NoVoice malware reached 2.3 million Android downloads through Google Play

THE BRIEF
McAfee researchers identified an Android malware operation called NoVoice that was distributed through more than 50 apps on Google Play and accumulated at least 2.3 million downloads. The apps included cleaners, galleries and games and could appear legitimate because they delivered their advertised functions without requesting obviously suspicious permissions. NoVoice then exploited older Android vulnerabilities, all patched between 2016 and 2021, to gain root access on vulnerable devices. Researchers described a multi-stage infection chain that hid an encrypted payload inside an image, downloaded device-specific exploits and established persistence at the system level. Once rooted, the malware could inject code into applications and McAfee observed payloads focused on stealing WhatsApp session material, including databases, Signal protocol keys and account identifiers. Google said devices updated since May 2021 are protected from the exploited flaws, removed the reported apps and stated that Play Protect blocks new installs. Users of outdated devices remain the main exposure.
WHY IT MATTERS
The incident shows why app-store presence cannot replace device patching. NoVoice reportedly relied on vulnerabilities that had been fixed for years, yet millions of downloads still created a large pool of potentially exposed devices. For businesses, personally owned Android devices can become an access path into work messaging, identity and cloud services if employees reuse accounts or handle sensitive information on unsupported hardware. The key risk is therefore not a novel exploit alone, but the long tail of devices that no longer receive security updates.
WHO SHOULD CARE
Android users, mobile-device administrators, organizations allowing BYOD, messaging-platform users and security teams responsible for endpoint hygiene should pay particular attention. This also matters to organizations whose staff use personal phones for work messaging or authentication.
WHAT TO DO NOW
- Require supported Android versions and minimum security-patch levels for devices accessing work services.
- Remove the identified applications and review affected devices for signs of compromise.
- Treat WhatsApp and other sessions on a suspected device as compromised and rotate relevant credentials or tokens.
- Use mobile-device management or conditional access to block outdated and rooted devices from corporate resources.