New Delhi, India
The risk of cyber fraud through advertisements promoting fake porn apps on social media platforms such as Facebook and Instagram has increased. The National Cybercrime Threat Analytics Unit (NCTAU), operating under the Indian Cyber Crime Coordination Centre (I4C), has warned Android users to stay alert against such malicious applications.
According to the cyber agency, these apps are designed to gain extensive control over users’ devices after being downloaded and installed. This access can potentially be misused to facilitate financial fraud and other cybercrimes.
Highlights
- NCTAU has warned about dangerous Android apps being promoted in the name of porn apps.
- Facebook and Instagram advertisements are being used to redirect users to fraudulent websites.
- Users are encouraged to download APK files and grant sensitive permissions such as Accessibility access.
- Once control of the device is obtained, the risk of financial fraud increases.
The Scam Begins With Facebook and Instagram Advertisements
According to NCTAU, misleading advertisements using names such as Night Play, Reloop, Kyss, Riva, Vima, Nexo, and Vixa were being promoted on Facebook and Instagram. These advertisements redirected users to phishing websites that claimed to offer access to adult content.
Instead of directing users to the Google Play Store, these websites instructed them to download and install APK files directly. This is one of the most critical stages of the scam. Installing APK files from outside official app stores can expose Android devices to serious security risks.
Attempt to Take Control of Devices Through Accessibility Permissions
After installation, such apps may request sensitive permissions that can provide extensive control over the device. In particular, misuse of Accessibility permissions can allow cybercriminals to monitor information displayed on the user’s screen and perform certain actions on the device.
Such access can potentially be exploited to obtain information related to banking and other financial activities or to carry out unauthorized transactions. In some cases, malicious apps may also attempt to prevent users from easily uninstalling them through normal device settings.
Traffic May Also Be Routed Through a VPN
The cyber agency also warned that some of these applications may install a VPN. Such functionality can potentially be used to route internet traffic associated with criminal activities through alternative paths. This may make it easier for cybercriminals to conceal their activities and misuse the compromised device.
How Can Users Stay Safe?
NCTAU has advised users not to download APK files after clicking on links or advertisements from unknown websites or social media accounts. Apps should always be downloaded from the Google Play Store or other trusted official sources.
Users should also carefully review the permissions requested by an application. If an unfamiliar app requests unusual or highly sensitive permissions that are not necessary for its stated functionality, users should avoid granting those permissions.
Cybersecurity experts emphasize that an advertisement appearing on social media is not necessarily trustworthy. Users should be particularly cautious with advertisements that pressure them to immediately download an APK file or change their device’s security settings.


