Fraudulent apps exploit interest in an alleged adult version of TikTok
Smartphone users in Japan are being warned about a growing cybercrime campaign in which malicious applications posing as TikTok can take control of devices and enable unauthorized money transfers through PayPay, one of the country’s most widely used cashless payment services.
PayPay says reports from customers claiming that money was sent without their knowledge increased sharply from August. Investigations have confirmed cases in which victims installed applications carrying names such as “TikTok 18+,” believing they could access adult-oriented video content. The applications were not official TikTok products. Instead, they infected smartphones with malware and allowed criminals to control the devices remotely.
Once installed, the malicious software can reportedly interfere with smartphone operations and facilitate transfers to third parties through the victim’s PayPay account. PayPay is urging customers to check their transaction histories carefully and look for unfamiliar applications installed on their devices.
How the scam reaches smartphone users
According to warnings from PayPay and cybersecurity experts, victims are often directed to fraudulent app stores through social media advertisements, emails, or other online messages. The links may be designed to look legitimate and can use attention-grabbing offers or adult-content claims to persuade users to download software outside official app marketplaces.
Cybersecurity company Trend Micro, based in Tokyo, says it has identified multiple malicious applications impersonating an adult version of TikTok. The company warns that the risks go beyond financial losses. After installation, attackers may be able to remotely operate many functions on a smartphone, including placing calls, sending messages or emails to contacts, and activating the camera.
Masaya Takahashi, a senior specialist at Trend Micro, advised users to delete suspicious applications immediately and to obtain apps only through official app stores. However, experts also stress that users should carefully check the developer name, reviews, download numbers, permissions, and the app’s official website, since fake applications can sometimes appear convincing.
Fake Rakuten apps also target account credentials
A separate campaign involving fraudulent applications impersonating Rakuten has also been detected in Japan. According to Rakuten and the Anti-Phishing Council, victims may receive emails or text messages claiming that they have won a prize, earned Rakuten Points, or received a coupon. The messages then direct them to a fake app store, where they are encouraged to install an application resembling an official Rakuten Points app.
Trend Micro’s analysis found that the fraudulent Rakuten application asks users to enter their Rakuten ID and password during login. Those credentials can then be stolen and potentially reused by criminals to access accounts or conduct further fraud.
What users should do
People who suspect they have installed a malicious application should avoid entering additional passwords or payment information, disconnect the device from the internet if necessary, and seek assistance from their mobile carrier, the relevant payment provider, or a cybersecurity professional. They should also review payment and account activity, change passwords from a trusted device, enable multi-factor authentication where available, and report suspected fraud to the police or appropriate consumer-protection authorities.
PayPay says eligible victims may receive compensation of up to the full amount of their loss, depending on the circumstances and the details of the case. Users should contact the company promptly and preserve evidence, including suspicious messages, application names, transaction records, and website addresses. The incident highlights the importance of Japan’s shift toward cashless payments while underscoring a basic digital-safety rule: attractive offers from unofficial sources can carry serious risks.