The ads promoted malicious Android apps that could steal banking credentials and OTPs, take control of users’ devices and transfer money without their knowledge.
Meta* removed dozens of advertisements from Facebook* and Instagram* promoting malicious Android apps masquerading as pornography apps after Indian authorities warned of a rise in financial fraud involving such programs.
According to Reuters, at least 39 such ads remained active after the advisory was issued by India’s Ministry of Home Affairs (MHA). The ministry flagged the advertisements to Meta, after which the company removed all the identified ads.
The scam apps were promoted under names including “Night Play”, “Reloop”, “Kyss”, “Vimo”, “Rivo”, “Nexo” and “Vixa”. The advertisements used sexually explicit videos and images to attract users and redirect them to websites offering pornographic content, where users were prompted to download APK files outside official app stores such as the Google Play Store.
Once installed, the apps requested accessibility and other sensitive permissions on Android devices. This allowed attackers to capture one-time passwords (OTPs) and bank PINs, take control of smartphones and carry out unauthorised financial transactions without the owners’ knowledge.
Indian authorities advised users to download apps only from official and trusted app stores, avoid installing APK files received through advertisements and suspicious links, and monitor their bank accounts and UPI transactions for suspicious activity.
Users who suspect that their devices have been infected were advised to restart them in Safe Mode and uninstall the malicious app. In more difficult cases, users may need to perform a factory reset.
The warning comes as India grapples with mounting cyber fraud. According to government data, cyber-fraud losses in the country reached nearly $2.4 Bn in 2025.
*banned and designated as extremist in Russia
Source: Inc42