NCTAU Warns of Financial Fraud Linked to Malicious Pornography Apps in India

The CSR Journal Magazine

The National Cybercrime Threat Analytics Unit (NCTAU), part of the Indian Cybercrime Coordination Centre (I4C), has issued a significant warning about an increase in financial fraud linked to malicious Android applications that disguise themselves as pornography apps. This advisory, released on August 26 by the Ministry of Home Affairs, highlights concerning trends in cybercrime.

Advertisements Promoting Malicious Applications

The I4C advisory notes that these fraudulent applications are being advertised on platforms such as Facebook and Instagram, under various names, including “Night Play,” “Reloop,” “Kyss,” “Vimo,” “Rivo,” “Nexo,” and “Vixa,” among other similar variants. The advertisements lure users by redirecting them to websites that contain pornographic content, where they are encouraged to download APK files from sources outside the Google Play Store.

How the Malware Operates

Once the malicious application is installed, it requests access to sensitive permissions, enabling attackers to control the device and execute malware in the background. The advisory explained that a secondary package might be downloaded, disguised as an update for the original app. This practice involves misusing granted permissions to facilitate complete takeover of the device, which can lead to unauthorised financial transactions.

Additionally, some applications install a virtual private network (VPN) on the device, routing internet traffic through server locations controlled by the attackers. This action can jeopardise the users’ transmitted data, making it vulnerable to exploitation or cybercrime.

The NCTAU has outlined a six-stage operation method used by these malicious apps:

1. Distribution via social media ads.
2. Redirection to phishing websites.
3. Downloading a secondary package masquerading as an app update.
4. Abuse of accessibility permissions for device control.
5. Installation of a malicious VPN.
6. Execution of unauthorised financial transactions.

Security Recommendations for Users

In response to this rising threat, the NCTAU strongly advises users to download applications exclusively from the Google Play Store or other reputable app stores, avoiding any APK files from advertisements, unknown websites, or dubious links. Users are urged not to grant accessibility permissions to applications they do not recognise, and to regularly review installed applications, removing any that seem unfamiliar.

The advisory also encourages users to keep Google Play Protect enabled, perform regular updates on their Android devices, and routinely inspect bank accounts and UPI transactions for any unusual activity. Furthermore, should users suspect they have downloaded a malicious app, they should restart their phones in Safe Mode, proceed to uninstall the suspicious application, and cleanse any related unknown apps before returning to normal operation.

If any challenges arise in the removal of the app, users are instructed to revoke its accessibility access and administrator privileges. Continual issues with the application necessitate backing up important data, with a recommendation to consider a factory reset as a last resort.

Reporting Cybercrime Incidents

The I4C advisory concludes with a call to action for citizens to report any fraudulent applications or cybercrime occurrences without delay. Individuals can contact 1930 or utilise the National Cybercrime Reporting Portal to report incidents effectively.

Long or Short, get news the way you like. No ads. No redirections. Download Newspin and Stay Alert, The CSR Journal Mobile app, for fast, crisp, clean updates!

App Store – https://apps.apple.com/in/app/newspin/id6746449540

Google Play Store – https://play.google.com/store/apps/details?id=com.inventifweb.newspin&pcampaignid=web_share

Latest News

Popular Videos