growing financial fraud threat involving malicious applications disguised as pornography apps and promoted through advertisements on social media platforms.
In an advisory, the NCTAU identified several applications, including “Night Play”, “Reloop”, “Kyss”, “Vimo”, “Rivo”, “Nexo” and “Vixa”, along with similar variants, as part of the emerging threat. The agency said such applications are primarily promoted through pornography-related advertisements and links appearing on Facebook and Instagram.
According to the advisory, users who click on these advertisements may be redirected to websites offering pornographic content. The websites then encourage visitors to download an Android Package Kit (APK) from outside the official Google Play Store.
The agency said many of the identified websites are associated with “.live” domains. Once the first malicious application is installed, users may be asked to download another package presented as an application update. This secondary installation can allow attackers to exploit permissions already granted to the initial application.
A major concern highlighted by the NCTAU is the malware’s ability to obtain Accessibility and other sensitive permissions. Once such permissions are granted, the malicious application can gain extensive control over the device, monitor activity and continue running in the background without the user's knowledge.
In some cases, the malware may also install a virtual private network (VPN) and route the victim’s internet traffic through servers controlled by attackers. This could expose sensitive information transmitted through the device and create opportunities for further malicious activity.
The advisory also warned that certain variants may interfere with the normal process of uninstalling the application, making it difficult for users to remove the malware through standard device settings.
How the Fraud Works
| Stage | Possible Threat |
|---|---|
| Social media advertisement | User is lured through misleading content |
| Malicious website | User is redirected outside the official app ecosystem |
| APK download | Unverified application is installed |
| Fake update | Secondary malicious package may be installed |
| Accessibility permissions | Malware gains greater device control |
| VPN installation | Internet traffic may be routed through attacker-controlled servers |
| Device compromise | Sensitive information and financial activity may be targeted |
The NCTAU said the suspected modus operandi can ultimately lead to unauthorised financial transactions. The agency has therefore urged users to exercise particular caution when downloading applications promoted through social media advertisements or unfamiliar websites.
The most important precaution is to download applications only from the Google Play Store or other trusted and verified app stores. Users have been specifically advised against installing APK files received through advertisements, suspicious websites or unknown links.
The agency has also cautioned users against granting Accessibility permissions to unfamiliar applications. Such permissions can provide applications with extensive capabilities on an Android device and should only be granted when genuinely required and to trusted applications.
Users should regularly review the applications installed on their devices and remove any unfamiliar or suspicious software. Keeping Google Play Protect enabled, installing the latest Android security updates and regularly monitoring bank accounts and UPI transactions can provide additional protection.
For users who are unable to remove a suspicious application normally, the NCTAU has recommended restarting the Android device in Safe Mode and then accessing the Apps section under Settings to uninstall it.
Before attempting removal, users should also disable the application's Accessibility access and revoke any administrator privileges it may have obtained through the device's security settings.
If the suspicious application cannot be removed or returns after restarting the device, the advisory recommends backing up important data and considering a factory reset.
The NCTAU's warning underlines the growing sophistication of digital fraudsters, who are increasingly using social media advertising, deceptive downloads and excessive device permissions to target users. With financial transactions increasingly conducted through smartphones, users are being urged to treat unexpected APK downloads and requests for sensitive permissions as major warning signs.