Technology
Times of India

Govt sounds alarm as Facebook, Instagram ads target banking passwords, phones

Source Entity

TOI TECH DESK

September 2, 2026
Govt sounds alarm as Facebook, Instagram ads target banking passwords, phones

The Indian government has issued an urgent warning regarding malicious Android apps disguised as pornographic content on Facebook and Instagram. These apps hijack devices and steal financial data by abusing accessibility permissions.

Urgent Cyber Security Alert: Malicious Apps Hijacking Android Devices

The Indian government, specifically the National Cybercrime Threat Analytics Unit (NCTAU) under the Indian Cyber Crime Coordination Centre (I4C), has issued a critical advisory regarding a surge in financial fraud. The threat involves malicious Android applications that are being actively promoted through deceptive advertisements on major social media platforms, including Facebook and Instagram. These ads lure users by masquerading as pornographic content, ultimately redirecting them to external websites where they are prompted to download APK files that compromise device security.

The Mechanism of the Attack

Once downloaded, these applications—identified by names such as "Night Play," "Reloop," "Kyss," "Vimo," "Rivo," "Nexo," and "Vixa"—do not function as standard software. Instead, they are designed to seize control of the user's Android device. By requesting and abusing accessibility permissions, these apps gain the ability to monitor user activity, intercept sensitive information, and potentially bypass multi-factor authentication protocols, leaving the user's financial accounts vulnerable to immediate exploitation.

The Role of Social Media in Distribution

This incident highlights a significant vulnerability within digital advertising ecosystems. By hosting ads that lead directly to malicious payloads, these platforms are inadvertently serving as vectors for cybercrime. The reliance on side-loading—the act of installing apps from outside the official Google Play Store—remains the primary method for these threat actors to bypass the robust security checks that typically prevent such malware from reaching mainstream consumers.

Broader Implications for Mobile Security

This trend signals a shift toward more sophisticated social engineering tactics. Rather than relying solely on phishing emails, attackers are now leveraging the high engagement rates of social media ads to target users directly. The ability of these apps to "hijack" devices suggests a move toward full-device control, which is significantly more dangerous than simple password theft. It underscores the necessity for users to maintain strict hygiene regarding app installations and to be wary of any content that redirects them to third-party APK downloads.

Mitigating the Threat and Future Trends

As cybercriminals continue to evolve their methods, the burden of protection is increasingly falling on both the individual and the platform. Users are urged to immediately uninstall any suspicious applications and avoid granting broad accessibility permissions to unknown software. Looking forward, we can expect regulatory bodies to place greater pressure on social media giants to vet their advertising content more stringently. The integration of better heuristic analysis in mobile operating systems may also become a requirement to flag apps that exhibit 'hijacking' behavior before they can cause financial damage.

Verification Required?

Read the full report from the primary source

Go to Times of India