McAfee reported that the NoVoice Android malware was distributed through more than 50 malicious apps on Google Play, where it amassed at least 2.3 million downloads by posing as legitimate utility, gallery, and casual game apps. The malware hid code in the com.facebook.utils package, concealed an encrypted payload inside a PNG file using steganography, profiled infected devices, and ran anti-analysis checks before contacting command-and-control servers. It then attempted to exploit one of 22 known Android vulnerabilities patched between 2016 and 2021 to gain root access, with older devices—especially Android 7 and below—facing the greatest risk.
Once rooted, NoVoice disabled protections including SELinux, injected code into launched apps, and targeted WhatsApp session data to enable account cloning. McAfee said the malware achieved deep persistence by modifying libandroid_runtime.so, deploying watchdog and recovery mechanisms, and reinstalling removed components, making even a factory reset ineffective on compromised devices. Devices with Android security patch levels from May 1, 2021 or later were not vulnerable to the recovered exploits, while infections were concentrated in regions with older unpatched phones, including Nigeria, Ethiopia, Algeria, India, and Kenya. Google has removed the identified apps and banned the associated developer accounts.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
Following responsible disclosure by McAfee, Google removed the identified malicious applications from Google Play and banned the associated developer accounts. Security guidance advised affected users to consider compromised devices unsafe and update to newer Android versions with recent security patches.
Technical analysis showed the malware hid components in the com.facebook.utils package, concealed an encrypted payload in a PNG file using steganography, and contacted command-and-control infrastructure before stealing WhatsApp session data to enable account cloning. McAfee also noted that devices patched to Android security level 2021-05-01 or later were not vulnerable to the recovered exploits.
After installation, NoVoice profiled devices, ran anti-analysis checks, and used one of 22 exploits tied to Android vulnerabilities patched between 2016 and 2021 to obtain root access. It then established persistence by modifying system libraries, disabling protections such as SELinux, injecting code into apps, and using recovery mechanisms that could survive factory resets.
McAfee identified an Android malware campaign dubbed Operation NoVoice in which a rootkit was embedded in more than 50 seemingly legitimate Google Play apps. The apps accumulated more than 2.3 million downloads and disproportionately affected users on older, unpatched Android devices in regions including Nigeria, Ethiopia, Algeria, India, and Kenya.
McAfee assessed that Operation NoVoice is related to the Android.Triada malware family, citing shared persistence methods and a known Triada-associated system property. This attribution connected the Google Play rootkit campaign to previously documented Android malware tradecraft.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 71 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecybersecuritynews.com
Open sourcemcafee.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.