MHA warns of malicious ‘pornography’ apps that can hijack Android phones, enable financial fraud

The malicious apps, promoted through Facebook and Instagram ads, can abuse Accessibility permissions to take control of devices and potentially enable unauthorised financial transactions.
For representational purposes (File Photo | AFP)
For representational purposes (File Photo | AFP)
Updated on
2 min read

NEW DELHI: The Ministry of Home Affairs (MHA) has issued an advisory warning of a rise in financial frauds carried out through malicious Android applications disguised as pornography apps and promoted through advertisements on Facebook and Instagram.

The National Cybercrime Threat Analytics Unit (NCTAU), under the Indian Cyber Crime Coordination Centre (I4C), issued advisory TAU/ADV/018 on August 26, warning users about fake apps named "Night Play", "Reloop", "Kyss", "Vimo", "Rivo", "Nexo" and "Vixa".

According to the advisory, the apps are advertised on Meta's platforms and redirect users to phishing websites, mainly on ".live" domains. Users are then prompted to download and install an APK file outside the Google Play Store.

The malware follows a six-stage process. After installation, it downloads a second package disguised as an app update and seeks Accessibility permissions. These permissions can allow the malware to read the screen, click buttons, enter OTPs and PINs and initiate fund transfers.

Some variants also install a VPN to route the victim's internet traffic through attacker-controlled servers. The apps may also resist normal uninstallation.

The MHA advised users to download applications only from the Google Play Store or other trusted app stores and avoid APK files shared through advertisements, websites or unfamiliar links.

Users have also been advised to reject Accessibility permission requests from unfamiliar apps, regularly review installed applications and remove suspicious ones. The advisory recommended keeping Google Play Protect enabled, updating device software and monitoring bank and UPI transactions for unauthorised activity.

If a suspicious application cannot be removed, the advisory recommends restarting the device in Safe Mode. Users can do this by pressing and holding the Power button, then long-pressing the "Power Off" option until the Safe Mode option appears and confirming the restart.

Once Safe Mode is activated, users should go to Settings, open Apps and uninstall the suspicious application and any other unfamiliar or related apps.

The phone can then be restarted normally to exit Safe Mode. The advisory recommends a factory reset as a last resort if the malicious application resists removal or reinstalls itself.

X
The New Indian Express
www.newindianexpress.com