CyberRakshakLabs Threat Intelligence & Cyber Awareness
A new warning from India's Indian Cyber Crime Coordination Centre (I4C) highlights a dangerous Android malware campaign in which fake adult/pornographic applications are promoted through Facebook and Instagram advertisements.
The danger isn't simply the misleading advertisement.
The real threat begins when the victim is redirected to an external website, downloads an APK outside the official app store, installs it and grants powerful permissions.
According to reporting on the I4C/NCTAU advisory, applications operating under names such as Night Play, Reloop, Kyss, Vimo, Rivo, Nexo and Vixa have been identified in this campaign.
The reported attack chain is:
Social-media advertisement
β
Fake adult-content website
β
Malicious APK download
β
APK installation
β
Accessibility / sensitive permissions
β
Device control
β
Potential financial fraud
π΄ 1. THE ATTACK STARTS WITH A SOCIAL-MEDIA AD
The campaign reportedly uses advertisements on:
The advertisements lure users with adult/pornographic content.
The victim clicks the advertisement and is redirected to a website outside the normal application ecosystem.
This is an important lesson:
Seeing an advertisement on a major social-media platform does not automatically make the destination trustworthy.
The advertisement can simply be the delivery mechanism for the attacker-controlled website.
2. THE VICTIM IS PUSHED TOWARD AN APK
Instead of directing the victim to Google Play, the website asks the user to download an APK.
This is a critical point in the attack.
APK β malware
APK is simply Android's application-package format.
Legitimate applications can also be distributed as APK files.
The security concern is:
Who provided the APK, and why are you being asked to install it?
When the chain becomes:
Advertisement β Unknown website β APK
the user has moved outside the normal trusted application-distribution path.
I4C advises users not to download APK files from advertisements, suspicious websites or unknown links.
3. IDENTIFIED APP NAMES
The reported advisory identifies applications including:
π΄ Night Play
π΄ Reloop
π΄ Kyss
π΄ Vimo
π΄ Rivo
π΄ Nexo
π΄ Vixa
There may be additional variants.
Therefore, users should not interpret this list as exhaustive.
The broader rule is much more important:
Do not install unknown APKs promoted through social-media advertisements.
4. THE DANGEROUS PERMISSION: ACCESSIBILITY
After installation, the malicious application may request powerful permissions.
One of the most concerning is:
Accessibility access
Accessibility is a legitimate Android feature designed to help people interact with their devices.
The problem is when an untrusted application obtains this capability.
According to the I4C warning, abuse of Accessibility permissions can allow malicious applications to control aspects of the device and potentially facilitate financial fraud.
Depending on the malware and permissions granted, such control can potentially be abused to:
Interact with the screen
Click buttons
Read information displayed on screen
Interact with applications
Facilitate OTP-related abuse
Perform unauthorised actions
This creates a major security problem.
Your banking application may be protected by authentication.
But if malware has extensive control over the device, the device itself becomes the attack surface.
5. SECONDARY APK / FAKE UPDATE
The threat does not necessarily stop after the first installation.
The advisory describes cases where a secondary package can be downloaded under the appearance of an application update.
The victim may think:
βThe app needs an update.β
But the βupdateβ can become another malicious component.
The chain can therefore become:
Initial APK
β
Permissions
β
Fake update
β
Additional malicious package
β
Expanded capability
This is why blindly approving installation/update prompts is dangerous.
6. VPN ABUSE
Some versions of the malicious applications may also install or configure a VPN.
A VPN itself is not malicious.
Legitimate VPN services are widely used.
The concern is when malware controls the VPN configuration.
According to the I4C warning, some versions may route Internet traffic through attacker-controlled infrastructure.
This can create another layer of risk because the device's network traffic may no longer follow the user's expected path.
7. WHY FINANCIAL FRAUD BECOMES POSSIBLE
Now combine the capabilities:
Malicious APK
Accessibility abuse
Device interaction
Sensitive information
=
Potential financial fraud
Attackers may attempt to abuse access to:
Banking applications
UPI applications
SMS/notifications
Authentication workflows
Personal information
The I4C warning specifically connects the campaign to unauthorised financial transactions.
8. THE COMPLETE ATTACK CHAIN
π― STAGE 1 β LURE
Instagram/Facebook advertisement
β
π STAGE 2 β REDIRECT
Fake adult-content website
β
π¦ STAGE 3 β DELIVERY
Malicious APK
β
π STAGE 4 β PERMISSION
Accessibility / sensitive permissions
β
π¦ STAGE 5 β CONTROL
Potential device control
β
π STAGE 6 β EXPANSION
Possible secondary APK/VPN
β
π° STAGE 7 β IMPACT
Potential unauthorised financial transactions
9. WHY THIS ATTACK IS SO EFFECTIVE
The attacker doesn't necessarily need to exploit an Android zero-day.
