CYBERRAKSHAK LABS Β· RESEARCH #017

🚨 From Instagram/Facebook Ad to Financial Fraud: How Fake Android Apps Can Hijack Your Phone

CyberRakshakLabs threat intelligence analysis of a malicious Android APK campaign promoted through Instagram and Facebook ads, including Accessibility abuse, secondary APKs, VPN abuse, financial-fraud risk and defensive actions.

By Vivek Kumar Β· Published 31 August 2026
RESEARCH#017
CATEGORYPhishing & Social Engineering
CRL ASSESSMENTHIGH
RESEARCH LEVELThreat Analysis
PUBLISHED2026-08-31
How CyberRakshakLabs researches threats β†’

CyberRakshakLabs Threat Intelligence & Cyber Awareness

A new warning from India's Indian Cyber Crime Coordination Centre (I4C) highlights a dangerous Android malware campaign in which fake adult/pornographic applications are promoted through Facebook and Instagram advertisements.

The danger isn't simply the misleading advertisement.

The real threat begins when the victim is redirected to an external website, downloads an APK outside the official app store, installs it and grants powerful permissions.

According to reporting on the I4C/NCTAU advisory, applications operating under names such as Night Play, Reloop, Kyss, Vimo, Rivo, Nexo and Vixa have been identified in this campaign.

The reported attack chain is:

Social-media advertisement

↓

Fake adult-content website

↓

Malicious APK download

↓

APK installation

↓

Accessibility / sensitive permissions

↓

Device control

↓

Potential financial fraud

πŸ”΄ 1. THE ATTACK STARTS WITH A SOCIAL-MEDIA AD

The campaign reportedly uses advertisements on:

Instagram

Facebook

The advertisements lure users with adult/pornographic content.

The victim clicks the advertisement and is redirected to a website outside the normal application ecosystem.

This is an important lesson:

Seeing an advertisement on a major social-media platform does not automatically make the destination trustworthy.

The advertisement can simply be the delivery mechanism for the attacker-controlled website.

2. THE VICTIM IS PUSHED TOWARD AN APK

Instead of directing the victim to Google Play, the website asks the user to download an APK.

This is a critical point in the attack.

APK β‰  malware

APK is simply Android's application-package format.

Legitimate applications can also be distributed as APK files.

The security concern is:

Who provided the APK, and why are you being asked to install it?

When the chain becomes:

Advertisement β†’ Unknown website β†’ APK

the user has moved outside the normal trusted application-distribution path.

I4C advises users not to download APK files from advertisements, suspicious websites or unknown links.

3. IDENTIFIED APP NAMES

The reported advisory identifies applications including:

πŸ”΄ Night Play

πŸ”΄ Reloop

πŸ”΄ Kyss

πŸ”΄ Vimo

πŸ”΄ Rivo

πŸ”΄ Nexo

πŸ”΄ Vixa

There may be additional variants.

Therefore, users should not interpret this list as exhaustive.

The broader rule is much more important:

Do not install unknown APKs promoted through social-media advertisements.

4. THE DANGEROUS PERMISSION: ACCESSIBILITY

After installation, the malicious application may request powerful permissions.

One of the most concerning is:

Accessibility access

Accessibility is a legitimate Android feature designed to help people interact with their devices.

The problem is when an untrusted application obtains this capability.

According to the I4C warning, abuse of Accessibility permissions can allow malicious applications to control aspects of the device and potentially facilitate financial fraud.

Depending on the malware and permissions granted, such control can potentially be abused to:

Interact with the screen

Click buttons

Read information displayed on screen

Interact with applications

Facilitate OTP-related abuse

Perform unauthorised actions

This creates a major security problem.

Your banking application may be protected by authentication.

But if malware has extensive control over the device, the device itself becomes the attack surface.

5. SECONDARY APK / FAKE UPDATE

The threat does not necessarily stop after the first installation.

The advisory describes cases where a secondary package can be downloaded under the appearance of an application update.

The victim may think:

β€œThe app needs an update.”

But the β€œupdate” can become another malicious component.

The chain can therefore become:

Initial APK

↓

Permissions

↓

Fake update

↓

Additional malicious package

↓

Expanded capability

This is why blindly approving installation/update prompts is dangerous.

6. VPN ABUSE

Some versions of the malicious applications may also install or configure a VPN.

A VPN itself is not malicious.

Legitimate VPN services are widely used.

The concern is when malware controls the VPN configuration.

According to the I4C warning, some versions may route Internet traffic through attacker-controlled infrastructure.

This can create another layer of risk because the device's network traffic may no longer follow the user's expected path.

7. WHY FINANCIAL FRAUD BECOMES POSSIBLE

Now combine the capabilities:

Malicious APK

Accessibility abuse

Device interaction

Sensitive information

=

Potential financial fraud

Attackers may attempt to abuse access to:

Banking applications

UPI applications

SMS/notifications

Authentication workflows

Personal information

The I4C warning specifically connects the campaign to unauthorised financial transactions.

