HomeYoutubeNoVoice: New Android malware on Google Play

NoVoice: New Android malware on Google Play

A highly sophisticated Android malware, dubbed NoVoice, has managed to infiltrate the Google Play, hidden in dozens of seemingly innocent apps. According to researchers, more than 50 apps containing the malware have exceeded 2.3 million downloads in total, demonstrating how easily even the security mechanisms of official marketplaces can be bypassed.

How malware went unnoticed

The applications that carried NoVoice included cleaning tools, image galleries, and simple games, categories that are particularly popular with the general public. The most worrying thing is that they worked normally and did not request suspicious permissions, which made them seem completely trustworthy.

This tactic highlights a significant shift in attackers' strategy: instead of overtly malicious applications, they are opting for "camouflaged" solutions that offer real functionality, reducing the chances of detection by users and control systems.

See also: FBI: AVrecon malware targets routers in 163 countries

NoVoice Android malware

Exploiting old vulnerabilities for complete control

Once a user opened an infected app, NoVoice attempted to gain root access to the device, exploiting known Android vulnerabilities that had been patched in previous years. Targeting older software versions demonstrates that many devices remain vulnerable due to delayed or non-existent security updates.

McAfee 's analysis revealed that the malware bears similarities to the well-known Triada trojan , but cannot be attributed with certainty to a specific group of cybercriminals.

Complex architecture and continuous communication with C2

After initial infection, NoVoice communicates with command-and-control servers, collecting detailed data about the device: hardware, Android version, installed applications, and security status. Based on this information, it selects the appropriate attack strategy.

This communication occurs at regular intervals, allowing the malware to download specialized exploits for each device. Researchers identified at least 22 different exploits, including bugs in the kernel and GPU drivers, that lead to a complete system compromise.

See also: CrystalRAT: New MaaS service advertised via Telegram

Rootkit with resistance to factory reset

Once it gains full control, NoVoice installs a powerful rootkit, replacing essential system libraries and interfering with Android functionality. It also creates multiple layers of persistence, ensuring that it remains active even after a factory reset.

A watchdog mechanism constantly checks the integrity of the malware and automatically reinstalls any deleted elements. In case of failure, it can even cause the device to reboot to restore control.

WhatsApp and digital identity theft targeted

One of the most dangerous features of NoVoice is its ability to steal data from WhatsApp. The malware extracts critical data, such as cryptographic keys, databases, and account information, allowing attackers to fully replicate the victim's session.

NoVoice: New Android malware on Google Play

This way, attackers can gain access to conversations, contacts and files without the user being immediately aware of it. NoVoice's modular design means it can be extended to other applications in the future.

Google's reaction and what users should do

The malicious apps have already been removed from Google Play after McAfee notified them, but the risk remains for those who had them installed. In these cases, it is considered highly likely that the device has already been compromised.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: “WhatsApp malware” campaign uses malicious VBS files

The primary line of defense is to regularly update the operating system and use actively supported devices. At the same time, users should pay special attention even to applications available through official stores.

NoVoice: New Android malware on Google Play

The new reality in the mobile threat landscape

The NoVoice case highlights a critical reality: attacks are becoming more “invisible” and more targeted. Security no longer depends only on the source of an application’s installation, but also on the device’s update status and user behavior.

In an environment where even trusted platforms can host threats, the need for constant vigilance and better user information becomes more urgent than ever.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS