Government Flags Malicious Apps Linked to Financial Fraud

TECHNOLOGY
Whalesbook Logo
AuthorVihaan Mehta|Published at:
Government Flags Malicious Apps Linked to Financial Fraud

The Ministry of Home Affairs has issued a critical warning regarding seven mobile apps—Night Play, Reloop, Kyss, Vimo, Rivo, Nexo, and Vixa—that are being used to steal banking credentials. These apps masquerade as adult content to trick users into granting permissions that allow attackers to drain bank accounts. Users are advised to delete these applications immediately and avoid downloading software from outside official app stores.

The Indian Cyber Crime Coordination Centre, operating under the Ministry of Home Affairs, has issued a high-priority advisory warning mobile users about a dangerous wave of financial fraud. The scam utilizes deceptive advertisements on social media platforms, including Facebook and Instagram, to lure victims into downloading malware disguised as adult entertainment applications. The specific apps flagged by the government are Night Play, Reloop, Kyss, Vimo, Rivo, Nexo, and Vixa.

The primary danger with these applications is that they are not sourced from official app stores. Instead, they are distributed through external websites as APK files, which are installer packages for Android that bypass standard security verification processes. This distribution method is a common tactic used to deliver malicious software to devices without triggering the usual safety alerts.

Once installed, the software exploits a feature known as Accessibility Permission. By tricking users into granting this specific permission, the application gains broad control over the device. This allows the malware to operate silently in the background, where it can monitor screen activity, intercept incoming text messages, and read sensitive data, including one-time passwords or OTPs.

For investors and general banking users, the financial risk is direct and severe. By gaining administrative control over the mobile device, these programs can interact with banking and payment applications installed on the phone. This capability allows attackers to initiate unauthorized financial transactions, potentially draining a victim's bank account before the user realizes their security has been breached. In many instances, the malware also installs unauthorized Virtual Private Network software to reroute internet traffic, ensuring the attackers maintain long-term access and surveillance over the device.

Following the government's alert, social media companies like Meta have removed the fraudulent advertisements that were driving traffic to these malicious websites. However, the risk persists for any user who has already installed these programs. Officials strongly advise users to uninstall these apps immediately and perform a security check on their mobile devices. Anyone who notices suspicious account activity or unauthorized transactions is urged to contact the national cybercrime helpline by dialing 1930 or to file an official report through the government's cybercrime portal at cybercrime.gov.in.

Disclaimer: This article is published for informational purposes only. This is not a buy sell recommendation.