Skip to content
Meta Removes Malware-Laced Porn Ads After India Flags $2.4 Billion Fraud Threat

Meta Removes Malware-Laced Porn Ads After India Flags $2.4 Billion Fraud Threat

Finance.Biggo • September 1, 2026

The takedown followed an advisory from India's National Cyber Threat Analytics Unit (NCTAU), which warned that fraudulent apps operating under names including "Night Play" and "Kyss" were being through social media ads. The apps directed users to phishing sites and, in some cases, installed VPN software that routed device traffic through attacker-controlled servers.

India recorded nearly $2.4 billion in cyber-fraud losses in 2025, according to government data, as criminal operators increasingly target the country's booming digital-payments ecosystem. The advisory marked the second time in recent weeks that New Delhi has confronted a major technology platform over financial fraud — the government previously directed Google to shut down hundreds of Firebase accounts used to impersonate major banks.

Reuters identified at least 39 ads still running after the advisory was issued on Monday. Many featured explicit video thumbnails designed to drive clicks. Meta removed all of them shortly after being contacted for , though the company did not respond to queries.

One active ad led to a website promoting a video application that promised hundreds of pornographic videos and around-the-clock content. Access required downloading a file named "Movexa.apk" directly from outside an official app store — a hallmark of sideloading that bypasses Google Play's security screening.

How the Malware Operates

According to the NCTAU warning, the malicious applications can request broad permissions after installation, granting them extensive control over an Android device. The agency flagged the VPN component as particularly concerning because it allows attackers to monitor or redirect internet traffic, potentially exposing data transmitted from the phone.

The malware can also secretly access information stored on victims' phones, capture one-time passwords and bank PINs, and transfer money from accounts without the owner's knowledge, India's advisory stated. The risk escalates when users grant unfamiliar applications sweeping permissions simply to access promised content.

Meta's advertising policies explicitly prohibit adult nudity and sexual activity, as well as ads using "identified deceptive or misleading practices" intended to defraud users. The company has said it is cracking down on such content, even as internal projections reported last year indicated that scam and banned-goods advertising would generate roughly 10% of its 2024 revenue — approximately $16 billion.

Recommendations for Android Users

Anyone who has installed a suspicious application should remove it immediately and check their device for unusual activity. Those who notice unauthorized financial transactions should their bank and report the incident to India's cybercrime helpline at 1930.

The episode underscores a persistent challenge for Meta as it balances advertising revenue against content moderation. While the company removed the flagged ads after being alerted, the fact that dozens remained active following the government advisory highlights the difficulty of policing a platform where malicious actors continuously adapt their tactics to evade detection.

Once added, BigGo Finance appears first in Google Top Stories, so you get the broadest, most up-to-the-minute, and most comprehensive global financial news first.

Extracted Entities

Attack Types (2)

Countries (1)

Industries (1)

Malware (2)

MITRE ATT&CK (1)