NoVoice is an Android rootkit malware family/campaign tracked by McAfee as Operation NoVoice. It was distributed through more than 50 trojanized applications on Google Play, including cleaners, gallery apps, and casual games, and accumulated at least 2.3 million downloads. The apps appeared functional and requested minimal permissions while silently contacting command-and-control infrastructure, profiling the device, and downloading tailored root exploits.
The malware targeted older Android devices by exploiting vulnerabilities patched between 2016 and 2021; devices with Android security patch level 2021-05-01 or later were reported as not susceptible to the recovered exploits, while older and unsupported devices, especially Android 7 and below, were at significant risk. McAfee recovered 22 exploit binaries from the campaign infrastructure. NoVoice used anti-analysis measures including emulator, debugger, VPN/proxy, Xposed, and geofencing checks, and excluded devices in Beijing and Shenzhen when geolocation was available. Malicious components were hidden in a tampered com.facebook.utils namespace, and an encrypted payload was concealed in a polyglot PNG image with data appended after the PNG IEND marker.
If exploitation succeeded, NoVoice gained root access, disabled protections including SELinux, replaced core system libraries such as libandroid_runtime.so and libmedia_jni.so, and patched framework bytecode on disk. This caused attacker-controlled code to execute inside apps launched by zygote, effectively injecting code into every app at startup. Persistence was reinforced with a watchdog daemon named watch_dog that checked the installation every 60 seconds and reinstalled missing components. The infection could survive factory reset because it wrote to the system partition; McAfee stated that remediation required reflashing the device with clean firmware.
The framework was modular and plugin-based, allowing arbitrary payload delivery at runtime. The only recovered post-exploitation payload, PtfLibc, targeted WhatsApp by copying its encrypted database and extracting Signal protocol identity keys, registration data, and other local storage values for exfiltration, which McAfee assessed could enable cloning of a victim’s WhatsApp session. Additional components included BufferA for silent app installation/uninstallation and BufferB for maintaining encrypted command-and-control channels, with fallback domain retrieval via api.googlserves[.]com.
McAfee linked NoVoice to the Android.Triada family based on shared persistence techniques and use of the os.config.ppgl.status property known from Triada-related samples. Google removed the malicious apps from Google Play and banned the associated developer accounts after responsible disclosure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
It then deploys a watchdog daemon (watch_dog) that checks the installation every 60 seconds. If anything is missing, it reinstalls it.
To survive reboots, the installer replaces the system crash handler with a rootkit launcher, installs recovery scripts, and stores a fallback copy of the exploitation stage on the system partition.
To survive reboots, the installer replaces the system crash handler with a rootkit launcher, installs recovery scripts, and stores a fallback copy of the exploitation stage on the system partition.
It then deploys a watchdog daemon (watch_dog) that checks the installation every 60 seconds. If anything is missing, it reinstalls it.
From that moment onward, every app that the user opens are injected with attacker-controlled code.
We recovered 22 exploits in total. Our deep analysis of one revealed a three-stage kernel attack: an IPv6 use-after-free for kernel read, a Mali GPU driver vulnerability for kernel read/write, and finally credential patching and SELinux disablement.
Hidden inside what appears to be a normal image file is an encrypted payload sitting quietly after the image’s end marker — a technique built specifically to pass standard security scans undetected.
It employed steganography to hide an encrypted payload within a PNG file, which was then extracted and loaded into system memory.
From that moment onward, every app that the user opens are injected with attacker-controlled code.
A log-deletion routine runs alongside the framework to remove forensic traces from the device.
The first (sec.jar) is a gate designed to detect analysis environments. It runs 15 checks, including emulator detection, root indicators, debuggers, VPN and proxy connections, Xposed hooks, and GPS geofencing.
It runs 15 checks, including emulator detection, root indicators, debuggers, VPN and proxy connections, Xposed hooks, and GPS geofencing.
The replacements are not copies of the original libraries. They are wrappers that intercept the system’s own functions. When any hooked function runs, it redirects to attacker code.
The persistence mechanisms employed by NoVoice, including replacing system libraries and installing recovery scripts, allow it to survive factory resets.
For unrooted devices, it sends the device’s chipset, kernel version, security patch date, and other identifiers to the C2.
The first (sec.jar) is a gate designed to detect analysis environments. It runs 15 checks, including emulator detection, root indicators, debuggers, VPN and proxy connections, Xposed hooks, and GPS geofencing.
It runs 15 checks, including emulator detection, root indicators, debuggers, VPN and proxy connections, Xposed hooks, and GPS geofencing.
It checks in with the server, sending over 30 device identifiers including hardware model, kernel version, installed packages, and whether the device has already been rooted.
The geofence compares the device’s location against bounding boxes for Beijing and Shenzhen hardcoded in the native library and excludes devices confirmed to be inside them.
26 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android malware hidden in Google Play apps that attempts to gain root access by exploiting older Android vulnerabilities, disables security features, injects code into launched apps, steals data, and targets WhatsApp session data for account cloning. It uses steganography to conceal an encrypted payload and employs persistence mechanisms that can survive factory resets.
Android rootkit distributed through seemingly benign Google Play apps. It silently profiles devices, performs validation checks, downloads device-specific exploit chains to gain root, disables SELinux protections, replaces libandroid_runtime.so for persistent code execution, reinstalls components via a watchdog, and was observed stealing WhatsApp session material.
Android rootkit delivered via seemingly benign Google Play apps. It profiles devices, downloads tailored root exploits, gains full control, replaces core system libraries, injects attacker-controlled code into every app at launch, survives factory reset, and can exfiltrate app data including WhatsApp session material.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.