Xamalicious Malware Lurks: 330k Android Devices Infected Through Disguised Apps

Android Logo 2019 present 1687630171

Over 330,000 Android devices have fallen victim to a previously unknown malware dubbed “Xamalicious,” researchers at McAfee revealed, highlighting the vulnerability of even the official Google Play Store to malicious actors. The malware masqueraded as seemingly harmless apps like horoscopes and skin editors, tricking unsuspecting users into downloading and installing it.

Key Highlights:

  • 14 infected apps identified on Google Play, some surpassing 100,000 downloads.
  • Xamalicious functions as a backdoor, granting attackers remote access to compromised devices.
  • Potential for ad fraud and data theft not ruled out.
  • Apps removed from Google Play, but existing infections require manual cleanup.
  • Increased vigilance and caution urged when downloading apps.

Android Logo 2019 present 1687630171 scaled

McAfee, a member of the App Defense Alliance, uncovered the Xamalicious threat while monitoring app activity on Google Play. The malware, disguised within seemingly innocuous apps like “Essential Horoscope for Android” and “3D Skin Editor for PE Minecraft,” managed to evade initial security checks and slip onto the official app store.

Technical Details:

  • Xamalicious is a .NET-based backdoor hidden within apps built using the Xamarin framework. This makes it more challenging to detect than traditional Java-based malware.
  • The malware utilizes two core libraries: “Core.dll” and “GoogleService.dll,” masquerading as legitimate components for app functionality.
  • Once activated, Xamalicious establishes communication with a remote server using hardcoded IP addresses and encryption techniques.

Once installed, Xamalicious operates as a backdoor, establishing a covert communication channel between the infected device and the attacker’s server. This grants malicious actors the ability to:

  • Steal sensitive data like login credentials, financial information, and personal files.
  • Install additional malware for further compromising the device.
  • Perform unauthorized actions such as sending spam messages or making fraudulent calls.
  • Monitor user activity and track their online behavior.

While the full extent of Xamalicious’ capabilities is still under investigation, researchers suspect its involvement in ad fraud schemes. The malware might be capable of automatically clicking on ads and installing adware to generate revenue for its operators.

The good news is that Google has responded swiftly and removed all identified Xamalicious-infected apps from the Play Store. However, existing infections remain a concern. Users who downloaded any of the following apps since mid-2020 are advised to immediately uninstall them and run a reputable security scan:

  • Essential Horoscope for Android
  • 3D Skin Editor for PE Minecraft
  • Logo Maker Pro
  • Auto Click Repeater
  • Count Easy Calorie Calculator
  • Dots: One Line Connector
  • Sound Volume Extender

This incident underscores the importance of practicing good app hygiene when using Android devices. Download apps only from trusted sources, carefully review app permissions before granting them, and keep your device and security software up-to-date.

Tags

About the author

Jamie

Jamie Davidson

Jamie is the Senior Rumors Analyst at PC-Tablet.com, with over 5 years of experience in tech journalism. He holds a postgraduate degree in Biotechnology, blending his scientific expertise with a deep passion for technology. Jamie plays a key role in managing the office staff writers, ensuring they stay informed with the latest technological developments and industry rumors. Known for his quiet nature, he is also an avid Chess player. Jamie’s analytical skills and dedication to following tech trends make him an essential contributor to the team, helping to maintain the site’s reputation for timely and accurate reporting.

Web Stories

5 Best Projectors in 2024: Top Long Throw and Laser Projectors for Every Budget 5 Best Laptop of 2024 5 Best Gaming Phones in Sept 2024: Motorola Edge Plus, iPhone 15 Pro Max & More! 6 Best Football Games of all time: from Pro Evolution Soccer to Football Manager 5 Best Lightweight Laptops for High School and College Students 5 Best Bluetooth Speaker in 2024 6 Best Android Phones Under $100 in 2024 6 Best Wireless Earbuds for 2024: Find Your Perfect Pair for Crystal-Clear Audio Best Macbook Air Deals on 13 & 15-inch Models Start from $149