In the Play Market dozens of apps with malicious NoVoice were found, which were downloaded by 2.3 million users

In the Play Market dozens of apps with malicious NoVoice were found, which were downloaded by 2.3 million users

83 hardware

Short Summary

More than 50 apps containing the malicious code *NoVoice* were found on Google Play Market.

- The virus uses known Android vulnerabilities (2016‑2021) to gain root privileges.
- It has been downloaded over 2.3 million times.
- The apps appear as photo galleries, games, and “cleaning” utilities – they do not request suspicious permissions.

McAfee experts confirmed the threat but could not identify a specific attacker; the virus resembles the *Triada* trojan.

How NoVoice Works
Stage | What Happens | Infection | Malicious Code Placement | Conditions for Infection | Information Gathering | Exploits | Persistence | Functional Modules | Modularity

- The malicious code is placed in the package `com.facebook✴.utils`, masquerading as the Facebook SDK. An encrypted payload (`enc.apk`) is hidden inside a PNG image, from which the file `h.apk` is extracted and loaded into memory. After that all temporary files are deleted.
- If the device is identified as located in Beijing or Shenzhen (China) and passes 15 checks for emulators, debuggers, and VPNs, the process stops; otherwise it continues.
- The malware contacts a remote server and sends: kernel version, Android version, list of installed apps, root status. Requests repeat every 60 seconds.
- McAfee discovered 22 exploits (kernel bugs, memory leaks, Mali driver vulnerabilities). They open a root shell and disable SELinux.
- After gaining root, the malware replaces system libraries `libandroid_runtime.so` and `libmedia_jni.so`, creates recovery scripts, hijacks crash handlers, and stores a backup payload in the system partition (not erased on reset). Every 60 seconds a watchdog daemon runs to verify the integrity of the rootkit.

Functional Modules
1) Hidden installation/removal of apps.
2) Connection to any internet app and data theft (most often from WhatsApp). When opening the messenger, the malware obtains databases, encryption keys, phone number, and Google Drive backups, sending them to a command server. This allows attackers to clone WhatsApp sessions.

Modularity
The virus can use other payloads for any apps on the device.

Protection
- Devices updated after May 2021 are no longer vulnerable because the exploits have been patched.
- Google Play Protect automatically removes found apps and blocks new installations.
- Users are advised to regularly install all available security updates.

Conclusion: *NoVoice* is a sophisticated rootkit that uses outdated Android vulnerabilities to gain root privileges, hide infections, and steal data from popular applications. Protection is only possible through timely patches and using Play Protect.

Comments (0)

Share your thoughts — please be polite and stay on topic.

No comments yet. Leave a comment — share your opinion!

To leave a comment, please log in.

Log in to comment