The advisory urges users to avoid unknown APKs, restrict Accessibility permissions, keep Play Protect enabled and report cybercrime through helpline 1930 | Representational image 
Nation

MHA warns of app scam that can take control of Android phones, steal money

The apps are promoted through social media advertisements and can trick users into downloading APK files outside the Google Play Store

The Union Home Ministry's Indian Cyber Crime Coordination Centre (I4C) has warned Android users about a growing cyber fraud tactic involving malicious applications disguised as pornography apps.

The National Cybercrime Threat Analytics Unit (NCTAU), under I4C, said it had observed an increase in financial frauds linked to such applications. An advisory issued on August 26 said these apps are mainly promoted through advertisements on social media.

How the scam works

According to the advisory, users are first directed through advertisements to websites offering pornographic content. They are then encouraged to download an Android Package Kit (APK) file from outside the Google Play Store.

The malicious app may ask for sensitive permissions, including Accessibility access. Once granted, attackers can potentially control several functions of the device while the application operates in the background.

The advisory named apps such as “Night Play”, “Reloop”, “Kyss”, “Vimo”, “Rivo”, “Nexo” and “Vixa”, along with similar variants.

Malware can enable financial fraud

The cybercrime unit said attackers can misuse Accessibility features to read information appearing on the screen, click buttons and enter OTPs or PINs. They may also confirm transactions and initiate fund transfers, potentially allowing money to be stolen from victims' bank accounts.

Some of these apps may download another application by presenting it as an update. They may also install a VPN that routes internet traffic through servers controlled by attackers, potentially exposing transmitted information.

The apps can further make removal difficult by preventing users from uninstalling them through normal phone settings.

What Android users should do

The NCTAU advised users to download applications only from the Google Play Store or other trusted app stores and avoid APK files promoted through advertisements, unknown links or suspicious websites.

Users should also avoid giving Accessibility permissions to unfamiliar applications, regularly check installed apps, keep Google Play Protect enabled and update their Android operating system.

People have also been advised to monitor bank accounts and UPI transactions for unusual activity.

Steps if a phone is compromised

For an infected device, the advisory recommends restarting the phone in Safe Mode and removing suspicious applications. Users may also need to revoke Accessibility access and device administrator privileges.

If an app cannot be removed or returns after a restart, users should back up important data and consider a factory reset.

The government has urged citizens to report cybercrime or fraudulent applications through helpline 1930 or the national cybercrime reporting portal.