Instead, the attacker exploits:
Human behaviour.
The victim does the following:
Click
β
Download
β
Install
β
Allow
And the attacker gets the opportunity they need.
This is why social engineering remains one of the most effective attack vectors.
π TECHNICAL THREAT PROFILE
Category Details
Initial Access Social-media advertisements
Platforms Instagram / Facebook
Target Android users
Delivery External APK
Social Engineering Adult/dating lure
Privilege Abuse Accessibility
Additional Capability Secondary APK
Network Capability Potential VPN abuse
Persistence Risk Application may resist removal
Impact Potential financial fraud
The exact behaviour can vary between samples and versions, so these should be treated as campaign-level characteristics, not guaranteed behaviour of every APK carrying these names.
π‘οΈ 10. HOW TO PROTECT YOURSELF
Rule #1 β Don't install APKs from advertisements
If an Instagram/Facebook advertisement says:
βDownload our app.β
Stop.
Open the official Google Play Store independently and search for the application.
Don't follow the APK download link.
Rule #2 β Treat Accessibility permission as highly sensitive
Before enabling Accessibility for an unfamiliar application:
Ask:
Why does this application need to control my device?
If you cannot clearly answer that:
Don't enable it.
Rule #3 β Keep Google Play Protect enabled
Do not disable security protections simply because an unknown website tells you to.
Rule #4 β Keep Android updated
Update:
Android
Google Play system
Applications
Security software
Rule #5 β Review installed applications
Regularly check for:
Unknown applications
Recently installed apps
Apps you don't remember installing
Suspicious names
Applications with unnecessary permissions
π¨ 11. IF YOU ALREADY INSTALLED THE SUSPICIOUS APK
Act quickly.
STEP 1 β Disconnect
If you suspect active malicious activity, disconnect the phone from the Internet where practical.
STEP 2 β Enter Safe Mode
Restart the phone in Safe Mode.
STEP 3 β Remove the suspicious application
Check:
Settings β Apps
Find the suspicious application and attempt to uninstall it.
STEP 4 β Revoke Accessibility
Go to the Accessibility settings and disable the suspicious application's access.
STEP 5 β Check administrator privileges
Review Device Administrator settings and remove suspicious administrative access.
The I4C guidance specifically recommends Safe Mode and removal of Accessibility/administrator access where necessary.
STEP 6 β Check banking activity
Immediately review:
Bank accounts
UPI
Cards
Wallets
STEP 7 β Secure accounts from a clean device
Change critical passwords using a device you trust.
STEP 8 β Factory reset if necessary
If the malicious application cannot be reliably removed or continues returning, back up trusted data and consider a factory reset.
π° 12. IF MONEY HAS ALREADY BEEN STOLEN
Act immediately.
In India, report financial cyber fraud through:
1930 β National Cyber Crime Helpline
and the:
National Cyber Crime Reporting Portal
The official portal confirms that 1930 is available for immediate reporting of cyber financial fraud.
You can also report suspicious identifiers such as websites, phone numbers, email IDs, SMS headers and social-media URLs through the portal's Report Suspect facility.
π₯ CYBERRAKSHAKLABS THREAT ASSESSMENT
Attack Vector
Social Engineering
Delivery
Malicious Android APK
Primary Abuse
Accessibility permissions
Secondary Risk
Additional APK / VPN
Target
Android users
Impact
Potential device takeover and financial fraud
Severity
π΄ HIGH
The greatest risk is not the advertisement itself.
It is the trust decision made after the advertisement.
π§ THE BIG LESSON
Cybercriminals don't always need to:
Hack your phone.
Sometimes they simply convince you to:
Install the hack yourself.
That's why the most important security control is often:
PAUSE BEFORE YOU INSTALL.
π‘οΈ CYBERRAKSHAKLABS SECURITY FORMULA
AD β LINK β APK β PERMISSION
Whenever you see this chain:
π¨ STOP.
Verify the source.
Check the application store.
Review permissions.
Never grant Accessibility to an unknown app.
Monitor financial activity.
π FINAL MESSAGE
Your smartphone contains:
π³ Your money
π Your authentication
π± Your identity
π¬ Your conversations
πΈ Your personal information
Don't allow an unknown application to become the administrator of your digital life.
Think before you click.
Verify before you install.
Review before you allow.
Be Aware. Be Intelligent. Be Secure. Be Cyber Safe.
CyberRakshakLabs
Cyber Awareness | Threat Intelligence | Digital Safety
AD β LINK β APK β PERMISSION
Whenever you see this chain: STOP. Verify the source. Check the application store. Review permissions. Never grant Accessibility to an unknown app. Monitor financial activity.