• About Us
King of Computer Media
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
King of Computer Media
No Result
View All Result

Home - Anti-Virus Software and Internet Security - 2.3 million people fell! A large-scale “NoVoice” rootkit attack appears on Android, and old devices cannot be deleted even if they are restored to their original factory settings

2.3 million people fell! A large-scale “NoVoice” rootkit attack appears on Android, and old devices cannot be deleted even if they are restored to their original factory settings

KOCPC Editor by KOCPC Editor
April 6, 2026 - Updated on August 5, 2026
in Anti-Virus Software and Internet Security

Internet anti-virus agency McAfee At the end of March 2026, the mobile security research team officially revealed a malware codenamed “Operation NoVoice” is a large-scale malware attack campaign. The most shocking thing about this attack is that the malware successfully penetrated into the official Google Play Store and lurked in more than 50 seemingly harmless apps. The cumulative downloads worldwide have exceeded an astonishing 2.3 million times. Researchers pointed out that this is not an ordinary adware or phishing program, but a highly persistent “Rootkit” level malware, its threat level is almost devastating to devices running older versions of Android systems.

A large-scale “NoVoice” rootkit attack appears on Android, and old devices cannot be deleted even if they are restored to their original factory settings

Disguising Everyday Tools: The Invisible Threat Penetrating Google Play

In information security research, “Operation NoVoice” shows extremely high organization and deception. The more than 50 infected applications are mainly disguised as the most commonly downloaded utility tools in users’ daily lives, including system cleaners, photo galleries, beauty cameras, and simple mini-games. When users install and launch these apps from the Google Play Store, they will ostensibly provide claimed functions to make users less wary, but in fact, at the bottom of the system, an intrusion targeting device control has already been quietly launched.

According to the analysis of security experts, the name of this attack named “NoVoice” comes from a clever disguise design in the program code: the malicious program will load a file called R.raw.novioce The content of the audio file is completely silent (zero volume), and its purpose is to maintain the operation of Android’s “Foreground Service” by playing silent information. This method can effectively avoid the system’s power saving optimization restrictions and ensure that malicious programs can continue to execute in the background without being noticed even when the user is not actively operating the phone.

The McAfee team discovered that once the infected application is opened, it immediately attempts to connect to the remote C2 (Command and Control) server. The server will automatically match and deliver a tailor-made “Root Exploit Payload” based on the specific hardware configuration, core version and software environment of the infected device. This “on-demand attack” model shows that the attacker organization behind it has deep technical reserves and sophisticated automation architecture.

Technical analysis: System-level shackles built using 22 old vulnerabilities

The core of NoVoice’s attack lies in its huge “vulnerability library.” Researchers confirmed that the malware integrates a total of 22 known security vulnerabilities, with release dates spanning 2016 to 2021. The most critical technical highlight is the use of “Use-after-free” core vulnerabilities in the IPv6 protocol and specific weaknesses in the Mali GPU driver. Through the serial combination of these vulnerabilities, malware can successfully break through Android’s sandbox mechanism (Sandbox) and obtain the highest level of system root privileges.

After gaining root privileges, NoVoice immediately performed a series of “surgical” system modifications. It will directly overwrite the Android system core library files libandroid_runtime.so. Because this library is the basis of the Android Runtime (ART) environment, malware can use it to automatically inject the attacker’s preset code when each application is launched. This technology allows malware to be implanted deep into the system like a parasite. It can not only monitor every move of the user, but also has powerful data stealing capabilities.

In the known cases of victimization so far, the attackers’ main goal was to steal users’ WhatsApp profiles. Through modified system libraries, NoVoice can directly access WhatsApp’s private database and copy the user’s communication session credentials. This means that attackers can directly impersonate the user’s identity on the remote device without obtaining the user’s account and password, read conversation records and even send fraudulent messages, posing a direct threat to the user’s privacy and interpersonal relationships.

Amazing persistence: Restoring to factory settings can’t help

For security experts, the most troublesome feature of “Operation NoVoice” is its “extreme persistence” (Persistence). On older devices running Android 7 or earlier, due to relatively weak system security mechanisms, NoVoice will write its own code into the “System Partition” after obtaining permission. This means that the most common self-rescue method used by ordinary users: “Factory Reset” has no effect on this malicious program.

“When a malicious program enters the system partition, it becomes part of the system.” McAfee’s report pointed out that even if all user data and applications are cleared, as soon as the device is restarted, the malicious program will be loaded along with the system core, re-establish the connection with the server and continue to operate. For these victims, the only way to completely eliminate them is to re-flash the official system firmware image file through a professional computer connection. However, the technical threshold for most ordinary users is extremely high and may even cause the device to become bricked.

Geography and Victim Profiling: Targeting Budget Devices

Information security research data shows that NoVoice infection cases are not evenly distributed around the world, but show obvious regional concentration characteristics. The main affected areas include Nigeria, Ethiopia, Algeria, India and Kenya and other developing countries. The common feature of these regions is that “budget devices” have a very high market share, and users generally still use older versions of the Android operating system.

These older devices have often stopped receiving system security updates (Security Patches) and have older core versions, which fall within the scope of the 22 vulnerabilities exploited by NoVoice. The attackers apparently carefully calculated their target groups and exploited the vulnerabilities in these devices’ defenses to spread the malware in large numbers. While infection rates are highest in developing countries, security experts warn that users in other regions with older tablets or second-hand phones are also at risk due to the global nature of the Google Play Store.

The current state of protection: Google’s actions and guidance for users to protect themselves

In response to this serious security incident, Google officials have taken immediate action. Currently, all more than 50 applications identified as containing NoVoice malicious code have been removed from the Google Play Store, and the relevant developer accounts have been permanently blocked. In addition, the Google Play Protect mechanism has also been updated with signatures that will not only block any new installation attempts, but will also proactively prompt users who have already installed them to remove them and automatically block them.

However, for users, the most effective line of defense is still regular system updates. McAfee’s research report provides a clear watershed: All Android devices that have received system updates (including security patches) after May 1, 2021, have basically been patched for the core vulnerabilities exploited by NoVoice, and are therefore not subject to this rootkit threat. This also reminds users once again that operating system updates are not only functional upgrades, but also a necessary barrier to maintain device security.

 

Source

Source: KOCPC Chinese

Tags: AndroidGoogle PlaymalwareMcAfeeNoVoiceRootkitVirus

Recent Posts

  • The Xiaomi Pad 8S Pro has passed network access certification and will debut with the self-developed XRING O3 chip.
  • The entire Google Pixel 11 lineup has been leaked! Official promotional renders of the Pixel 11 Pro XL have also surfaced
  • Are Chinese phone battery capacities falsely labeled? A brief look at the “capacity locking” phenomenon in Chinese silicon-carbon batteries.
  • NCC is leaderless, recklessly sending out national-level alert messages!?
  • What does “QR” in QR Code mean?

Recent Comments

No comments to show.
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology

No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology