logo

New Xamalicious Backdoor Infects 25 Android Apps, Affects 327K Devices

ID: eeca8750-fdee-50e3-97c8-958be0e52193

STIX ID: report--eeca8750-fdee-50e3-97c8-958be0e52193

Feed Name: HackRead

Threat Score
75/100

Date Published: 2024-01-03

Date Updated: 2026-04-22

Author: Waqas

...
...

McAfee Mobile Research uncovered Xamalicious, a widespread Android backdoor hidden through the Xamarin build process and distributed across roughly 25 apps (some previously on Google Play and many via third-party stores), impacting an estimated 327,000 devices; it tricks users into granting accessibility privileges, downloads a dynamic second-stage payload enabling full device control and automated ad-fraud (linked to the Cash Magnet app), and uses encrypted C2 communications, making it a persistent, financially motivated mobile malware threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.