NoVoice Android Malware Infected 2.3 Million Devices via Google Play — WhatsApp Sessions at Risk

A sophisticated Android malware named NoVoice was found hidden in over 50 Google Play apps downloaded 2.3 million times. It roots infected devices and steals WhatsApp session data — a serious threat for GCC businesses that rely on WhatsApp for daily communications.

Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA Region3 min read
A digital illustration representing the NoVoice Android malware discovered on Google Play, which infected 2.3 million devices and targeted WhatsApp session data.

A digital illustration representing the NoVoice Android malware discovered on Google Play, which infected 2.3 million devices and targeted WhatsApp session data.

A new Android malware named NoVoice was found on Google Play, hidden in more than 50 apps that were downloaded at least 2.3 million times.

The apps carrying the malicious payload included cleaners, image galleries, and games. They required no suspicious permissions and provided the promised functionality.

After launching an infected app, the malware tried to obtain root access on the device by exploiting old Android vulnerabilities that received patches between 2016 and 2021.

Discovery

Researchers at cybersecurity company McAfee discovered the NoVoice operation but could not link it to a specific threat actor. However, they highlighted that the malware shared similarities with the Triada Android trojan.

NoVoice infection chain

The threat actor concealed malicious components in the com.facebook.utils package, mixing them with legitimate Facebook SDK classes.

An encrypted payload hidden inside a PNG image file using steganography is extracted and loaded in system memory while wiping all intermediate files to eliminate traces.

McAfee notes that the threat actor avoids infecting devices in certain regions, like Beijing and Shenzhen in China, and implemented 15 checks for emulators, debuggers, and VPNs. If location permissions are not available, the malware continues the infection chain.

The malware then contacts the command-and-control server and collects device information such as hardware details, kernel version, Android version, installed apps, and root status, to determine the exploit strategy.

The malware polls the command-and-control server every 60 seconds and downloads various components for device-specific exploits designed to root the victim system.

McAfee observed 22 exploits, including use-after-free kernel bugs and Mali GPU driver flaws. These exploits give the operators a root shell and allow them to disable SELinux enforcement on the device, effectively dropping its fundamental security protections.

After rooting the device, key system libraries such as libandroid_runtime.so and libmedia_jni.so are replaced with hooked wrappers that intercept system calls and redirect execution to attack code.

The rootkit establishes multiple layers of persistence, including installing recovery scripts, replacing the system crash handler with a rootkit loader, and storing fallback payloads on the system partition.

Because that part of the device's storage is not wiped during a factory reset, the malware persists even after an aggressive cleanup.

A watchdog daemon runs every 60 seconds to check the rootkit's integrity and automatically reinstalls missing components. If checks fail, it forces the device to reboot, causing the rootkit to reload.

WhatsApp data theft

During the post-exploitation phase, attacker-controlled code is injected into every app launched on the device. Two main components are deployed — one that enables silent installation or removal of apps, and another that operates within any app with internet access.

The latter serves as a primary data theft mechanism, and McAfee observed that it primarily targeted the WhatsApp messaging app.

When WhatsApp is launched on an infected device, the malware extracts sensitive data required to replicate the victim's session, including encryption databases, the Signal protocol keys, and account identifiers such as phone number and Google Drive backup details.

This information is then exfiltrated to the command-and-control server, allowing the attackers to clone the victim's WhatsApp session on their own device.

Although researchers recovered only a WhatsApp-focused payload, NoVoice's modular design makes it technically possible to have used other payloads targeting any application on the device.

Omar Al-Hakeem

Senior Cyber Threat Analyst | MENA Region

Omar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.

Intelligence Focus Areas

Mobile SecurityAndroid Threat Intelligence GCC Cybersecurity 2026