Govt. Warned Of Porn Scam Apps; Meta Ads Stayed Live | #cybercrime | #infosec


You can access the government advisory from here

India’s cybercrime coordination centre warned on August 26, 2026, that fraudulent Android apps posing as pornography services were being advertised on Facebook and Instagram to steal banking credentials.

Five days later, Reuters found at least 39 such ads still running. Meta removed them on August 31 — after Reuters asked about them. The company did not respond to Reuters’ questions about the removal or the advisory.

That sequence is the story. A government advisory identified the campaign, named the apps and described how they worked. It did not get the ads taken down. A press query did.

Why it matters

An advisory is not a takedown notice, and the Indian Cyber Crime Coordination Centre (I4C) has separate powers to issue those. What the gap shows is how much of platform enforcement still depends on someone outside the system noticing.

It also matters because of the scale. India recorded close to $2.4 billion in cyber-fraud losses in 2025, according to Reuters, with scammers increasingly targeting the country’s digital payments infrastructure. Ads are the top of that funnel.

What the advisory said

The advisory came from the National Cybercrime Threat Analytics Unit (NCTAU), a unit under I4C at the Ministry of Home Affairs.

It named seven app variants: Night Play, Reloop, Kyss, Vimo, Rivo, Nexo and Vixa. All were promoted through advertisements on Facebook and Instagram.

The advisory set out a six-stage sequence:

  • Ads on social media platforms draw users in.
  • Clicks redirect to phishing websites offering pornographic content.
  • Users are prompted to download an APK file — an Android installer package obtained outside official app stores.
  • A second package is downloaded, disguised as an app update.
  • The app requests Accessibility permissions, which give it broad control over the device.
  • A VPN is installed, routing the device’s traffic through servers the attackers control, after which unauthorised financial transactions follow.

Once installed, the malware runs in the background. The advisory notes that it may also stop users from uninstalling it through normal device settings.

I4C’s recommendations were directed at users. Download only from the Play Store or trusted sources. Do not grant Accessibility permissions to unknown apps. Keep Google Play Protect on and monitor bank and UPI transactions. Report incidents to 1930 or the National Cybercrime Reporting Portal.

Worth noting what that list does not contain: any obligation on the platform carrying the advertisements.

There is also a reporting problem specific to this lure. A campaign built around pornography exploits embarrassment, and people defrauded this way are less likely to come forward. Loss figures for campaigns of this kind are likely to understate them.

What Meta’s own documents say about scam ads

Meta’s handling here is not an isolated lapse in review. Reuters reported in November 2025 on internal company documents covering exactly this. Meta had projected that roughly 10% of its 2024 revenue, about $16 billion, would come from advertising for scams and banned goods.

A December 2024 internal document estimated that Meta was showing users about 15 billion “higher risk” scam advertisements a day, generating roughly $7 billion a year, reported Reuters.

Two details from that reporting explain the enforcement pattern better than any policy statement.

First, the threshold. Meta’s automated systems would ban an advertiser only where they predicted at least 95% certainty of fraud.

Second, what happened below that threshold. Advertisers suspected of fraud but falling short of 95% certainty were not removed. They were charged higher ad rates, which the documents describe as a deterrent. The company continued to take their money.

Meta has disputed the framing. Spokesperson Andy Stone told the ABC that the internal assessment “was done to validate our planned integrity investments, including in combating frauds and scams, which we did.” He added: “We aggressively fight fraud and scams because people on our platforms don’t want this content, legitimate advertisers don’t want it and we don’t want it either.”

The US Securities and Exchange Commission and the UK Financial Conduct Authority have both opened inquiries into Meta’s role in facilitating financial scams.

The third time in three months

For Indian regulators, this is a familiar sequence.

In July 2026, MeitY summoned Meta after a BBC investigation found Instagram ads promoting child sexual abuse material. The ministry ordered the company to disable the ads and explain within seven days how they had passed ad review.

In August, MediaNama reported that researchers at the Tech Transparency Project had found more than 50 ads carrying AI-generated child sexual abuse material across Meta’s platforms. Some were still running roughly a month after the July investigation. Around 30 further violations surfaced after the researchers contacted Meta for comment.

The pattern in all three cases is the same. Ads clear review. An external party finds them. The company removes them after being asked and states that it works aggressively on the problem.

Meta announced a set of anti-scam tools for WhatsApp and Facebook in March 2026. Whether those tools were in play here is not clear, and MediaNama has asked.

The part that sits outside Meta

Removing the ads does not remove the apps, and this is where the story stops being about one platform.

The campaign depends on sideloading, installing an app from outside an official store. Google Play Protect scans sideloaded apps. But the malware’s design works around what scanning catches. It downloads its real payload after installation, disguised as an update, and only then asks for Accessibility permissions.

Accessibility is the pivot. The permission exists so that people with disabilities can use screen readers and similar tools. That means it grants deep control over what the device displays and does. Malware that obtains it can read the screen, click on the user’s behalf and block its own removal. Legitimate need and attacker utility sit in the same permission. That is why it is hard to restrict without breaking accessibility for the people who rely on it.

Google is adding friction here, but not yet in India. Developer verification for sideloaded apps begins on September 30, 2026, in Brazil, Indonesia, Singapore and Thailand. Apps from unregistered developers will face an installation flow that includes a mandatory 24-hour wait and multiple confirmation steps. India is not in that first wave. Google plans to expand the requirement globally across certified Android devices in 2027.

So for the next year, in one of the world’s largest Android markets, the install path this campaign relies on stays as frictionless as it is now.

Questions MediaNama has sent to Meta

  • Were the 39 advertisements identified by Reuters removed as a result of the I4C advisory of August 26, or as a result of the press query?
  • Did Meta receive the advisory, and what action followed?
  • How did ads for the named apps — Night Play, Reloop, Kyss, Vimo, Rivo, Nexo and Vixa — clear ad review?
  • Does the 95% fraud-certainty threshold reported by Reuters still govern advertiser bans, and does it apply to advertisers in India?
  • Are advertisers suspected of fraud below that threshold still charged higher rates rather than removed?
  • Were the anti-scam tools announced in March 2026 applied to this campaign?
  • How many advertising accounts linked to this campaign have been disabled, and how many ads were served in India before removal?

Questions MediaNama has sent to MeitY and I4C

  • Was a takedown notice issued to Meta under the Information Technology Act in respect of these advertisements, or only an advisory?
  • If only an advisory, why was no notice issued given that the ads remained live?
  • How many people have reported losses linked to this campaign, and what is the reported loss figure?
  • Following the July summons over child sexual abuse material ads, has any compliance action been taken against Meta?

Meta, MeitY and I4C had not responded at the time of publication. This story will be updated if they do.

Also read:



Click Here For The Original Source.

——————————————————–

..........

.

.