I4C advises caution as it sees rise in financial fraud through 'malicious' Android apps

Indian Cyber Crime Coordination warns of financial fraud via fake pornography apps. These malicious applications are advertised on Facebook and Instagram platforms. Users are tricked into downloading APK files from suspicious websites and links. O...

ANI
New Delhi: Indian Cyber Crime Coordination (I4C) has observed a rise in financial fraud perpetrated through malicious Android applications masquerading as pornography apps, circulated through Facebook and Instagram advertisement operating under 'Night Play', 'Reloop', 'Kyss', 'Vimo', 'Rivo', 'Nexo', 'Vixa' and other similar variants.

According to an I4C advisory, "These applications are primarily distributed through advertisements on Facebook and Instagram, which redirect to websites serving pornographic content, where the user is prompted to download the APK (a package form used by Android). After installation, the app requests permissions that allows it to install additional applications and by abusing accessibility permission, takes control of the users' device, which may result in financial fraud. Some apps also install a VPN, which may be used to route internet traffic pertaining to malicious and criminal activity. The app may prevent users from uninstalling it through the device settings."

I4C Advises Caution as it Sees Rise in Fin Frauds Through ‘Malicious’ Android Apps
‘primarily distributed VIA advertisements on Facebook, Instagram’: 14C
The malicious application is distributed through pornographic content-related advertisements or links majorly on Facebook and Instagram. These ads redirect to phishing websites. In most cases, domains of the website majorly belong to "live". Users are persuaded to download and install the APK from sources outside the Google Play Store, the advisory noted.


It added, "A secondary package gets downloaded and installed on the pretext of an app update, based on permissions abused by the first. After installation, the application asks users to grant accessibility and other sensitive permissions. Once enabled, the malware gains control of the device and continues to run in the background. Some apps may also install a VPN on the device, thereby routing all internet traffic through attacker-controlled servers. This compromises user's transmitted data, which may be exploited for malicious or criminal activities."

Since the malware has the ability to take over the compromised device, installing such apps may lead to financial fraud. I4C said that applications should be downloaded only from Google Play Store or other trusted app stores. Do not download APK files from advertisements, websites or suspicious links. Do not grant accessibility permission for unknown applications. Review installed applications and remove any app you do not recognise. Keep Google Play Protect enabled and keep your Android device updated. Check your bank account and UPI transactions regularly.
Download
The Economic Times Business News App
for the Latest News in Business, Sensex, Stock Market Updates & More.
Download
The Economic Times News App
for Quarterly Results, Latest News in ITR, Business, Share Market, Live Sensex News & More.
READ MORE
ADVERTISEMENT

READ MORE:

LOGIN & CLAIM

50 TIMESPOINTS

More from our Partners

Loading next story
Business News › News › India › I4C advises caution as it sees rise in financial fraud through 'malicious' Android apps
Text Size:AAA
Success
This article has been saved

*

+