The Android malware xHelper was found using a multi-stage infection chain that lets it survive app removal and even some factory resets by gaining root privileges and embedding itself into the system partition. Disguised as a cleaner app, xHelper hides after installation, gathers device information, and downloads additional modules including Agent.of, Helper.b, Leech.p, and Triada, which work together to obtain elevated access and install persistent components.
Researchers reported that the malware modifies /system/lib/libc.so, sets immutable file attributes, reinstalls itself from a system-partition package, and can remove root-management tools such as Superuser, making remediation difficult. The infection effectively leaves a backdoor capable of superuser command execution and broad access to application data, giving attackers deep control over compromised devices. Recommended recovery is to replace the altered libc.so with a clean version from original firmware where possible, though a full device reflash is considered the more reliable fix, especially because some affected phones may already carry malware in preinstalled firmware.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
Securelist states that xHelper remained highly active after mass attacks began in the middle of the previous year, establishing the start of the large-scale campaign. The malware was characterized by strong persistence on infected Android devices.
Securelist analyzed an active xHelper sample and described how it masquerades as a cleaner app, downloads multiple malicious stages including Agent.of, Helper.b, Leech.p, and Triada, gains root on some devices, modifies the system partition, and survives deletion or factory reset. The report also noted that the malware can install a superuser backdoor and recommended replacing the infected libc.so or fully reflashing affected phones.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 15 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.