Users may also need to disable Accessibility access and remove device: A practical reader guide

Users may also need to disable Accessibility access and remove device: A practical reader guide

Malicious Android applications masquerading as pornography apps are increasingly being used by cybercriminals to take control of users’ mobile phones and carry out unauthorised financial transactions, the Union home ministry’s Indian Cyber Crime Coordination Centre (I4C) warned.

Once installed, the malicious application seeks sensitive permissions, including Accessibility access. If the user grants these permissions, the malware gains control over the device and continues running in the background. The malware may also download and install a secondary application by disguising it as an update to the original app. In some cases, the malicious applications install a virtual private network (VPN), routing the user’s internet traffic through attacker-controlled servers.

This could expose transmitted data to further misuse, the advisory said.

The cybercrime unit recommended regularly reviewing installed applications and removing those that are not recognised, while keeping Google Play Protect enabled and the Android operating system updated. The apps may also attempt to prevent users from uninstalling them through normal device settings, making removal more difficult. Users have also been advised against granting Accessibility permissions to unfamiliar applications. For devices already compromised, the advisory suggests restarting the phone in Safe Mode and uninstalling suspicious or unknown applications. Users may also need to disable Accessibility access and remove device administrator privileges granted to malicious apps. If an application cannot be removed or reappears after restarting, users have been advised to back up important data and consider a factory reset.