xHelper is an Android Trojan best known for its unusual persistence and downloader behavior. It has been observed masquerading as a utility or cleaner application, then hiding its launcher presence after installation while remaining active on the device. Its core function is to retrieve and execute additional malicious components without the user’s knowledge, making it an effective staging mechanism for broader compromise.
xHelper has been associated with multi-stage infection chains in which it gathers basic device information, downloads follow-on modules, and ultimately facilitates installation of additional malware families. Reported downstream payloads have included downloader components, Triada-related modules, ad-fraud tooling, and other malware capable of obtaining root privileges on vulnerable Android devices. On affected older Android builds, particularly Android 6 and 7 devices, these chains have been used to modify the system partition, install persistent components, and make removal difficult even after app deletion or factory reset.
A defining characteristic of xHelper is persistence. In documented cases, the malware survived conventional cleanup because later-stage components with elevated privileges reinstalled it from the system partition. Associated activity has included remounting the system partition, placing malicious components into privileged locations, altering startup behavior to ensure execution after reboot, setting immutable attributes on files to resist deletion, and interfering with remediation by modifying core system libraries. xHelper-linked infections have also been described as installing a backdoor that can execute commands with superuser privileges and expose application data to attackers.
xHelper has functioned primarily as a stealthy downloader and installer, but infections tied to it have also involved ad fraud and delivery of further malware. It has been seen inside trojanized Android applications, including apps distributed through official and unofficial marketplaces, and has also appeared in ecosystems involving preinstalled malware on low-cost devices. Some reporting indicates that certain xHelper infections were delivered through Triada-related chains rather than directly by other Android malware families sometimes found on the same devices.
The malware targets Android smartphones and poses elevated risk on outdated or vendor-customized devices where privilege escalation and system-partition abuse are feasible. Its operational role in broader Android malware ecosystems, especially alongside Triada and other downloader components, has made xHelper a notable example of persistent mobile malware capable of surviving standard user remediation steps.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
16 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Trojan installer module delivered by Helper as a follow-on payload.
Referenced as an example of an unremovable Android Trojan that could be installed on vulnerable outdated devices via the APKPure compromise.
A stealthy Android downloader Trojan that silently installs additional apps on the victim device, potentially introducing adware or other malware.
Highly persistent Android trojan/downloader that hides from the user, fingerprints device, and stages multiple nested droppers to ultimately install additional payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.