NoVoice Android Malware With 22 Exploits Attacks Millions
Key Takeaways A sophisticated Android rootkit, dubbed NoVoice, compromised over 2.3 million devices globally. The malware, distributed through more than 50 seemingly benign apps on Google Play,...
Key Takeaways
- A sophisticated Android rootkit, dubbed NoVoice, compromised over 2.3 million devices globally.
- The malware, distributed through more than 50 seemingly benign apps on Google Play, exploited 22 vulnerabilities to gain full root access without user interaction.
- Devices running Android 7 or older, or those with security patches older than May 1, 2021, are most vulnerable. A factory reset is insufficient for removal.
NoVoice Android Rootkit Infiltrates Millions Through Google Play
A highly advanced Android rootkit, identified as “NoVoice,” has secretly infected more than 2.3 million devices worldwide. The stealthy malware was disseminated through over 50 applications that were available on the Google Play store. For a detailed analysis of this threat, including its extensive array of 22 exploits, a comprehensive report is available here.
Table Of Content
Dubbed “Operation NoVoice,” the malware leverages 22 distinct exploits to achieve complete control over Android devices, all while operating silently. This makes it one of the most potent Android threats identified in recent memory. The malicious applications, disguised as common utilities like phone cleaners, gallery tools, and casual games, functioned normally upon launch, exhibiting no suspicious behavior, unusual permission requests, or visible indicators of compromise.
However, beneath the surface, these apps were covertly connecting to remote servers, gathering detailed information about the device’s hardware and software, and preparing to deploy targeted exploits. The McAfee mobile research team, which uncovered this campaign, derived the malware’s name from a silent audio file, R.raw.novioce, embedded in a later-stage payload. This zero-volume file ensures a background service remains active, providing a persistent and undetectable foothold for attackers. The intentional misspelling of “no voice” aptly describes the malware’s silent operational methodology.
The scale of this operation is particularly concerning. Over 50 malicious applications were confirmed on Google Play before their eventual removal, collectively amassing at least 2.3 million downloads. The infection spread across multiple continents, with Nigeria, Ethiopia, Algeria, India, and Kenya experiencing the highest rates, likely due to the prevalence of older, unpatched Android devices in these regions.
Following responsible disclosure by McAfee, Google promptly removed all identified malicious applications and banned the associated developer accounts. Android devices with a security patch level of May 1, 2021, or newer are resistant to the exploits found on the command-and-control (C2) server. Nevertheless, older devices running Android 7 or earlier remain highly vulnerable, and crucially, a standard factory reset will not eliminate this deeply embedded rootkit.
How the Infection Takes Root and Stays Hidden
The infection process initiates immediately upon a user opening a compromised application, requiring no further interaction. Malicious code, stealthily injected into the app’s Facebook SDK initialization path, executes silently in the background. A clever evasion technique involves an encrypted payload hidden within what appears to be a normal image file, appended after the image’s end marker. This method is specifically designed to bypass conventional security scans.
Before escalating privileges, the malware performs 15 verification checks. These checks include detecting emulators, enforcing GPS geofencing, identifying VPN usage, and monitoring for debugger activity. Notably, devices physically located within Beijing and Shenzhen are excluded from the attack. If all validation checks are successful, the malware contacts its C2 server to download root exploits specifically tailored to the device’s chipset and kernel version.
A total of 22 distinct exploits were recovered, with one particularly potent chain employing a three-stage kernel attack. This exploit sequence leverages an IPv6 use-after-free vulnerability, a Mali GPU driver flaw, and credential patching to completely disable Android’s SELinux protections. Once root access is established, the rootkit replaces a critical system library, libandroid_runtime.so, ensuring that attacker-controlled code runs every time any application launches on the device.
A sophisticated watchdog process continuously monitors the installation, checking every 60 seconds and automatically reinstalling any components that may have been removed. While the only confirmed data theft payload recovered was designed to clone WhatsApp sessions by extracting encryption keys and session data, the underlying framework is built to accommodate and execute any arbitrary task at any given time.
What You Should Do
- Perform a Firmware Reflash: If you suspect your device is infected, a full firmware reflash is necessary, as a factory reset will not remove this rootkit.
- Update Your Device: Ensure your Android device has a security patch level of May 1, 2021, or later. This mitigates exposure to the known exploits used by NoVoice.
- Block C2 Domains: Network administrators should consider blocking known C2 domains associated with this campaign to disrupt the infection chain.
- Exercise Caution with Apps: Only download applications from trusted developers with established reputations and positive reviews. Be especially wary of utility and gaming applications from unknown sources.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.