Fake Porn Apps Target Android Users Via Ads On Facebook, Instagram: How To Stay Safe

Cybercriminals are increasingly targeting Android users through deceptive advertisements promoting malicious applications disguised as pornographic content on platforms such as Facebook and Instagram. The National Cybercrime Threat Analytics Unit (NCTAU), part of the Union Home Ministry’s Indian Cyber Crime Coordination Centre (I4C), has raised alarms about this trend, prompting Meta to take action by removing numerous sexually explicit advertisements.

The NCTAU reports that these ads are cleverly crafted to lure unsuspecting users into phishing traps or to entice them into downloading malware that can compromise their banking credentials and empty their accounts. The I4C has identified a range of malicious applications linked to this threat, including “Night Play,” “Reloop,” “Kyss,” “Vimo,” “Rivo,” “Nexo,” “Vixa,” and other similar variants.

How the Scam Works

The modus operandi of these cybercriminals involves promoting malicious apps through enticing pornography-related advertisements on social media. When users click on these ads, they are redirected to websites that offer pornographic content, which then prompt them to download an Android app, typically in the form of an APK file.

These APK files are not sourced from the Google Play Store; instead, users are encouraged to install them directly from the website. The advisory notes that many of these websites utilize “.live” domains. Once the initial app is installed, users may be prompted to download a second package that masquerades as an app update. This second package can exploit permissions already granted to the first app.

According to the advisory, the malicious app may request users to enable Accessibility Services and other sensitive permissions. Granting these permissions can provide the malware with extensive control over the device, allowing it to operate unnoticed in the background. Some variants of the malware may even install a VPN on the device, potentially routing the user’s internet traffic through servers controlled by the attackers, thereby exposing sensitive data to misuse. The suspected chain of attack unfolds as follows:

Social media ad → Malicious website → APK download → Fake update → VPN/Accessibility permissions → Device takeover → Possible unauthorized financial transactions.

How to Protect Yourself

  • Whenever possible, download Android apps from the Google Play Store or other trusted app stores.
  • Avoid installing APK files from advertisements, random websites, or suspicious links.
  • Do not grant Accessibility access to unknown apps, as such permissions can provide significant control over your device.
  • Regularly review the apps on your phone and remove anything unfamiliar or unused.
  • Keep Google Play Protect enabled and install the latest Android security updates promptly.
  • Monitor your bank and UPI accounts for any unusual activity. If you notice an unauthorized transaction, report it to your bank and the relevant cybercrime authorities immediately.

What to Do If You Can’t Uninstall the Suspicious App

  1. Try Safe Mode: If a suspicious app cannot be uninstalled normally, restart your Android device in Safe Mode. Then navigate to Settings → Apps and attempt to remove the app.
  2. Remove Special Permissions: Before uninstalling, you may need to disable its Accessibility access and revoke any administrator privileges it holds.
  3. Factory Reset: If the app remains persistent or reappears after a restart, back up your important data and perform a factory reset as a last resort.
AppWizard
Fake Porn Apps Target Android Users Via Ads On Facebook, Instagram: How To Stay Safe