I4C warns against malicious Android apps from social media ads

Cybersecurity Advisory on Malicious Android Applications

The Indian Cyber Crime Coordination Centre (I4C), operating under the Ministry of Home Affairs, has recently issued a critical advisory regarding the proliferation of malicious Android applications masquerading as adult-content apps. These deceptive applications are being promoted through social media advertisements and are typically distributed outside of official app stores, posing significant risks to users.

On August 26, the National Cybercrime Threat Analytics Unit (NCTAU) within the I4C highlighted the dangers associated with these apps. Users are often redirected from advertisements to dubious websites that prompt them to download Android Package Kit (APK) files from unverified sources, bypassing the Google Play Store and other trusted platforms. The I4C warns that such downloads can severely compromise mobile device security, as these malicious applications may request sensitive permissions, including accessibility permissions, which grant them extensive control over the device.

The advisory elaborates, stating, “Once installed, these malicious apps may request sensitive permissions, including accessibility permissions, and gain control of the device.” Furthermore, these applications can install additional software without the user’s consent, modify device settings, and facilitate unauthorized financial transactions, potentially leading to significant monetary losses from bank accounts or digital payment platforms.

In light of these threats, the I4C strongly advises citizens to exercise caution by downloading applications exclusively from trusted sources, such as the Google Play Store. Users are urged to refrain from installing APK files obtained from advertisements, unknown websites, or suspicious links. The advisory emphasizes the importance of not granting accessibility permissions to untrusted applications, as these permissions can provide harmful apps with considerable control over devices.

Additional recommendations from the advisory include:

  • Regularly reviewing installed applications and promptly removing any unfamiliar apps.
  • Keeping Google Play Protect enabled for enhanced security.
  • Closely monitoring bank accounts and Unified Payments Interface (UPI) transactions to quickly identify any unauthorized activities.

This warning comes at a time when concerns are escalating regarding cybercriminals exploiting digital platforms and mobile applications to access sensitive data, devices, and financial information. The I4C encourages victims to report any fraudulent apps or incidents of cyber fraud without delay via the national cybercrime helpline at 1930 or through the government’s cybercrime reporting portal at cybercrime.gov.in.

As a reminder, citizens are urged to remain vigilant and adhere to the official cyber safety guidance provided by the Ministry of Home Affairs and the I4C. This advisory serves as a crucial reminder of the inherent dangers associated with downloading applications from unofficial sources, particularly those advertised as providing access to adult or restricted content. Cybersecurity officials consistently advocate for verifying the authenticity and source of apps before installation and avoiding the granting of unnecessary permissions to unfamiliar applications.

AppWizard
I4C warns against malicious Android apps from social media ads