India
oi-Gaurav Sharma
A new Android scam is causing a lot of concern among cybercrime authorities as fraudsters are targeting smartphone users with fake porn themed apps and trying to gain access to their sensitive data, device and even their bank accounts.
Apps such as Night Play, Reloop, Kyss, Vimo, Rivo, Nexo and Vixa are reported to be advertised on Facebook and Instagram. However, clicking on any of the ads redirects the user to a suspicious website which then asks them to download APK files from an external source instead of the official app store.
Cybercrime authorities report an Android scam using fake apps like Night Play and Vixa, advertised on Facebook and Instagram, that trick users into downloading malicious APK files, potentially stealing sensitive data and bank account information via granted permissions.

How The Scam Works
The fraud typically starts with social media advertisement. Once the ad is clicked, the user is redirected to a website with adult themed content. The webpage then asks the user to download APK to view the content.
Once downloaded, the malicious application asks for permissions such as accessibility. If the user approves the requested permissions without checking them, the application will have full control of the phone.
One of the worst permissions that users can allow a suspicious application is accessibility permission. With this permission, attackers can takeover the phone in the background and do whatever they want with the device.
It is also worth noting that sometimes after installation these fake apps can download another malicious package masquerading as an update. Since the user has already allowed some permissions, the new application will get complete access to the device very easily.
Fake Apps Can Also Reroute Internet Traffic
Even though having a suspicious application with full access to the device is dangerous in itself, it gets even worse.
Some versions of these malicious apps are capable of installing their own configuration on the phone and routing all internet traffic through their own servers. This basically means that the attackers will have access to all information that the phone is sending and receiving on the internet.
On top of that, some versions of these apps make themselves untouchable, meaning that the user won’t be able to delete them.
Once attackers are able to fully control the device, they can start making unauthorized transactions or accessing the financial accounts directly and steal a lot of money.
How To Protect Your Android Phone
There are some essential steps that every Android user should take in order to protect their devices:
- Only download apps from Google Play Store or reputable app stores.
- Do not install APK files sent by social media ads, unknown websites or suspicious links.
- Never allow suspicious applications with Accessibility access.
- Always double check suspicious applications and uninstall them.
- Keep Google Play Protect turned on.
- Update the operating system and security applications regularly.
- Keep an eye on all financial activities especially UPI transactions.
What To Do If A Suspicious App Is Already Installed
If the user suspects that they have a malicious application on their phone, they should first try to reboot the device in Safe Mode. On most Android devices, this can be done by holding the Power button and then holding the Power Off option until the Safe Mode notification appears.
Once the device is in Safe Mode, users should navigate to Settings > Apps and take a look at recently installed applications. In most cases, the suspicious application will appear there. The application should be uninstalled along with any other suspicious apps.
If the application is preventing the user from being uninstalled, check if it has replaced the default launcher on the device. If that is the case, navigate to Settings > Apps > Default Apps > Home App and change it to the default launcher provided by the phone.
Users should also check the Accessibility settings and revoke permission for suspicious applications:
Settings > Accessibility > Installed Services/Downloaded Apps
Find the suspicious application and disable its Accessibility access.
Another thing that users should do is check device administrator:
Settings > Security or Security & Privacy > Device Admin Apps
If the suspicious application is listed there, disable it and then try to uninstall the application again. After these steps are done, make sure to check the Apps tab and see if the malicious application is gone.
If the malware keeps coming back, users should back up their data and factory reset the device.
Anyone who has fallen victim to such scam should immediately report it by calling 1930 or submitting a report on the cybercrime portal at cybercrime.gov.in.
Reporting such incidents can help authorities track down the fraudsters and prevent other users from becoming victims.
