The National Cybercrime Threat Analytics Unit (NCTAU) has reported a rise in financial fraud linked to deceptive Android applications that pose as pornography apps. These apps are advertised on social media platforms like Facebook and Instagram under names such as ‘Night Play’, ‘Reloop’, ‘Kyss’, ‘Vimo’, ‘Rivo’, ‘Nexo’, and ‘Vixa’. Users who click on these ads are redirected to websites promising adult content, where they are encouraged to download APK files. Once installed, these apps often request sensitive permissions, particularly Accessibility access, which can allow malware to take control of the device and facilitate financial fraud. Some malicious apps may also install a VPN, rerouting internet traffic through servers controlled by attackers and exposing sensitive data. The malware is primarily promoted through ads linked to pornographic content, redirecting users to phishing websites that prompt APK downloads from non-Google Play sources, often using the “.live” domain extension. After installation, the initial app may download a second malicious package disguised as an update, exploiting the permissions granted to the original app.