Search

Cookies

We use cookies to improve your experience. By continuing, you accept our use of cookies.

Technology

MHA Warns Android Users: Fake "Adult" Apps Steal Money, Hijack Devices

· · 2 min read

India's Ministry of Home Affairs (MHA) has issued a critical warning to Android users about malicious apps disguised as adult content. These apps, spread via social media, can steal money and gain control of devices by exploiting accessibility permissions.

The Indian Ministry of Home Affairs (MHA) is alerting Android users to a dangerous new threat: malicious applications masquerading as adult content apps. These fake apps are primarily distributed through advertisements on popular social media platforms like Facebook and Instagram, posing a significant risk of financial fraud and device compromise.

How the Fake Apps Operate

Users are typically lured by advertisements that redirect them to websites featuring pornographic content. On these sites, they are prompted to download Android Package Kit (APK) files, bypassing the secure Google Play Store. Once installed, these applications request extensive permissions, including sensitive Accessibility access.

The MHA's National Cybercrime Threat Analytics Unit warns that granting Accessibility permissions can allow attackers to take full control of a device, enabling them to carry out financial transactions without the user's consent. Some of the identified app names include 'Night Play', 'Reloop', 'Kyss', 'Vimo', 'Rivo', 'Nexo', and 'Vixa', along with various similar variants.

"Once installed, such applications can seek powerful permissions and create security problems on a device. If you come across an unfamiliar app promoted through social media or a website, paying attention to its source and requested permissions is important." - Ministry of Home Affairs

Beyond stealing money, these malicious applications can also install Virtual Private Networks (VPNs) that route internet traffic through attacker-controlled servers. This allows cybercriminals to monitor user activity and potentially extract further personal data. Some apps are even designed to prevent users from uninstalling them through standard device settings, making removal extremely difficult.

MHA's Recommendations for Android Users

To protect against these sophisticated threats, the Ministry of Home Affairs has issued clear guidance:

  • Download from Trusted Sources: Always download applications exclusively from the Google Play Store or other verified, reputable platforms.
  • Avoid Untrusted APKs: Never install APK files obtained from social media advertisements, unfamiliar websites, or suspicious links.
  • Be Cautious with Permissions: Critically evaluate all requested permissions, especially Accessibility access, and never grant them to untrusted or unfamiliar applications.
  • Check and Uninstall: Regularly check your device for suspicious applications and ensure they are fully uninstalled if found.
  • Factory Reset as Last Resort: If an app refuses to delete or reappears after rebooting your device, back up essential files and perform a factory reset.

Staying vigilant and adhering to these security practices is crucial for Android users to safeguard their devices, personal data, and financial security from these evolving cyber threats.

Related