Advertisement
X

Cyber Fraud Alert: I4C Warns Against Clicking Adult App Links On Social Media, Could Lead To Bank Fraud

The National Cybercrime Threat Analytics Unit (NCTAU) of the I4C has issued an advisory cautioning people about a device-hijacking malware that can corrupt the device security system and could lead to financial fraud  

I4C warns against adult app links on social media Photo: AI
Summary
  • I4C warns against clicking on adult apps in advertisement on social media that may lead to financial fraud.

  • Malicious APKs in the guise of such ads can hijack phones and steal personal and banking data.

  • The advisory suggests keeping Google Play Protect enabled and report financial fraud on 1930

Advertisement

The Indian Cybercrime Coordination Centre (I4C) of the Ministry of Home Affairs has issued an urgent advisory, asking people to take precaution while clicking on any advertisement or link on social media. Its National Cybercrime Threat Analytics Unit (NCTAU), which works under I4C, has advised Android users against sophisticated cyber frauds, detecting a sharp rise in unauthorised financial transactions driven by malicious applications masked as pornography apps.

Fraudsters are using popular platforms to trap unsuspecting users. The advisory reads that it has observed “a rise in financial frauds perpetrated through malicious Android applications masquerading as pornography apps, circulated through Facebook and Instagram ads operating under the names “Night Play”, “Reloop”, “Kyss”, “Vimo”, “Rivo”, “Nexo”, “Vixa”, and other similar variants.

Modus Operandi: How The Device Hijack Occurs

  • According to the NCTAU, the modus operandi begins with advertisements promoting adult content on major social media platform feeds. When a person clicks the ad, it redirects victims to external phishing websites.

  • Such phishing websites mostly use “.live” domain extensions. Users are persuaded to download an Android Package (APK) file directly from the browser, bypassing the safety of the Google Play Store.

  • Once the initial APK file is downloaded on the device, the malware starts corrupting the security system. The initial app abuses the basic permissions and silently downloads and instals a secondary app under the guise of a standard application update.

  • The app prompts the user to grant accessibility and other sensitive permissions. Once permission is granted, the malware takes control of the device and executes commands silently in the background.

  • In several instances, the App automatically configures a Virtual Private Network (VPN). This routes all of the victim’s Internet traffic through attacker-controlled servers, which means exposing the victim’s confidential data that can be used for malicious activities.

  • Having background access, screen control, and intercepted data traffic on the victim’s device, the attackers execute unauthorised bank or Unified Payments Interface (UPI) transactions.

However, the worst part is that victims can’t uninstal the suspected app. The advisory says, “The app may prevent users from uninstalling it through the device settings.”

So, what can be done if such an app has been downloaded on the device?

The advisory suggests two methods for uninstalling such an app, which otherwise cannot be uninstaled.  

Advertisement

Two Methods For Uninstalling A Malicious App

Method 1:

Suspecting a malicious app on the device, the user needs to restart the phone in Safe Mode by holding the physical power button and selecting the ‘Safe Mode’ option. When the phone restarts, the “Safe Mode” appears at the bottom of the screen. Open Settings, go to Apps, select the suspicious applications, and tap Uninstall. 

Remove any other unknown apps as well. Once complete, restart the phone normally. The device will automatically exit Safe Mode.  

Method 2:

Under this method, the user can disable the malicious app by restoring the device’s default system launcher (such as System Launcher, One UI Home, or Pixel Launcher). For this, go to Apps – Default Apps – Home App and select the system launcher. 

Open Settings, tap Accessibility, and open Downloaded Apps. Select the suspicious app, and turn off its accessibility. Then, go to Security or Security & Privacy under Settings – open Device Admin Apps, select the suspicious app, deactivate it, and turn it off.

Advertisement

Most importantly, after uninstalling the malicious app, verify that it has been uninstaled. Go to Settings – Apps and check whether the suspicious app has been removed; however, if it cannot be removed, take the back-up of your important data and perform a Factory Reset.

NCTAU Recommendations: How To Stay Safe

The advisory is meant to make people aware and not download links randomly from social media ads. The NCTAU recommends following three steps to stay safe:

  • Instal applications only from the Google Play Store or other trusted app stores

  • Keep Google Play Protect enabled

  • Avoid APK downloads from Web advertisements

  • Check your bank account regularly

  • Check your installed apps regularly and remove any app you don’t recognise

If a fraud has happened, inform the cyber cell on the number 1930. Remember, mobile apps have made life easier, but have also given rise to personal and sensitive data theft risk. Thus, it is essential to stay aware to stay safe.

Advertisement
Show comments
Published At: