Meta Removes Malware Ads on Facebook, Instagram After India Flags Them
Meta removed dozens of Facebook and Instagram ads that used explicit content to trick Indian users into installing banking malware.
Scam operators have learned that the fastest way to drain a bank account is not through brute-force hacking, but through seduction. On Monday, Meta removed dozens of advertisements from Facebook and Instagram after India's government flagged a campaign using sexually explicit thumbnails to trick users into installing malicious Android apps. The apps, masquerading as pornography platforms, were designed to silently harvest banking credentials and one-time passwords from Indian users.
According to an advisory issued by the government, ads operating under names like "Night Play" and "Kyss" directed users to phishing websites. From there, victims were prompted to download APK files — Android application packages distributed outside official app stores — that could access stored phone data, capture PINs, and transfer money without the owner's knowledge. India's digital payments surge has made this vector increasingly lucrative: the country recorded nearly $2.4 billion in cyber-fraud losses in 2025.
How the Scam Worked
The mechanics were straightforward but effective. Clicking an ad led to a website promising hundreds of pornographic videos. To access the content, users had to download a file named "Movexa.apk" directly, bypassing Google Play's security screening entirely. This technique, called sideloading, is common in India where users often seek content unavailable through official channels. When you sideload an app, you disable the very systems built to catch malware before it reaches your phone.
Once installed, the malware could:
- Secretly read information stored on the device
- Capture one-time passwords (OTPs) and bank PINs in real time
- Initiate unauthorized fund transfers from linked accounts
- Operate in the background without visible indicators
Reuters found at least 39 such ads still active after the government advisory was issued. Meta removed them only after Reuters flagged the remaining ads to the company directly. The platform had not responded to government queries at the time of removal.
India's Regulatory Response and the Bigger Picture
This is the second major intervention by Indian authorities against a global tech platform in recent weeks. The government previously directed Google to shut down hundreds of Firebase accounts being used to impersonate major banks. The pattern suggests that the Ministry of Electronics and Information Technology (MeitY) is moving from reactive takedowns to proactive disruption of the infrastructure that enables financial fraud at scale.
For Indian users, the incident carries a sharp lesson about sideloading. While Android allows installing apps from outside the Google Play Store by default, each sideloaded APK bypasses Google's Verify Apps system, which scans for known malware signatures. The government's advisory effectively treats this as a consumer protection issue, not merely a platform moderation failure.
The apps could secretly access information stored on users' phones, capture one-time passwords and bank PINs, and transfer money from accounts without the owner's knowledge.
From a regulatory standpoint, the incident lands in a crowded field. The Digital Personal Data Protection (DPDP) Act, 2023, which came into force in 2024, places obligations on data fiduciaries to protect user data. While Meta's ad review systems are not directly regulated under the DPDP Act, the law's emphasis on consent and data security creates pressure for platforms to tighten vetting. Meanwhile, the Reserve Bank of India's recurring warnings about digital payment fraud — and its push for multi-factor authentication — highlight the gap between platform-level accountability and user-level protection.
Why Meta's Ad Review Keeps Missing the Mark
Meta's own policies explicitly prohibit ads containing "adult nudity and sexual activity" and ban "deceptive or misleading practices" intended to scam users. Yet the ads slipped through. This is not an isolated oversight. Reuters reported last year that Meta had internally projected scam and banned-goods advertising would generate roughly 10% of its 2024 revenue — about $16 billion — even as the company publicly claims to be cracking down.
The tension is structural. Meta's ad auction system rewards engagement, and explicit content drives clicks. When automated review systems — which rely on machine learning to flag violations — encounter novel scams that blend legitimate-looking landing pages with malicious backend behavior, detection lags behind deployment. For Indian regulators, the question is whether voluntary takedowns after media exposure are sufficient, or whether the IT Rules, 2021, need sharper teeth for intermediary liability in advertising.
Indian developers and security researchers have a role here too. The malware's reliance on sideloading suggests that user education alone will not close the gap. Better integration between platform ad review and mobile security ecosystems — perhaps through real-time APK scanning partnerships with Indian cybersecurity firms — could catch these threats before they reach users. Until then, the safest advice remains unchanged: if an app asks you to disable security settings to install it, the price of that video is probably your savings account.
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Angry
0
Sad
0
Wow
0