
Meta has removed dozens of Facebook and Instagram advertisements that used sexual content to lure users into downloading malicious Android applications linked to banking fraud and data theft. According to a Reuters report, the removal came after Indian authorities raised concerns about financial fraud targeting the country's rapidly growing digital payments ecosystem. The action follows Meta's advertising policies that prohibit ads containing adult nudity or sexual activity, as well as products or services involving deceptive or misleading practices intended to defraud users of money.
The Indian Cybercrime Coordination Centre (I4C) has issued a warning about a sophisticated cybercrime campaign targeting social media users through fake adult and dating applications. According to reports from the I4C, cybercriminals are using ads on platforms such as Instagram and Facebook to lure users with sexually explicit content and dating-related offers. These malicious advertisements lead users to download malicious Android applications that can steal sensitive data and commit financial fraud. The I4C's Threat Analytics Unit (TAU) has identified several applications as part of this campaign, including 'Night Play,' 'Reloop,' 'Kyss,' 'Vimo,' 'Rivo,' 'Nexo' and 'Vixa.' The advisory urged users to be cautious when clicking on such advertisements or downloading apps promoted through them.
According to the I4C warning, the malicious applications can request access to SMS, contacts, photos, storage and Accessibility Services. This comprehensive permission structure allows scammers to control infected phones, read one-time passwords (OTPs), access personal information, and conduct unauthorized financial transactions. The malicious apps are designed to trick users into downloading APK files from shady websites, with the application asking for sensitive permissions to access adult site content. As reported by the Indian government's alert, such malicious apps could steal banking PINs and one-time passwords, access data stored on users' phones and transfer money from bank accounts without the owner's knowledge. Some applications may also install hidden VPNs without taking permission, enabling attackers to reroute internet traffic through their own servers.
India suffered cyber fraud losses of around $2.4 billion in 2025 as scammers increasingly targeted the country's rapidly growing digital payments ecosystem, according to a Reuters report. This represents a significant escalation in cybercrime activities affecting the country's financial infrastructure. The fraudulent apps typically require users to download a file called 'Movexa.apk' directly from outside the official app store, bypassing standard security measures. Users were prompted to download APK files and install them manually on Android devices, where the applications request extensive permissions that provide scammers with complete control over infected devices.
This removal represents the second time in recent weeks that Indian authorities have raised concerns about financial fraud linked to major technology platforms, according to Reuters reports. Earlier, authorities had ordered Google to remove hundreds of accounts on its Firebase platform after finding that criminals were allegedly using the service to impersonate major institutions. The I4C has provided specific guidance for users to protect themselves, recommending they avoid downloading APK files from social media ads or unfamiliar websites and instead download applications only from trusted app stores with Google Play Protect enabled. Users should regularly check their list of installed apps and remove anything they do not remember downloading, and ensure they use Google Play Protect with device updates. Additionally, users should never allow suspicious applications with Accessibility access and always double check suspicious applications before uninstalling them.