Cyber fraud is no longer limited to phone calls, messages or fraudulent links. The Indian Cyber Crime Coordination Centre (I4C) has warned Android users about malicious applications being promoted on social media platforms such as Facebook and Instagram by disguising them as adult-content apps.
Users who click on these advertisements are redirected to external websites and persuaded to download APK files from outside the Google Play Store. Once installed, the apps can seek sensitive permissions and attempt to gain access to the device and personal information.
Which Fake Apps Has I4C Flagged?
The I4C, which operates under the Ministry of Home Affairs, has flagged suspicious applications operating under names such as “Night Play”, “Reloop”, “Kyss”, “Vimo”, “Rivo”, “Nexo” and “Vixa”, among others.
These apps are reportedly promoted through social media advertisements offering users access to adult content. Clicking on the advertisements takes users to websites where they are instructed to download an application to view the content.
How Does the APK Fraud Begin?
The fraud begins when users are persuaded to install an APK file from an external website instead of downloading an application through the Google Play Store. After installation, the malicious application may request access to sensitive functions such as notifications, messages or other device features. The risk becomes particularly serious when users grant an unfamiliar application access to Android’s Accessibility Services.
Why Is Accessibility Permission So Dangerous?
Accessibility Services is designed primarily to assist people who have difficulty operating touchscreen devices. However, cybercriminals can misuse this functionality. According to cybersecurity experts, a malicious application with Accessibility access may be able to read information displayed on the screen, interact with other applications and potentially approve certain permission requests on behalf of the user.
This creates a direct threat to banking and digital payment information. Smartphones often contain banking applications, UPI accounts, one-time passwords (OTPs), private messages and other sensitive information. If a malicious application gains extensive control over such a device, attackers may potentially exploit that access to facilitate financial fraud.
Some variants of the malware may also download another package by disguising it as an application update. In certain cases, the malicious software may install a VPN and attempt to route internet traffic through servers controlled by attackers. Such activity can further compromise the security and privacy of an affected device.
What Warning Signs Should Android Users Watch For?
Cybersecurity experts have advised users to pay close attention to unusual activity after installing an unfamiliar application. A phone appearing to tap or interact on its own, an unfamiliar VPN icon appearing on the device, or an unknown application showing up under Accessibility settings could be warning signs of a possible compromise.
Experts have also warned that users may be more likely to trust advertisements appearing on familiar social media platforms. However, being redirected from a legitimate platform to an external website and then being asked to install an APK significantly increases the security risk. Cybercriminals are increasingly targeting users before a financial transaction takes place, using deceptive advertisements and applications to gain access to devices and sensitive information.
The I4C has advised Android users to download applications only from the Google Play Store or other trusted app stores. Users should avoid APK files received through advertisements, websites or suspicious links. They should also keep Google Play Protect enabled, regularly update their Android devices and periodically review the applications installed on their phones.
Users should immediately review and remove applications they do not recognise and avoid granting Accessibility access to unfamiliar applications. Particular caution is required when an application asks users to enable unusual permissions or follow instructions to bypass normal installation procedures.
Users should also regularly monitor their bank accounts and UPI transactions for unauthorised activity. If someone suspects that their device has been infected with malware or notices an unauthorised financial transaction, they should immediately contact their bank and report the incident through India’s cybercrime helpline at 1930.
The threat also extends beyond personal smartphones. Employees may use the same devices for work email, banking and personal activities, potentially exposing organisational information to malicious applications. Companies should therefore consider restricting app installation from external sources on devices that access sensitive corporate data and maintain a response plan for suspected compromises.
The latest warning highlights a simple but critical cybersecurity rule: users should never install an unfamiliar application merely because an online advertisement promises free or exclusive content. Downloading apps from trusted sources and carefully reviewing requested permissions can significantly reduce the risk of handing control of a smartphone to cybercriminals.
About the author — Ayesha Aayat writes on cybercrime, digital safety, and emerging online threats. Her work focuses on public awareness, legal clarity, and technology-driven risks.