New Delhi: They come disguised as pornography apps, pushed through seemingly innocuous Facebook and Instagram ads. But behind names such as Night Play, Reloop, Kyss, Vimo, Rivo, Nexo and Vixa lies an emerging financial fraud ecosystem increasingly being used to target unsuspecting users and siphon off their money, sources in the security establishment said.
The National Cybercrime Threat Analytics Unit (NCTAU) has observed a rise in financial fraud perpetrated through malicious Android applications and has alerted agencies to keep a close watch on them.Explaining how the fraud works, a senior official said that these applications are primarily distributed through advertisements on Facebook and Instagram. Clicking on these ads redirects users to websites serving pornographic content, where they are prompted to download an Android Package Kit.
“After installation, the app requests permissions that allow it to install additional applications and by abusing accessibility permissions, take control of the users’ device, which results in financial fraud,” the officer said.
“Some apps also install a VPN, which may be used to route internet traffic pertaining to criminal activity. The app may prevent users from uninstalling it through the device settings,” the officer said.
Once all these steps are completed, the victim’s bank account is accessed and money stolen. These apps use accessibility permissions to control the victim’s device, which means the perpetrator has access to the phone screen, passwords, one-time passwords (OTPs), and can initiate transactions, the officer explained.
ThePrint has reached out to a Meta representative for comment. This report will be updated if and when a response is received.
The Indian Cyber Crime Coordination Centre has issued an advisory warning people about these apps.
According to the advisory, some of these applications may also install a virtual private network (VPN) on the device, routing internet traffic through servers controlled by the attackers.
“This compromises the user’s transmitted data, which may subsequently be exploited for malicious or criminal activities. Since the malware has the ability to take over the compromised device, installing such apps may lead to financial fraud,” it said.
The advisory cautioned users to install applications only from the Google Play Store or other trusted app stores and avoid downloading APK files through advertisements, websites or suspicious links. It also advised against granting accessibility permissions to unknown applications.
Users have also been asked to periodically review applications installed on their phones, keep Google Play Protect enabled, ensure their Android devices are updated, and regularly check bank accounts and UPI transactions for any suspicious activity.
(Edited by Sugita Katyal)
