Govt Warns of Malicious Porn Apps That Can Hijack Phones and Drain Bank Accounts
The Ministry of Home Affairs has issued a fresh cyber-fraud warning after its Indian Cyber Crime Coordination Centre (I4C) detected a rise in malicious Android applications disguised as pornography apps. The National Cybercrime Threat Analytics Unit (NCTAU) said the apps are being promoted through advertisements on Facebook and Instagram and can potentially give criminals extensive control over victims’ phones.
The apps are marketed under names including “Night Play”, “Reloop”, “Kyss”, “Vimo”, “Rivo”, “Nexo” and “Vixa”, among other variants. Instead of being legitimate entertainment applications, they allegedly act as malware designed to compromise Android devices and facilitate financial fraud.
The scam begins with a social-media advertisement containing sexually explicit material. Clicking the advertisement can redirect a user to a website offering adult content, where the victim is encouraged to download an APK file from outside the Google Play Store. This sideloading step is a critical part of the attack because the malicious application is not necessarily subject to the normal safeguards associated with official app stores.
Once installed, the application can request Accessibility permissions and other sensitive permissions. According to the government warning, these capabilities can allow attackers to operate parts of the device remotely or perform actions without the user’s knowledge.
The danger goes well beyond simply stealing photographs or browsing information. Authorities warn that compromised devices can potentially be used to facilitate unauthorised financial transactions, putting banking applications, payment credentials and accounts at risk.
The malware may also download another package while pretending that an app update is required. This gives criminals an additional opportunity to install components capable of expanding their control over the device.
Another particularly serious feature identified by investigators is the possible installation of a VPN controlled by the attacker. Such a setup can route the victim’s internet traffic through infrastructure controlled by criminals, potentially exposing browsing activity and other sensitive information.
Some versions may also attempt to make themselves difficult to remove. The government advisory says users should check whether suspicious applications remain on the device and, if an application cannot be removed or returns after a restart, back up important information and consider performing a factory reset.
The incident also highlights a growing problem for India’s digital-payment ecosystem: criminals are increasingly using social engineering to persuade people to install malware rather than attempting to break directly into bank systems. A recent government crackdown separately found malicious websites and applications being used to steal financial information through Google’s Firebase infrastructure.
The scale of the wider problem is substantial. Reuters reported that Indians suffered approximately $2.4 billion in alleged cyber-fraud losses during 2025, according to government data, while digital-payment usage continues to expand rapidly.
Meta has already removed dozens of the flagged advertisements from Facebook and Instagram after India raised the issue. Reuters, however, found at least 39 such advertisements still active after the government’s warning, before Meta subsequently removed them.
The government is therefore warning users not to judge an application by the advertisement that promotes it. An app appearing inside a Facebook or Instagram advertisement does not make the app trustworthy. The safest approach is to avoid APK downloads from advertisements, websites or unknown links and install applications only through trusted official sources.
Users should also be extremely cautious when an unfamiliar application asks for Accessibility access. That permission can provide powerful control over an Android device and should not normally be granted to an unknown application merely to view online content.
Anyone who believes their bank account or device has been compromised should act immediately rather than waiting to see what happens. The government advises victims of cyber financial fraud to contact the 1930 cybercrime helpline and report the incident through the national cybercrime reporting system.
The larger lesson from the warning is straightforward: the scam is not really about pornography—it is about getting the victim to install malware. The adult-content bait is simply the psychological hook used to bypass caution, while the real objective can be access to the phone, personal information and ultimately the victim’s money.
