The National Cybercrime Threat Analytics Unit has warned of a rise in financial frauds involving malicious pornography apps circulated through advertisements on social media, which take control of the device and potentially facilitate unauthorised financial transactions.
The malicious Android applications masquerading as pornography apps, operating under names including “Night Play,” “Reloop,” “Kyss,” “Vimo,” “Rivo,” “Nexo” and “Vixa,” are distributed through advertisements or links on Facebook and Instagram that redirect users to websites offering pornographic content, according to the unit, which works under the Union Home Ministry’s anti-cybercrime agency Integrated Cybercrime Coordination Centre (I4C).
Advertisements redirect to phishing websites serving pornographic content. Website domains mainly end in “.live”. Users are then persuaded to download and install the APK from sources outside the Google Play Store.
“After installation, the app requests permissions that allow it to install additional applications and, by abusing accessibility permission, take control of the users’ device, which may result in financial fraud. Some apps also install a VPN, which may be used to route internet traffic pertaining to malicious/criminal activity. The app may prevent users from uninstalling it through the device settings,” the advisory said.
In some cases, the malware may also prevent users from uninstalling the application through normal device settings, making it harder for victims to regain control of their phones.
Authorities have advised Android users to install applications only from Google Play or other trusted app stores and to avoid downloading APK files from advertisements, websites or suspicious links.
Users have also been advised not to grant Accessibility permissions to unknown applications and to regularly review installed applications, removing those they do not recognise.
The unit recommended keeping Google Play Protect “enabled” and Android devices updated. Users should also regularly check their bank accounts and UPI transactions for unauthorised activity.







