'NoVoice' Android malware on Google Play infected 2.3 million devices
ID: aeb131ef-862a-5ab0-a84f-a1694273b028
STIX ID: report--aeb131ef-862a-5ab0-a84f-a1694273b028
Feed Name: Bleeping Computer
Threat Score
McAfee discovered NoVoice, an Android malware campaign distributed via over 50 Google Play apps (≈2.3M installs) that uses steganography to load encrypted payloads, fingerprints devices, downloads and runs device-specific exploits to gain root, installs a persistent rootkit that survives factory resets, and exfiltrates WhatsApp encryption databases and keys to enable session cloning; Google removed the apps after disclosure and patched devices mitigate the threat.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
