In a concerning trend, cybercriminals are increasingly deploying malicious Android applications disguised as pornography apps to seize control of users’ mobile devices and execute unauthorized financial transactions. The Indian Cyber Crime Coordination Centre (I4C), under the Union home ministry, has issued a warning regarding this alarming development.
The National Cybercrime Threat Analytics Unit (NCTAU), a component of I4C, has reported a surge in financial fraud linked to these applications, which are primarily advertised on social media platforms. An advisory released on August 26 highlighted several apps operating under names such as “Night Play,” “Reloop,” “Kyss,” “Vimo,” “Rivo,” “Nexo,” and “Vixa,” among others.
What happens after installing these apps?
Upon installation, these malicious applications request sensitive permissions, including Accessibility access. If users inadvertently grant these permissions, the malware can take control of the device, running silently in the background. The cybercrime unit has indicated that attackers can exploit Accessibility features to:
- Read information displayed on the screen
- Click buttons
- Enter one-time passwords (OTPs) or PINs
- Confirm transactions
- Initiate fund transfers
This series of actions can ultimately lead to unauthorized access to the victim’s bank account, resulting in financial theft.
Moreover, the malware may download and install a secondary application, often disguised as an update to the original app. In some instances, these malicious applications install a virtual private network (VPN), rerouting the user’s internet traffic through servers controlled by the attackers, thereby exposing sensitive data to potential misuse.
Compounding the issue, these apps may employ tactics to prevent users from uninstalling them through standard device settings, complicating the removal process.
The NCTAU has strongly advised Android users to:
- Only install applications from the Google Play Store or other trusted app stores.
- Avoid downloading APK files promoted through advertisements, suspicious websites, or unknown links.
- Refrain from granting Accessibility permissions to unfamiliar applications.
- Regularly review installed applications and remove any that are unrecognized.
- Keep Google Play Protect enabled and ensure the Android operating system is up to date.
Additionally, users are encouraged to routinely monitor their bank accounts and UPI transactions for any suspicious activity. For devices that may already be compromised, the advisory suggests restarting the phone in Safe Mode and uninstalling any suspicious or unknown applications. Users should also disable Accessibility access and revoke device administrator privileges granted to malicious apps.
If an application proves resistant to removal or reappears after a restart, users are advised to back up important data and consider performing a factory reset. The government has urged citizens to report any fraudulent applications or cybercrime incidents promptly through the national cybercrime helpline 1930 or the government’s cybercrime reporting portal.