logo

'NoVoice' Android malware on Google Play infected 2.3 million devices

ID: aeb131ef-862a-5ab0-a84f-a1694273b028

STIX ID: report--aeb131ef-862a-5ab0-a84f-a1694273b028

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2026-04-01

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

McAfee discovered NoVoice, an Android malware campaign distributed via over 50 Google Play apps (≈2.3M installs) that uses steganography to load encrypted payloads, fingerprints devices, downloads and runs device-specific exploits to gain root, installs a persistent rootkit that survives factory resets, and exfiltrates WhatsApp encryption databases and keys to enable session cloning; Google removed the apps after disclosure and patched devices mitigate the threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.