I4C Issues Major Warning Over Android Malware Hidden Behind Instagram and Facebook Ads
I4C warns Android users about malicious apps promoted through Instagram ads that can steal data, misuse permissions and enable financial fraud through APK scams.
An Instagram ad may appear harmless, but a single wrong click could put your Android phone and finances at risk. The Indian Cyber Crime Coordination Centre (I4C) has warned users about malicious Android apps being promoted through Facebook and Instagram ads, including apps disguised as entertainment or adult-content services.
According to the I4C advisory, the National Cybercrime Threat Analytics Unit (NCTAU) has observed an increase in financial fraud associated with these apps. The malicious software is promoted through social media advertisements and can redirect users to websites that ask them to download an Android APK file from outside the official app store.
The scam often begins with an attractive advertisement on Instagram or Facebook. After clicking the ad, users may be redirected to a website offering adult or entertainment content. The website then prompts the user to download an APK, a file that allows Android apps to be installed outside the usual app store. Once installed, the app may request access to sensitive permissions.
One of the biggest red flags is a request for Accessibility permission. If granted, this permission can give a malicious app extensive control over the device. It may allow the app to perform actions in the background, install additional apps, or access sensitive information. In some cases, the malware may also install a VPN and route the device's internet traffic through servers controlled by attackers. Certain malicious apps can even make themselves difficult to remove.
The ultimate objective may be financial fraud, with criminals using control of the compromised device to steal sensitive information or carry out unauthorised transactions.
I4C and cybersecurity experts recommend downloading apps only from trusted sources such as the Google Play Store. Avoid installing APK files provided through suspicious advertisements, websites, messages, or unknown links. Be particularly cautious if an unfamiliar app requests Accessibility, SMS, screen-reading, device administrator, or permission to install other applications. These permissions can give an app significant control over an Android device.
Users should also keep Google Play Protect enabled and regularly update both their Android devices and installed apps. Checking which apps have sensitive permissions and removing anything unfamiliar can provide another layer of protection.
Unusual battery drain, unexpected heating, unfamiliar advertisements, or other unexplained changes in phone behaviour could also indicate the presence of Android malware.
If you suspect that your phone has been compromised, disconnect it from the internet and stop using it for banking activities immediately. Disable suspicious Accessibility, VPN, and device administrator permissions, and then try removing the app through Safe Mode. If an unauthorised transaction has already taken place, contact your bank immediately and report the incident through the National Cyber Crime Reporting Portal or 1930. You should also change important passwords using a trusted device. If the malicious app cannot be removed, back up essential data and consider performing a factory reset.
The safest approach is straightforward: never install an APK simply because an advertisement or website tells you to. Even an app that looks legitimate can contain dangerous malware designed to steal your personal information or money.
Information referenced in this article is from The Indian Express