Meta Pulls 39 Scam Ads Promoting Malicious Porn Apps After India’s Warning

Meta Pulls 39 Scam Ads Promoting Malicious Porn Apps After India’s Warning
Meta Pulls 39 Scam Ads Promoting Malicious Porn Apps After India’s Warning

Meta removed dozens of advertisements from Facebook and Instagram after the Centre warned that malicious Android apps masquerading as pornography apps were being promoted through sexually explicit content on the platforms.

The apps could steal banking credentials and OTPs, take control of users’ devices, and transfer money from their accounts without their knowledge, according to an advisory issued by the Ministry of Home Affairs (MHA).

Reuters found at least 39 such ads active after the advisory was issued. Meta removed all the ads shortly after the news agency flagged them to the company. 

Inc42 has reached out to Meta for a comment on the development. The story will be updated if a response is received.

The advisory, issued on August 26, followed a rise in financial fraud involving malicious Android apps disguised as pornography apps, the National Cybercrime Threat Analytics Unit (NCTAU) under the Indian Cybercrime Coordination Centre (I4C) said.

The apps were promoted through Facebook and Instagram advertisements under names such as “Night Play”, “Reloop”, “Kyss”, “Vimo”, “Rivo”, “Nexo” and “Vixa”, among other variants.

The advertisements used sexually explicit videos and images to attract users and redirect them to phishing websites offering pornographic content. Users were then prompted to download APK files outside official app stores such as the Google Play Store.

One of the advertisements reviewed by Reuters redirected users to a website promoting a video app that promised access to hundreds of pornographic videos. Users had to download a file named “Movexa.apk” directly from the website.

Once installed, the malicious apps sought accessibility and other sensitive permissions, allowing attackers to access information stored on a device and operate the malware in the background. 

The apps could subsequently download another package disguised as an update. By misusing the permissions granted to the initial app, the malware could capture OTPs and bank PINs, take control of the device, and facilitate unauthorised financial transactions.

Some of the apps could also install a VPN and route the device’s internet traffic through servers controlled by the attackers, potentially exposing users’ transmitted data. The malware could also prevent users from uninstalling the app through the device’s normal settings.

Protecting Infected Devices

The NCTAU advised users to download apps only from the Google Play Store or other trusted app stores and avoid installing APK files received through advertisements, websites or suspicious links.

Users have also been asked not to grant accessibility permissions to unknown apps, keep Google Play Protect enabled, regularly review installed apps, update their Android devices, and monitor bank accounts and UPI transactions for suspicious activity.

Users who suspect that their devices have been infected should restart them in ‘Safe Mode’ and uninstall the suspicious app. If the app cannot be removed, they should disable its accessibility access and revoke any device administrator privileges granted to it.

If the app reappears after the device is restarted, users have been advised to back up essential data and consider performing a factory reset. Cybercrime incidents can be reported by calling 1930 or through the National Cybercrime Reporting Portal.

India’s Cyber Fraud Battle

The warning comes as India grapples with mounting cyber fraud. The country recorded nearly $2.4 Bn in cyber-fraud losses in 2025, according to government data.

It also comes days after the Centre reportedly directed Google to shut down hundreds of accounts on its Firebase platform after discovering that criminals were using the service to impersonate major banks.

Meta’s advertising policies prohibit ads containing adult nudity and sexual activity, as well as those promoting products, services or schemes through deceptive practices intended to defraud users.

However, Meta had internally estimated that advertisements promoting scams and banned goods could generate around 10% of its 2024 revenue, or nearly $16 Bn, Reuters reported last year. The projection came even as the social media giant said it was stepping up efforts to crack down on fraudulent advertisements.

The post Meta Pulls 39 Scam Ads Promoting Malicious Porn Apps After India’s Warning appeared first on Inc42 Media.