logo

Operation NoVoice: Rootkit Tells No Tales

ID: f88ade9d-d58c-52cf-abe2-60efc4c153a0

STIX ID: report--f88ade9d-d58c-52cf-abe2-60efc4c153a0

Feed Name: McAfee Labs Blog

Threat Score
85/100

Date Published: 2026-03-31

Date Updated: 2026-04-28

Author: McAfee Labs

...
...

McAfee researchers detail the NoVoice Android rootkit campaign: malicious apps on Google Play (over 50 apps, ~2.3M downloads) profile devices and fetch tailored kernel exploits from C2 servers to gain root, disable SELinux, overwrite core system libraries, and inject attacker-controlled code into every app for persistent, factory-reset‑resistant control; the framework is modular, actively maintained, and observed exfiltrating WhatsApp session keys.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.