Meta Takes Down 39 Dangerous Adult-App Ads After India Warns of Malware and Online Scams

Meta has removed dozens of advertisements from Facebook and Instagram that were allegedly promoting fake adult-content applications. The action came after the Indian government raised concerns that these advertisements could be used to distribute malware, conduct phishing attacks and steal sensitive information from users' smartphones.

The advertisements reportedly used provocative video thumbnails to attract users before redirecting them to suspicious websites. Visitors were then encouraged to download Android APK files, potentially exposing their devices and personal information to cybercriminals.

Government Flagged the Threat to Meta

According to a Reuters report, the Indian government alerted Meta about advertisements promoting apps and services using names such as Night Play and Kiss.

The ads allegedly directed users to phishing websites through adult-themed content. Once there, users were encouraged to download files outside official app stores.

The government warned that malicious applications could potentially gain access to sensitive information stored on smartphones, including one-time passwords (OTPs), banking credentials and PINs.

Home Ministry Warns About Suspicious APK Files

The government's advisory reportedly mentioned several app names, including Night Play, Reloop, Kiss, Vimo, Rivo, Nexo and Vixa. Authorities also cautioned that criminals could use modified versions or similarly named applications to distribute malware.

A particularly risky practice is downloading an APK directly from a website after clicking an advertisement.

Some of these malicious applications may ask users to install additional packages by pretending they are updates. In certain cases, they may even attempt to install VPN-related software that could potentially route internet traffic through infrastructure controlled by attackers.

Why Accessibility Permissions Are Dangerous

One of the biggest concerns is the misuse of Android accessibility permissions.

Accessibility services are legitimate Android features designed primarily to help people with disabilities interact with their devices. However, if malicious software gains access to these permissions, it may obtain extensive control over certain functions of the phone.

Cybercriminals could potentially abuse such access to monitor activity, interact with applications and facilitate financial fraud.

For this reason, users should be extremely cautious when an unfamiliar application asks for accessibility access, particularly if there is no genuine reason for the app to require it.

What If a Suspicious App Cannot Be Uninstalled?

Some malicious applications may attempt to make removal more difficult. If an unfamiliar app refuses to uninstall through the normal settings or appears again after the phone is restarted, users should treat the situation seriously.

The government's guidance recommends backing up important personal data and considering a factory reset if a malicious application cannot be removed through normal methods.

Users should also change important passwords and monitor their financial accounts if they suspect that sensitive information may have been compromised.

Reuters Found 39 Ads on Meta Platforms

Reuters reportedly identified at least 39 advertisements promoting such suspicious services on Facebook and Instagram even after the government advisory had been issued.

Several of the advertisements reportedly used thumbnails resembling adult videos to attract clicks.

After Reuters contacted Meta about the advertisements, the company removed them from its platforms. Meta reportedly did not provide a response to Reuters' questions regarding the specific advertisements.

One Ad Promoted a File Called Movexa.apk

One advertisement reviewed by Reuters reportedly redirected users to a website claiming to provide access to a large collection of adult videos.

Instead of directing users to an official app store, the website asked them to download an Android file named Movexa.apk.

This is a major warning sign. APK files downloaded directly from unknown websites can bypass the security checks and safeguards users may receive when installing applications through official app stores.

The Indian government has warned that malicious applications of this kind could potentially compromise personal information, intercept OTPs or banking details and facilitate unauthorised financial transactions.

Meta's Policies Also Prohibit Such Ads

Meta's advertising rules prohibit advertisements containing adult nudity or sexual activity. Its policies also prohibit content intended to deceive, defraud or scam users.

The appearance of these advertisements despite those restrictions highlights the difficulty of completely preventing malicious campaigns from reaching online platforms.

How Users Can Stay Safe

To reduce the risk of falling victim to such scams, users should:

  • Avoid downloading APK files from advertisements, random websites or unknown links.

  • Install applications through Google Play Store or other trusted app stores.

  • Never grant accessibility permissions to an unfamiliar app without a legitimate reason.

  • Be suspicious of websites demanding an app download to access videos or other content.

  • Avoid clicking on sensational advertisements promising free or exclusive content.

  • Keep the phone's operating system and security software updated.

  • If an unfamiliar application behaves suspiciously, remove it and consider seeking professional technical assistance.

The key lesson is simple: an attractive advertisement does not mean the app or website behind it is safe. When an online ad pressures you to download an APK from an unknown source, it is better to close the page than risk exposing your phone and financial information.