Fake dating apps are being used to target Android users: How the new cyber scam works

In a concerning development, India’s cybercrime authorities have issued a warning regarding the misuse of dating and adult-themed advertisements on popular social media platforms like Instagram and Facebook. These ads, which may initially appear to be harmless promotions, are being exploited by criminals to distribute malicious Android applications that can compromise users’ devices.

How does the scam begin?

The operation begins innocuously enough on social media, where users encounter advertisements promising access to adult services or dating platforms. However, instead of directing users to reputable app marketplaces such as Google Play, these ads redirect them to external websites. Here, users are often prompted to download an APK file and install it manually, bypassing the security measures typically associated with trusted app stores. This redirection should serve as a significant warning signal.

Which apps are linked to the campaign?

The Indian Cybercrime Coordination Centre (I4C), through its Threat Analytics Unit, has identified several applications associated with this malicious campaign. The list includes Night Play, Reloop, Kyss, Vimo, Rivo, Nexo, and Vixa. Users are cautioned not to rely solely on an app’s name to determine its safety. A more prudent approach is to avoid installing unfamiliar applications promoted through unsolicited social media advertisements, especially when these require downloading an APK from an external source.

Why do the apps ask for phone permissions?

Once installed, these malicious applications may seek access to various sensitive areas of the user’s phone. The I4C has highlighted that these apps could request permissions for:

  • SMS messages
  • Contacts
  • Photos and other files
  • Device storage
  • Accessibility Services

Such permissions can provide fraudsters with access to valuable information. Notably, Accessibility Services can enable an application to interact with the phone’s interface, potentially allowing attackers to observe screen information or perform actions on behalf of the user, which could lead to the exposure of sensitive data such as one-time passwords (OTPs).

How can this lead to financial fraud?

A compromised device can serve as a gateway for criminals to access information useful for committing fraud. For instance, if malware can intercept incoming messages, it may reveal OTPs or other verification details. When combined with other credentials obtained by a scammer, this information could facilitate unauthorized transactions. Furthermore, the malware may seek broader control over the device, amplifying the potential damage beyond the initial app installation.

Additionally, some of these applications can deploy hidden VPNs, redirecting a victim’s internet traffic through infrastructure controlled by the attacker, thus creating further privacy and security concerns.

What makes an APK download risky?

An APK, the file format used to install Android applications, is not inherently harmful. The risk arises from the source of the file. When an unfamiliar website prompts a user to manually install an APK after clicking on a social media advertisement, it circumvents the security checks that established app stores provide. Therefore, any unsolicited request to download an APK should be treated with caution, distinguishing it from the safer process of installing known applications through Google Play.

What should Android users do?

The I4C has provided several recommendations for users to enhance their security:

  • Use trusted app stores: Avoid manually installing apps from unfamiliar links.
  • Keep Google Play Protect active: This security feature can help identify potentially harmful applications.
  • Review permissions: Be discerning about the permissions requested by applications, particularly those involving Accessibility Services, SMS, and device administration.
  • Be cautious with social media ads: A well-designed advertisement does not guarantee the legitimacy of the application or website behind it.

What if the suspicious app has already been installed?

For users who suspect their device has been compromised, the first step is to restart the phone in Safe Mode and attempt to uninstall the suspicious application. If removal proves difficult, the I4C advises disabling the app’s Accessibility and Device Administrator permissions before trying to uninstall it. Should these measures fail, a factory reset of the device may be necessary. Users who believe they have fallen victim to fraud are encouraged to report the incident promptly by calling 1930 or using the National Cyber Crime Reporting Portal.

AppWizard
Fake dating apps are being used to target Android users: How the new cyber scam works