Android Alert: 50 Google Play Apps Linked to ‘NoVoice’ Malware Reached 2.3M Downloads
ID: 00c0970c-52aa-50cd-a4cb-c4e4540d7a11
STIX ID: report--00c0970c-52aa-50cd-a4cb-c4e4540d7a11
Feed Name: TechRepublic Security
NoVoice is an Android malware campaign that was distributed through apparently legitimate apps on Google Play (over 2.3 million downloads); it exploits a collection of older Android/kernel/GPU vulnerabilities (22 exploits observed) to gain root, installs persistent components on the system partition that survive factory resets, and contacts a C2 to receive device-specific payloads enabling data theft (including WhatsApp session data and potentially banking data). Google removed the apps after reporting; devices updated with patches since May 2021 are reportedly protected.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
