Android Backdoor ‘Xamalicious’ Infects Over 338K Devices via Google Play

Date:

Updated: [falahcoin_post_modified_date]

New Delhi, Dec 28 – Researchers have discovered a new Android malware called ‘Xamalicious’, which has infected over 330,000 devices through malicious apps on Google Play. Security software company McAfee identified 14 infected apps on Google Play, three of which had over 100,000 installs each. Although the apps have been removed from the platform, users who downloaded them since mid-2020 may still have active infections on their phones, requiring manual cleanup and scanning. Additionally, 12 other malicious apps carrying the Xamalicious threat are being distributed through unofficial third-party app stores.

The majority of infections were found on devices in the United States, Germany, Spain, the UK, Australia, Brazil, Mexico, and Argentina, according to McAfee’s telemetry data. Xamalicious is a.NET-based Android backdoor that is disguised as ‘Core.dll’ and ‘GoogleService.dll’ within apps built with the open-source Xamarin framework. This makes it more difficult to analyze the code. Upon installation, it requests Accessibility Service access, granting it the ability to perform privileged operations and obtain further permissions. The malware then contacts a command and control (C2) server to retrieve a second-stage DLL payload (‘cache.bin’) if specific geographical, network, device configuration, and root status requirements are met.

It’s concerning to see such a large number of users affected by this Android malware, said a spokesperson from McAfee. We urge users to be cautious when downloading apps from unofficial sources and ensure they have reliable security software installed on their devices.

The malicious apps with the highest number of installs include Essential Horoscope for Android, 3D Skin Editor for PE Minecraft, and Logo Maker Pro, each with 100,000 installs. Other infected apps include Auto Click Repeater, Count Easy Calorie Calculator, Dots: One Line Connector, and Sound Volume Extender, with varying install numbers.

Users are advised to be vigilant and cautious when downloading apps, especially from unofficial sources. It is crucial to have reputable security software installed on devices to detect and protect against such threats.

As the popularity of Android devices continues to rise, it is imperative that users remain vigilant and adopt secure practices to safeguard their personal information and devices from malicious actors.

In conclusion, the Xamalicious Android backdoor has compromised hundreds of thousands of devices through infected apps on Google Play. Despite the removal of these apps, users who downloaded them since mid-2020 may still have active infections that require manual cleanup. It is essential for users to exercise caution when downloading apps and prioritize the security of their devices to mitigate the risk of malware infections.

[single_post_faqs]
Neha Sharma
Neha Sharma
Neha Sharma is a tech-savvy author at The Reportify who delves into the ever-evolving world of technology. With her expertise in the latest gadgets, innovations, and tech trends, Neha keeps you informed about all things tech in the Technology category. She can be reached at neha@thereportify.com for any inquiries or further information.

Share post:

Subscribe

Popular

More like this
Related

Revolutionary Small Business Exchange Network Connects Sellers and Buyers

Revolutionary SBEN connects small business sellers and buyers, transforming the way businesses are bought and sold in the U.S.

District 1 Commissioner Race Results Delayed by Recounts & Ballot Reviews, US

District 1 Commissioner Race in Orange County faces delays with recounts and ballot reviews. Find out who will come out on top in this close election.

Fed Minutes Hint at Potential Rate Cut in September amid Economic Uncertainty, US

Federal Reserve minutes suggest potential rate cut in September amid economic uncertainty. Find out more about the upcoming policy decisions.

Baltimore Orioles Host First-Ever ‘Faith Night’ with Players Sharing Testimonies, US

Experience the powerful testimonies of Baltimore Orioles players on their first-ever 'Faith Night.' Hear how their faith impacts their lives on and off the field.