Cybercriminals are increasingly using malicious Android applications disguised as pornography apps to take control of users' devices and conduct unauthorized financial transactions. The Indian Cyber Crime Coordination Centre (I4C) has issued a warning about this trend. These apps are often promoted on social media and require users to download APK files from outside the Google Play Store.
The National Cybercrime Threat Analytics Unit (NCTAU) has reported a rise in financial fraud linked to these applications, which include names like “Night Play,” “Reloop,” and “Kyss.” Once installed, these apps request sensitive permissions, such as Accessibility access, allowing malware to read screen information, click buttons, enter OTPs or PINs, confirm transactions, and initiate fund transfers, leading to unauthorized access to bank accounts.
Additionally, the malware may install secondary applications or a VPN to reroute internet traffic through attacker-controlled servers, exposing sensitive data. These apps may also prevent uninstallation through standard device settings.
The NCTAU advises users to only install apps from trusted sources, avoid unknown APK files, refrain from granting Accessibility permissions to unfamiliar apps, regularly review installed applications, and keep their devices updated. Users should monitor bank accounts for suspicious activity and, if compromised, restart in Safe Mode to uninstall malicious apps. If removal is difficult, backing up data and performing a factory reset is recommended. Citizens are encouraged to report fraudulent applications or cybercrime incidents through the national cybercrime helpline 1930 or the government’s reporting portal.