Meta removes dozens of India ads tied to banking malware

  • Meta removed dozens of Facebook and Instagram ads promoting malicious Android applications.
  • Reuters found at least 39 ads active after India issued its government advisory.
  • NCTAU warned the applications could capture bank credentials and transfer money without users’ knowledge.

Meta removed dozens of Facebook and Instagram advertisements after India’s National Cyber Threat Analytics Unit warned that promotions under names including Night Play and Kyss were steering users toward malicious Android applications disguised as pornography apps. The campaigns directed users to phishing websites and, in some cases, direct downloads of APK files outside official app stores. Reuters identified at least 39 ads still active after the advisory and alerted Meta, which removed them shortly afterward. The applications could access phone data, capture one-time passwords and bank PINs, and transfer money without users’ knowledge; some could also install a virtual private network that routed device traffic through attacker-controlled servers. India recorded nearly $2.4 billion in cyber-fraud losses in 2025. The episode follows India’s direction to Google to shut down hundreds of Firebase accounts used to impersonate major banks, while Meta had internally projected scam and banned-goods advertising would generate about $16 billion, or 10% of 2024 revenue. Meta shares closed at $572.34 on Monday, down 0.98%, while India also temporarily restricted access to Telegram in June over allegations involving leaked National Eligibility-cum-Entrance Test question papers.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.