NoVoice Android Malware Infects 2.3 Million Devices via Google Play Apps

NoVoice Android Malware Infects 2.3 Million Devices via Google Play Apps

First seen 2 Apr 2026, 10:03 UTC BleepingcomputerGbhackersCybersecuritynewsScworldVoi.Id 85% similarity 72.5

Article Content

Browse articles
ThreatCluster

The NoVoice Android malware has been discovered on Google Play, hidden in over 50 apps that have been downloaded more than 2.3 million times. This malware, identified by McAfee, exploits 22 vulnerabilities in older Android versions to gain root access and compromise devices. The infected apps, which include cleaners and games, required minimal permissions and functioned normally to avoid detection. Once activated, NoVoice attempts to gain root access by exploiting vulnerabilities patched between 2016 and 2021. It employs steganography to conceal malicious payloads within PNG files and uses various checks to avoid detection by emulators and VPNs. After compromising a device, the malware can inject code into all launched applications, primarily targeting WhatsApp to exfiltrate session data. The malware's persistence mechanisms allow it to survive factory resets, posing a significant risk to users. Google has removed the malicious apps, but users who downloaded them are advised to consider their devices compromised.

Key Points: • NoVoice malware has infected over 2.3 million Android devices via Google Play. • The malware exploits 22 vulnerabilities to gain root access and clone WhatsApp sessions. • Users are advised to update their devices and only download apps from trusted sources.

ThreatCluster AI

Timeline

2026-04-01
McAfee reports discovery of NoVoice malware on Google Play.
2026-04-01
Google removes over 50 malicious apps from Play Store.
2026-04-02
Cybersecurity articles published detailing NoVoice's capabilities.

Community

Browse all →