An advertisement appearing on Facebook or Instagram can look legitimate. The link it opens may even use infrastructure belonging to a well-known technology company.
Neither detail guarantees that the application being promoted is safe.
Indian authorities have identified Android banking-fraud campaigns that combine social-media advertisements, convincing phishing pages and malicious APK files. Some operations have also used Google’s Firebase platform to host deceptive pages or receive information stolen from infected phones.
The services themselves are legitimate. The danger comes from criminals misusing them to make malicious links appear more trustworthy.
Here is how the attack works, which warning signs Android users should recognise and what to do if a suspicious application has already been installed.
The scam often begins with an ordinary-looking advertisement
A recent Indian government advisory warned about malicious Android applications promoted through Facebook and Instagram advertisements.
According to a Reuters investigation, some advertisements used adult-content themes to persuade people to visit external websites and download applications unavailable through an official app store. Meta removed dozens of the reported advertisements after they were flagged.
Other campaigns may use different bait, including:
credit-card offers;
reward-point redemption;
credit-limit increases;
government-benefit claims;
urgent account-verification warnings;
investment or loan offers;
free entertainment applications.
The subject can change, but the objective is usually the same: persuade the victim to leave the trusted platform and install an APK file manually.
A paid advertisement is not necessarily an endorsement from Facebook, Instagram or another platform. Advertising systems process enormous volumes of content, and malicious advertisers may disguise their actual destination or replace it after approval.
Why a cloud-hosted link can appear trustworthy
Scammers sometimes host phishing pages or supporting infrastructure using legitimate cloud-development services.
In August 2026, India’s Cyber Crime Coordination Centre reportedly directed Google to remove numerous Firebase-hosted websites and databases associated with Android malware and bank-impersonation schemes.
A separate Reuters report on the Firebase campaign said at least 57 sites and databases were identified for removal during August. Some pages allegedly copied the appearance of major Indian banks, while other databases received information collected from infected phones.
Firebase is a legitimate Google platform used by developers to build applications and websites. Its appearance in a URL does not mean Google created, reviewed or endorsed the page.
The same principle applies to other familiar services. A website can use HTTPS, display a padlock and operate from a recognisable cloud domain while still containing a phishing form or malicious download.
The padlock only indicates that the connection between the browser and website is encrypted. It does not prove that the person operating the website is trustworthy.
How the complete attack chain works
Although individual campaigns differ, a typical Android banking-malware attack can be divided into seven stages.
1. The criminal creates an attractive or urgent offer
The campaign may promise free content, a bank reward, a government payment or an account upgrade. Urgency is frequently used to prevent users from examining the offer carefully.
2. The offer is promoted through a familiar platform
The victim encounters the link inside a social-media advertisement, message, search result or forwarded post.
Because the link arrived through a widely used service, the user may assume it has already been checked.
3. The link opens a convincing external website
The landing page may display copied bank logos, customer-support language or familiar colours. It may also use a legitimate cloud-hosting domain to appear more credible.
Users should examine the complete address, not merely the logo, padlock or first recognisable word in the URL.
4. The website asks the user to download an APK
Instead of opening the Google Play Store, the page downloads an Android Package Kit directly.
Android may then ask the user to permit the browser, messaging app or file manager to “install unknown apps.” This warning is an important security boundary.
A bank should not require customers to install an account update from an APK sent through an advertisement, SMS, WhatsApp message or unofficial website.
5. The application requests powerful permissions
After installation, the fake app may request access to:
One permission may have a legitimate purpose. A combination of unrelated permissions is a stronger warning sign.
Accessibility access is especially sensitive because it can allow an application to read screen content, press buttons or interact with other apps on the user’s behalf.
6. Information is collected or transactions are manipulated
A malicious app may imitate a bank login screen, read incoming OTP notifications, capture information entered by the victim or send device data to a remote server.
The Reuters investigation reported that authorities warned of applications capable of obtaining banking credentials, OTPs and PINs or initiating transactions without the victim’s knowledge.
Users should never share a PIN, password, CVV or OTP merely because an app claims that verification is required.
7. The criminal tries to delay discovery
The fake application may hide its icon, prevent easy removal, suppress notifications or display errors while continuing to operate in the background.
A victim may only notice the compromise after seeing an unfamiliar transaction, login alert or change to a bank account.
