India warns of social media scams pushing malicious Android apps for financial theft

Indian authorities caution users against social media adverts promoting adult content apps that conceal malware designed to hijack devices and steal finances, amid rising fraud reports.

India’s cybercrime authorities have warned that a growing number of Android frauds are being pushed through social media adverts that promise adult or entertainment content but instead steer users towards malicious apps. The Indian Cyber Crime Coordination Centre says the scam typically begins with an advert on Instagram or Facebook and can end with a compromised phone, stolen data and unauthorised financial transactions.

According to the advisory, the National Cybercrime Threat Analytics Unit has identified a cluster of apps circulating under names including Night Play, Reloop, Kyss, Vimo, Rivo, Nexo and Vixa. Users are taken from the advert to a website, often on a “.live” domain, where they are urged to download an APK file outside the Google Play Store. Once installed, the app may seek accessibility and other sensitive permissions that can let it install further software, run in the background and, in some cases, make it harder to remove.

The government’s warning, reported by several Indian news outlets, reflects a broader pattern in mobile fraud: attackers increasingly rely on social engineering rather than sophisticated code. Vikram Raichura, founder and managing director of helo.ai by Vivaconnect, said one of the most dangerous tactics is simply persuading users to approve permissions without understanding what they allow. Nidhi Srivastava, a cybersecurity expert and founder of DigiArmorX, said the combination of adult-themed lures and powerful device permissions can give criminals significant control once an APK is installed.

Experts recommend downloading apps only from trusted app stores, avoiding APKs sent through adverts or unfamiliar links, and treating requests for accessibility, screen-reading, SMS or device-admin access as red flags. Google Play Protect should remain switched on, unknown app installs should be blocked in browser settings, and users should review installed apps regularly. If a suspicious app is already present, specialists advise disconnecting the phone from the internet, revoking permissions, removing the app in safe mode if necessary, and reporting any unauthorised transactions immediately through the cybercrime helpline or portal.

Disclaimer: This article is intended to inform and educate, not to recommend or endorse any financial product, investment or strategy. Please consider your own financial circumstances and seek professional advice where appropriate before making financial decisions.