8. THE COMPLETE ATTACK CHAIN

🎯 STAGE 1 β€” LURE

Instagram/Facebook advertisement

↓

🌐 STAGE 2 β€” REDIRECT

Fake adult-content website

↓

πŸ“¦ STAGE 3 β€” DELIVERY

Malicious APK

↓

πŸ” STAGE 4 β€” PERMISSION

Accessibility / sensitive permissions

↓

🦠 STAGE 5 β€” CONTROL

Potential device control

↓

πŸ”„ STAGE 6 β€” EXPANSION

Possible secondary APK/VPN

↓

πŸ’° STAGE 7 β€” IMPACT

Potential unauthorised financial transactions

9. WHY THIS ATTACK IS SO EFFECTIVE

The attacker doesn't necessarily need to exploit an Android zero-day.

Instead, the attacker exploits:

Human behaviour.

The victim does the following:

Click

↓

Download

↓

Install

↓

Allow

And the attacker gets the opportunity they need.

This is why social engineering remains one of the most effective attack vectors.

πŸ”Ž TECHNICAL THREAT PROFILE

Category Details

Initial Access Social-media advertisements

Platforms Instagram / Facebook

Target Android users

Delivery External APK

Social Engineering Adult/dating lure

Privilege Abuse Accessibility

Additional Capability Secondary APK

Network Capability Potential VPN abuse

Persistence Risk Application may resist removal

Impact Potential financial fraud

The exact behaviour can vary between samples and versions, so these should be treated as campaign-level characteristics, not guaranteed behaviour of every APK carrying these names.

πŸ›‘οΈ 10. HOW TO PROTECT YOURSELF

Rule #1 β€” Don't install APKs from advertisements

If an Instagram/Facebook advertisement says:

β€œDownload our app.”

Stop.

Open the official Google Play Store independently and search for the application.

Don't follow the APK download link.

Rule #2 β€” Treat Accessibility permission as highly sensitive

Before enabling Accessibility for an unfamiliar application:

Ask:

Why does this application need to control my device?

If you cannot clearly answer that:

Don't enable it.

Rule #3 β€” Keep Google Play Protect enabled

Do not disable security protections simply because an unknown website tells you to.

Rule #4 β€” Keep Android updated

Update:

Android

Google Play system

Applications

Security software

Rule #5 β€” Review installed applications

Regularly check for:

Unknown applications

Recently installed apps

Apps you don't remember installing

Suspicious names

Applications with unnecessary permissions

🚨 11. IF YOU ALREADY INSTALLED THE SUSPICIOUS APK

Act quickly.

STEP 1 β€” Disconnect

If you suspect active malicious activity, disconnect the phone from the Internet where practical.

STEP 2 β€” Enter Safe Mode

Restart the phone in Safe Mode.

STEP 3 β€” Remove the suspicious application

Check:

Settings β†’ Apps

Find the suspicious application and attempt to uninstall it.

STEP 4 β€” Revoke Accessibility

Go to the Accessibility settings and disable the suspicious application's access.

STEP 5 β€” Check administrator privileges

Review Device Administrator settings and remove suspicious administrative access.

The I4C guidance specifically recommends Safe Mode and removal of Accessibility/administrator access where necessary.

STEP 6 β€” Check banking activity

Immediately review:

Bank accounts

UPI

Cards

Wallets

STEP 7 β€” Secure accounts from a clean device

Change critical passwords using a device you trust.

STEP 8 β€” Factory reset if necessary

If the malicious application cannot be reliably removed or continues returning, back up trusted data and consider a factory reset.

πŸ’° 12. IF MONEY HAS ALREADY BEEN STOLEN

Act immediately.

In India, report financial cyber fraud through:

1930 β€” National Cyber Crime Helpline

and the:

National Cyber Crime Reporting Portal

The official portal confirms that 1930 is available for immediate reporting of cyber financial fraud.

You can also report suspicious identifiers such as websites, phone numbers, email IDs, SMS headers and social-media URLs through the portal's Report Suspect facility.

πŸ”₯ CYBERRAKSHAKLABS THREAT ASSESSMENT

Attack Vector

Social Engineering

Delivery

Malicious Android APK

Primary Abuse

Accessibility permissions

Secondary Risk

Additional APK / VPN

Target

Android users

Impact

Potential device takeover and financial fraud

Severity

πŸ”΄ HIGH

The greatest risk is not the advertisement itself.

It is the trust decision made after the advertisement.

🧠 THE BIG LESSON

Cybercriminals don't always need to:

Hack your phone.

Sometimes they simply convince you to:

Install the hack yourself.

That's why the most important security control is often:

PAUSE BEFORE YOU INSTALL.

πŸ›‘οΈ CYBERRAKSHAKLABS SECURITY FORMULA

AD β†’ LINK β†’ APK β†’ PERMISSION

Whenever you see this chain:

🚨 STOP.

Verify the source.

Check the application store.

Review permissions.

Never grant Accessibility to an unknown app.

Monitor financial activity.

πŸ” FINAL MESSAGE

Your smartphone contains:

πŸ’³ Your money

πŸ” Your authentication

πŸ“± Your identity

πŸ’¬ Your conversations

πŸ“Έ Your personal information

Don't allow an unknown application to become the administrator of your digital life.

Think before you click.

Verify before you install.

Review before you allow.

Be Aware. Be Intelligent. Be Secure. Be Cyber Safe.

CyberRakshakLabs

Cyber Awareness | Threat Intelligence | Digital Safety

πŸ›‘οΈ CyberRakshakLabs Security Formula

AD β†’ LINK β†’ APK β†’ PERMISSION

Whenever you see this chain: STOP. Verify the source. Check the application store. Review permissions. Never grant Accessibility to an unknown app. Monitor financial activity.