Five checks to make before installing an Android app
Use the bank’s official channel
Open your bank’s website by entering its address yourself or use an app already installed from its verified Google Play listing.
Do not install an application using a download link received through an advertisement, message or phone call.
If uncertain, contact the bank using the number printed on the card, statement or official website. Do not call a number displayed on the suspicious page.
Confirm where the download opens
A legitimate Android banking app should normally open inside Google Play.
If tapping “Install” downloads a file ending in .apk, stop unless you deliberately requested an APK from a developer you independently trust.
The presence of a well-known company’s name elsewhere on the page does not make the file safe.
Examine the developer and listing history
On Google Play, check:
the complete developer name;
the developer’s official website and support address;
the number and quality of reviews;
download history;
requested data access;
the date of the latest update.
Scammers can copy an app’s name and icon. The developer identity and official bank website provide stronger evidence.
Review permissions in context
A banking app may reasonably need notifications or camera access for document scanning. It should not require unrestricted Accessibility control merely to show an account balance.
Android users can review access under Settings → Security and privacy → Privacy → Permission manager. Menu names may differ slightly by manufacturer.
Keep Google Play Protect enabled
Google Play Protect checks applications during installation and periodically scans installed apps. Google says it may warn about, disable or remove an application identified as potentially harmful. It can also request a cloud-based scan of an unfamiliar app installed outside Google Play.
To run a manual scan:
Open the Google Play Store.
Tap your profile picture.
Select Play Protect.
Tap Scan.
Play Protect adds an important layer of defence, but it cannot guarantee that every newly created malicious app will be detected immediately.
Warning signs after an app has been installed
Check the phone carefully if a recently installed application:
requests Accessibility or device-administrator access;
asks you to disable Play Protect;
demands an OTP, UPI PIN, card PIN or CVV;
opens over other applications;
causes bank or SMS notifications to disappear;
installs without appearing in the normal app drawer;
makes the phone unusually warm or drains the battery rapidly;
triggers unknown login alerts or transactions.
One symptom does not automatically prove that malware is present. Several appearing immediately after an unfamiliar APK installation should be treated seriously.
What to do if you installed a suspicious APK
First, disconnect the affected phone from Wi-Fi and mobile data. Do not use it to log into banking, email or payment accounts.
Using another trusted device:
Contact the bank through its official number.
Ask the bank to block or monitor affected cards and accounts.
Change important passwords, beginning with email and financial accounts.
Review recent banking and UPI transactions.
Inform the mobile operator if the SIM unexpectedly loses service.
Report financial cyber fraud immediately.
Victims in India can call the national cybercrime helpline at 1930 and file a complaint through the government’s National Cyber Crime Reporting Portal. The official portal specifically directs victims of financial cyber fraud to use 1930 for immediate reporting.
The Reserve Bank of India advises customers to notify their bank immediately after noticing an unauthorised electronic transaction. Reporting quickly may help limit further loss and is relevant when liability is assessed.
How to remove the suspicious application safely
If the app can be removed normally, open Settings → Apps, select it and tap Uninstall.
If uninstalling is blocked, first check whether it has device-administrator or Accessibility access and revoke that access. Menu names vary, so use the Settings search function for “Device admin apps” and “Accessibility.”
After removing it:
run a Play Protect scan;
install all available Android and Google Play system updates;
review permissions granted to other unfamiliar apps;
check whether unknown payment or remote-control apps remain;
continue monitoring bank accounts and login alerts.
If the app had extensive device control, sensitive information was entered or suspicious behaviour continues, backing up essential photographs and documents before performing a factory reset may be the safest option. Avoid restoring the suspicious APK from a backup.
A trusted-looking link is not the same as a trusted app
These campaigns work because each step borrows credibility from something familiar: a social platform, an advertisement, a cloud domain, a bank logo or Android itself.
Users do not need to become security experts to break the chain. The most effective rule is simple:
Do not install banking, reward, government-benefit or entertainment APKs promoted through advertisements or unsolicited links.
Open the organisation’s official website or verified Google Play listing independently. Keep Play Protect enabled, question unrelated permissions and contact the bank immediately if financial information may have been exposed.
A few minutes spent verifying an application can prevent criminals from gaining access to the phone that holds messages, passwords, OTPs and payment accounts.