In an advisory, the NCTAU identified apps including “Night Play”, “Reloop”, “Kyss”, “Vimo”, “Rivo”, “Nexo” and “Vixa”, along with similar variants, as part of the threat.
According to the advisory, the malicious applications are primarily distributed through pornography-related advertisements and links on social media platforms. Users who click on such advertisements may be redirected to websites hosting pornographic content and prompted to download an Android Package Kit (APK) from outside the Google Play Store. Many of the identified websites are associated with “.live” domains.
After installation, users may be asked to download a secondary package disguised as an app update. The malicious software can then seek Accessibility and other sensitive permissions. If granted, these permissions can give attackers extensive control over the device and allow the application to operate in the background.
The NCTAU also cautioned that certain variants may install a virtual private network (VPN), potentially routing the user’s internet traffic through attacker-controlled servers and exposing transmitted data to misuse.
Some malicious applications may also attempt to prevent users from uninstalling them through normal device settings.
The suspected attack chain begins with a social media advertisement, followed by redirection to a malicious website and installation of an APK. In some cases, this may lead to VPN installation, requests for Accessibility permissions, device takeover and ultimately unauthorised financial transactions.
The agency advised users to download applications only from the Google Play Store or other trusted app stores and avoid APK files received through advertisements, unfamiliar websites or suspicious links.
Users have also been advised not to grant Accessibility permissions to unfamiliar applications and to regularly review installed apps and remove those they do not recognise.
Keeping Google Play Protect enabled, installing the latest Android security updates and regularly checking bank accounts and UPI transactions are among the other precautions recommended by the NCTAU.
For users unable to uninstall a suspicious application normally, the advisory recommends restarting the device in Safe Mode and removing the application through the Apps section in Settings. Users can also disable Accessibility access and revoke administrator privileges before attempting to uninstall the app.
If the application cannot be removed or returns after a restart, users have been advised to back up important data and consider performing a factory reset of the device.
















































































