
The XHelper malware, which affects devices running the Android, was first discovered in October 2019.
XHelper is particularly persistent, since once installed on the device, it remains active even if the user deletes it and performs a factory reset.
Android XHelper Malware
The malicious actors presented the XHelper malware as a device cleaning and speeding application. However, it does not have any such functionality.
Once the app on a victim's device, it simply disappears from the main screen or application menu.
Then, a server controlled by the attacker downloads the second malicious component, “Trojan-Dropper.AndroidOS.Agent.of” which decrypts the payload using the native library.
The next dropper is “Trojan-Dropper.AndroidOS.Helper.b”, which launches “Trojan-Downloader.AndroidOS.Leech.p” for further infection.
Leech.p downloads “HEUR: Trojan.AndroidOS.Triada.dd”, which exploits vulnerabilities to escalate privileges on the victim’s device.
“Malicious files are sequentially stored in the application, which is inaccessible to other programs. This allows malware authors to hide their tracks and use malicious modules known to security solutions,” Kaspersky.
The XHelper malware adds a number of files to the /system/bin and adds requests to install recovery.sh which causes Triada.dd to run at system.
Some users reported that they disabled XHelper activity by disabling permissions and locking it using software . Others reported that they “tried to deny permissions to XHelper without uninstalling it, but it re-enabled all permissions.”
