Key Highlights

  • I4C's National Cybercrime Threat Analytics Unit (NCTAU) has warned users about a rise in financial fraud via fake porn apps.
  • Apps flagged include 'Night Play', 'Reloop', 'Kyss', 'Vimo', 'Rivo', 'Nexo' and 'Vixa'.
  • Malicious apps are promoted via ads on Facebook and Instagram and installed as APKs outside Google Play Store.
  • The malware seeks Accessibility permissions and may install a rogue VPN to reroute user traffic.
  • Users are advised to download apps only from trusted stores and avoid granting Accessibility access to unknown apps.

India's cybercrime authorities have issued one of the most detailed and urgent public advisories of the year. The National Cybercrime Threat Analytics Unit (NCTAU) — operating under the Union Home Ministry's Indian Cyber Crime Coordination Centre (I4C) — has warned Android users about a growing pattern of financial fraud involving malicious applications disguised as pornography apps and aggressively promoted through advertisements on Facebook and Instagram.

The warning comes at a time when digital advertising, casual mobile app installation and permission-granting habits are creating an increasingly rich attack surface for fraudsters — and the specific apps identified show how targeted, structured and sophisticated these scams have become.

The Apps Flagged in the Advisory

In its advisory, the I4C identified several apps that users should immediately be wary of. The named apps include 'Night Play', 'Reloop', 'Kyss', 'Vimo', 'Rivo', 'Nexo' and 'Vixa', along with similar variants that may be circulating under different names.

That specificity is important. It gives users a clear list of names to check against their installed apps — and gives the media ecosystem a defined vocabulary to communicate the risk to a wider public audience.

How the Attack Works

According to the advisory, the malicious applications are primarily promoted through pornography-related advertisements or links on Facebook and Instagram. Users clicking on these advertisements are redirected to websites hosting pornographic content, where they are prompted to download an Android Package Kit (APK) from outside the Google Play Store.

The websites involved are largely associated with '.live' domains, the advisory said. That domain-level pattern is a useful red flag — one that users can add to their own personal vigilance checklist when engaging with app promotions online.

The Two-Step Malware Trap

The attack unfolds in stages. After the initial application is installed, users may be prompted to download a secondary package disguised as an app update. This process can exploit permissions obtained or abused by the first application, making the second installation even more damaging.

The malware then seeks Accessibility and other sensitive permissions from the user. Once these permissions are granted, the malicious application can obtain extensive control over the device — and continue operating quietly in the background, often without the user realising the extent of the compromise.

The Rogue VPN Trick

Adding another dangerous layer to the attack, the NCTAU has also warned that some variants may install a virtual private network (VPN). Once installed, this VPN allows attackers to route the user's internet traffic through servers under their control, exposing transmitted data to misuse and facilitating further malicious activity.

That's a serious escalation. Once traffic is rerouted through an attacker-controlled VPN, virtually every online action a user takes — including banking, messaging and personal browsing — can potentially be intercepted, monitored or manipulated.

Persistent, Hard-to-Remove Apps

Some of these applications may also prevent users from uninstalling them through normal device settings — a design pattern deliberately intended to keep the malware active on the victim's device for as long as possible.

That kind of persistence transforms a one-time bad decision (installing a malicious APK) into an ongoing security exposure that can extend for weeks or months.

The Full Attack Chain

Putting it all together, the suspected modus operandi begins with a social media advertisement, followed by redirection to a malicious website and APK installation. This can lead to VPN installation in some cases, requests for Accessibility permissions, device takeover and eventually unauthorised financial transactions.

That's a chain designed specifically to defraud users — and every step in that chain corresponds to a moment where users could, if aware, break the sequence and protect themselves.

The Government's Safety Advice

To protect themselves, users have been advised to download applications only from the Google Play Store or other trusted app stores. The NCTAU has specifically cautioned against downloading APK files through advertisements, websites or suspicious links, and has urged users not to grant Accessibility permissions to unfamiliar applications.

Additional recommendations include regularly reviewing applications installed on Android devices, removing anything unfamiliar, keeping Google Play Protect enabled, installing the latest Android security updates, and regularly checking bank accounts and UPI transactions for any signs of unauthorised activity.

What to Do If a Suspicious App Won't Uninstall

For users who find that a suspicious application cannot be uninstalled through normal device settings, the NCTAU has laid out a specific recovery pathway.

The advisory recommends restarting the device in Safe Mode and then navigating to the Apps section in Settings to remove the application. Users can also disable the app's Accessibility access and revoke administrator privileges through the device's security settings before attempting to uninstall it.

If the application still cannot be removed — or if it reappears after a restart — the advisory recommends backing up important data and carrying out a factory reset of the device. That's a significant but necessary step, and one that reflects just how deeply entrenched these malicious apps can become once installed.

Why It Matters

India has one of the largest Android user bases in the world. Millions of users install apps daily, often through routes outside the Google Play Store. Add to that the country's rapidly expanding digital financial infrastructure — UPI, mobile banking, digital wallets, insurance apps, investment platforms — and any malware that takes over a device's Accessibility permissions can have serious real-world financial consequences.

The specific choice of pornography-themed lures reflects a well-understood pattern in social engineering. Attackers rely on the fact that many users are unlikely to seek help, verify credentials or ask questions when engaging with adult content — making them softer targets for follow-through malware installation.

Public Awareness and Digital Literacy Impact

The value of the I4C advisory lies not just in the immediate warning, but in the digital literacy it builds. Every user who reads the advisory learns a concrete lesson: don't install APKs from ads, never grant Accessibility permissions to unknown apps, and always verify app sources.

That kind of institutional digital literacy — spread through public advisories, news coverage and social media — is one of the most important defences a country can build against evolving cyber threats.

Platform Accountability Angle

The advisory also implicitly raises questions about platform-level advertising verification. If malicious apps are being promoted through advertisements on Facebook and Instagram, platform review mechanisms have clearly been bypassed. Digital rights advocates and cybersecurity researchers are likely to push for tighter ad verification processes on major platforms — particularly for ads that route users toward APK downloads from suspicious domains.

For Meta-owned Facebook and Instagram, this is an important moment to review how such ads are slipping through review systems, and how enforcement can be tightened before more users fall victim.

Industry Impact

For India's cybersecurity industry, the advisory reinforces a growing category of threat — social-engineering-led Android malware campaigns targeting financial credentials and device control. For banks and payment platforms, it underscores the importance of user education alongside technical fraud detection. For device manufacturers, it strengthens the case for stricter default settings around APK sideloading and Accessibility permission grants.

The Bigger Picture

The I4C's advisory on 'Night Play', 'Kyss', 'Vixa' and similar apps is a stark reminder that in the age of instant downloads, one careless click can cost users far more than they realise. What starts as a click on an adult-content ad can end with rerouted internet traffic, stolen banking credentials and unauthorised financial transactions.

For every Android user in India, the message is clear. Download only from trusted sources. Never grant Accessibility permissions to apps you don't fully recognise. Never install APKs promoted through pop-up ads or social media links. And regularly review both your installed apps and your bank transaction history.

In a country moving rapidly toward a digital-first economy, cybersecurity awareness is no longer optional. It is a basic life skill. And the I4C's timely, specific and unambiguous advisory offers exactly the kind of public education Indians will benefit from taking seriously — because in the world of Android malware today, the difference between safety and compromise often comes down to a single tap. Make sure yours is an informed one.