NEW DELHI, INDIA — Meta removed dozens of Facebook and Instagram advertisements after Indian cybercrime authorities warned that malicious Android downloads promoted as adult-content apps could expose users to financial fraud.
Meta removed the advertisements on Monday after Indian authorities identified a scheme in which social-media promotions directed users away from official app stores and toward Android Package Kit, or APK, downloads capable of obtaining powerful permissions on a device.
The platform action is a new development following the Indian government warning. Reuters reported that it found at least 39 advertisements still active after the advisory and that Meta removed them after the news organization brought the ads to the company’s attention.
India’s National Cybercrime Threat Analytics Unit, part of the Indian Cyber Crime Coordination Centre under the Ministry of Home Affairs, said malicious applications were being promoted through Facebook and Instagram under names including “Night Play,” “Reloop,” “Kyss,” “Vimo,” “Rivo,” “Nexo” and “Vixa,” as well as similar variants. The advisory was dated August 26, according to Indian reporting on the document.
The government’s Akashvani News service said the advertisements sent users to websites where they were encouraged to install APK files from outside Google Play. Once installed, the applications could request Accessibility access and other sensitive permissions that may allow an attacker to control parts of the device or facilitate financial fraud.
Some applications could also download additional packages presented as updates, install a virtual private network capable of routing internet traffic through attacker-controlled infrastructure and interfere with attempts to uninstall the software, according to the government warning.
Meta removed ads after they remained visible following the warning
Reuters said it located at least 39 advertisements that remained active after the government warning became public. Many used sexually explicit imagery to attract clicks, and at least one directed users to a site offering an APK file outside an official application store. Meta removed the advertisements shortly after Reuters contacted the company about them.
Meta did not respond to Reuters’ questions about the advisory, according to the news agency. The available reporting therefore does not establish whether Meta also disabled the advertisers’ accounts, blocked related domains or APK files, or introduced broader enforcement measures against the campaign.
Meta’s own published guidance says it does not permit the dissemination of spyware, malware or software that creates an unexpected or deceptive experience, including links to sites containing such software. Its Ad Library also provides a searchable record of advertisements running across Meta technologies, although its coverage and retention rules vary by advertisement category and jurisdiction.
The gap between the government warning and the continued presence of ads documented by Reuters makes Meta’s subsequent takedown the central platform-enforcement development in the case.
Indian authorities urge users to avoid APK downloads from advertisements
Indian authorities advised users to install applications only through Google Play or other trusted app stores, avoid downloading APK files through advertisements, websites or suspicious links, and refuse Accessibility access to unfamiliar applications.
The advisory also recommended checking that a suspicious application has been completely removed. If it cannot be uninstalled or reappears after a restart, users were advised to back up important information and consider a factory reset.
Reuters reported, citing Indian government data, that cyber-fraud losses in the country approached $2.4 billion in 2025. That national figure covers cyber fraud broadly and should not be interpreted as losses attributable to the applications identified in this specific campaign.
The government warning describes the identified software as capable of compromising sensitive information and enabling unauthorized financial activity, but the evidence reviewed does not establish that every advertised application caused a financial loss or that every person who downloaded one had money stolen.
Further information from Meta and Indian investigators — including the number of affected users, whether advertiser accounts were permanently disabled and the value of any losses directly linked to the identified applications — has not been publicly established in the sources reviewed.
More from this section
Technology- Loading related stories…
