From Facebook Ads to Device Takeover: Inside the Android Malware Campaign Flagged by I4C

‘KYSS’ Android Banking RAT Poses as Adult App, Hijacks Phones and Targets Financial Accounts

The420 Web Desk
7 Min Read

A new wave of malicious Android applications disguised as pornography and entertainment apps is drawing attention from Indian cybercrime authorities and independent malware researchers after investigators found that the apps can abuse accessibility permissions, take control of devices and potentially enable unauthorised financial transactions. An advisory issued by the Indian Cyber Crime Coordination Centre’s National Cybercrime Threat Analytics Unit on August 26 warned of apps circulating under names such as Night Play, Reloop, Kyss, Vimo, Rivo, Nexo and Vixa, many of them promoted through Facebook and Instagram advertisements.

One of the most detailed technical examinations of this malware family came from Rudra Ponkshe, a student malware researcher at the National Forensic Sciences University, who analysed a sample branded KYSS and documented how a seemingly simple adult-themed app could operate as a sophisticated Android banking remote-access trojan. Ponkshe’s July analysis found capabilities including overlay attacks against financial and cryptocurrency apps, silent exfiltration of contacts and gallery data, accessibility-based automation and command-and-control infrastructure that could allow remote operators to issue instructions to infected devices.

A Lipstick Icon That Opens the Door to the Phone

Ponkshe’s investigation began with an APK carrying a lipstick-kiss icon and the name KYSS.

On launch, instead of behaving like a conventional app, it pushed the user toward Android settings and requested accessibility access. Once those permissions were granted, the malware’s capabilities expanded dramatically.

Using tools including MobSF, JADX, Frida and a rooted Android test environment, Ponkshe found that the application was heavily obfuscated and designed to frustrate routine static analysis. The app’s manifest appeared to use non-standard encoding, while filenames were randomly generated. Dynamic analysis later showed the application communicating with command-and-control infrastructure and sending device information back to its operators.

The malware collected details including device model, available memory, charging status and whether accessibility permissions or battery-optimisation exemptions had been granted. Ponkshe also observed communications suggesting the operators were being notified when another device had been successfully infected.

The technical sophistication matters because Android accessibility services are designed to assist users with disabilities. Once abused by malware, however, they can provide extensive visibility into what appears on the screen and allow automated interaction with applications.

That can turn an apparently harmless download into a tool capable of navigating interfaces, stealing data and assisting fraudulent activity.

I4C Warns of a Wider Porn-App Fraud Campaign

The Indian Cyber Crime Coordination Centre’s advisory describes a broader distribution model that closely resembles the techniques uncovered in the KYSS analysis.

According to the advisory, victims encounter attractive advertisements on Facebook and Instagram and are redirected to websites serving pornography-related content. They are then encouraged to install APK files from outside the Google Play Store.

The first app may subsequently download another package under the guise of an update. Once installed, the malware asks for sensitive permissions, particularly accessibility access, allowing it to continue running in the background and gain greater control over the device.

Some variants may also install a VPN and route the victim’s internet traffic through infrastructure controlled by attackers. The advisory warns that this traffic could potentially be exploited for criminal activity and that certain applications may make themselves difficult to uninstall.

The final objective can be financial.

Because the malware can control the compromised device, authorities warn that it may be able to initiate or facilitate unauthorised banking and UPI transactions.

The I4C advisory recommends installing applications only from trusted app stores, avoiding APKs promoted through ads or suspicious websites, refusing accessibility permissions to unknown applications and routinely reviewing banking and UPI transactions.

Users who suspect compromise are also advised to remove accessibility and administrator permissions from the malicious app before uninstalling it, and to use Android Safe Mode if normal removal is blocked.

A Banking Trojan Built for More Than One Country

Ponkshe’s research suggests that KYSS was not built for a single victim group or geography.

During analysis, he found language-detection logic that altered the app’s interface depending on the device locale, a sign that the malware was intended for use across multiple regions. He also identified overlay capabilities targeting 19 applications across Japan and Latin America, along with cryptocurrency apps.

The malware also used encrypted communications with its backend infrastructure. Ponkshe found that it relied on a static AES key and that its command-and-control traffic included websocket connections, allowing infected devices to remain in communication with operators.

That combination — social-media advertising, adult-content lures, accessibility abuse, remote control and financial targeting — illustrates how mobile malware campaigns increasingly blur the distinction between fraud and traditional hacking.

Attackers do not necessarily need to break into a bank.

They can instead compromise the device from which the customer already has legitimate access.

Once the victim grants powerful permissions, the phone itself can become the attack surface.

The I4C advisory asks victims of suspicious applications or financial fraud to report incidents immediately through the 1930 cybercrime helpline or the National Cyber Crime Reporting Portal.

For users, the warning is deceptively simple: the most dangerous part of the scam may not be the adult-content website or the advertisement that led there.

It may be the moment a phone asks for permission — and the user taps “Allow.”

Stay Connected