The Unkillable Spy: How “Operation NoVoice” Rootkits Hijack Androids and Clone WhatsApp
ID: 482db66e-9c0e-59ff-816a-2c74b37023c2
STIX ID: report--482db66e-9c0e-59ff-816a-2c74b37023c2
Feed Name: securityonline.info
Threat Score
McAfee researchers uncovered "Operation NoVoice," a sophisticated Android rootkit campaign distributed through seemingly legitimate Google Play apps that profile devices, download tailored root exploits, and achieve persistent, system-level control (surviving factory resets). The malware injects into every app launch—targeting WhatsApp to clone sessions—and is backed by active C2 infrastructure; devices with security patches older than May 2021 are especially at risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
