
Cyber Security
Meta Removes 39 Malware Ads After Reuters Finds Them Live Following India Alert
Updated on Tue, Sep 1, 2026
Meta removed dozens of Facebook and Instagram advertisements promoting malicious Android apps in India after authorities warned that the apps could steal banking information, intercept security codes and potentially transfer money from victims’ accounts without their knowledge.
The development became more concerning when Reuters found dozens of similar advertisements still active after the government warning.
TL;DR
- Indian authorities warned users about malicious Android apps promoted through Facebook and Instagram ads.
- The apps could steal banking credentials, PINs and one-time passwords.
- Reuters found 39 related advertisements still active after the government advisory.
- Meta removed the ads after Reuters contacted the company.
- India recorded nearly $2.4 billion in cyber-fraud losses during 2025.
India has warned users about a wave of malicious Android applications being promoted through Facebook and Instagram advertisements, with attackers using sexually explicit content to lure people into downloading software capable of compromising their banking information.
Meta subsequently removed dozens of the advertisements, but the sequence of events raised questions about how effectively the company's advertising systems detect potentially dangerous campaigns.
Reuters found 39 ads still running after the Indian government issued its advisory, with Meta removing those advertisements after the news agency contacted the company.
The Next Web highlighted the same sequence, noting that Meta removed the remaining advertisements after being approached about them. The ads were removed after two warnings.
How Did The Malware Target Banking Users?
The advertisements promoted Android applications masquerading as pornography apps under names including "Night Play" and "Kyss."
Users who clicked the advertisements were directed to phishing websites where they could download APK files outside official application stores.
Once installed, the malicious applications could access information stored on users' devices, including banking credentials.
More importantly, the malware could capture one-time passwords and banking PINs, security measures typically designed to prevent unauthorized transactions even when account credentials have been compromised. The apps could steal banking credentials.
The applications could then potentially transfer money from a victim's bank account without their knowledge.
The technique highlights the risk of sideloading Android applications from unknown websites, particularly when advertisements direct users away from official app stores.
Why Are The 39 Advertisements Significant?
The advertisements themselves make this more than a conventional malware-distribution story.
Instead of relying only on phishing emails, obscure websites or private messaging groups, the malicious applications were promoted through paid advertising on Meta's Facebook and Instagram platforms.
India had already issued an advisory about the campaign when Reuters found 39 advertisements still active.
Those 39 ads remained publicly available after authorities had warned about the same type of malicious application.
Meta removed them after Reuters contacted the company.
The company did not respond to Reuters' questions about its findings.
The Next Web argued that this sequence places greater scrutiny on Meta's advertising moderation because the company both operates the advertising platform and maintains the systems responsible for detecting abusive advertisements. Meta's advertising enforcement faces renewed scrutiny.
However, there is no evidence suggesting that Meta intentionally sought to distribute banking malware.
The central question instead concerns how quickly its systems identify malicious advertisements and why similar campaigns remained active after authorities had already highlighted the threat.
Topics For More Insights
India Lost Nearly $2.4 Billion To Cyber Fraud
The incident comes amid growing concern surrounding financial cybercrime in India.
Indians lost nearly $2.4 billion to cyber fraud during 2025, according to government data cited by Reuters. India recorded major cyber-fraud losses in 2025.
India is also one of Meta's largest markets, making the effectiveness of Facebook and Instagram's advertising enforcement particularly important for users in the country.
The malicious campaign also demonstrates how attackers can abuse sensitive or embarrassing content to discourage victims from quickly reporting fraud.
Someone who knowingly downloaded an app presented as pornography, for example, may hesitate to report the incident immediately, potentially giving attackers more time to exploit compromised information.
What Is Meta Doing About Scam Ads?
Meta says it has been increasing its efforts to detect fraud and scam campaigns across its platforms.
In March 2026, the company said it removed more than 159 million scam advertisements worldwide during 2025, with 92% removed before users reported them.
In India specifically, Meta said it banned more than 12.1 million pieces of advertising content for violating its policies against fraud, scams and deceptive practices, with more than 93% removed proactively. Meta says millions of scam ads were removed.
The company also said it removed 10.9 million Facebook and Instagram accounts connected to criminal scam centers during the year.
Meta has introduced additional anti-scam tools across Facebook, Messenger and WhatsApp, while also working with law-enforcement authorities and financial regulators.
It has also partnered with India's Indian Cyber Crime Coordination Centre and Securities and Exchange Board of India on its "Scams se Bacho" awareness campaign.
Still, the latest incident suggests that automated enforcement systems can miss malicious campaigns even after the broader attack pattern has been identified.
For Facebook and Instagram users, the immediate takeaway remains straightforward: advertisements appearing on major social platforms should not automatically be treated as proof that an application or website is trustworthy.
Users should avoid downloading APK files from unknown websites, particularly when an advertisement directs them outside an official app store, and should be cautious about applications requesting access to SMS messages, banking information or other sensitive device permissions.
First published on Tue, Sep 1, 2026
Enjoyed what you've read so far? Great news - there's more to explore!
Stay up to date with the latest news, a vast collection of tech articles including introductory guides, product reviews, trends and more, thought-provoking interviews, hottest AI blogs and entertaining tech memes.
Plus, get access to branded insights such as informative white papers, intriguing case studies, in-depth reports, enlightening videos and exciting events and webinars from industry-leading global brands.
Dive into TechDogs' treasure trove today and Know Your World of technology!
Disclaimer - Reference to any specific product, software or entity does not constitute an endorsement or recommendation by TechDogs nor should any data or content published be relied upon. The views expressed by TechDogs' members and guests are their own and their appearance on our site does not imply an endorsement of them or any entity they represent. Views and opinions expressed by TechDogs' Authors are those of the Authors and do not necessarily reflect the view of TechDogs or any of its officials. While we aim to provide valuable and helpful information, some content on TechDogs' site may not have been thoroughly reviewed for every detail or aspect. We encourage users to verify any information independently where necessary.
Loading comments...

