Close Menu
Read Us 24×7
    What's Hot
    Sukanya Samriddhi Yojana

    Benefits of Sukanya Samriddhi Yojana for Savings

    May 13, 2025
    Best Automated Penetration Testing Tools

    10 Best Automated Penetration Testing Tools

    May 13, 2025
    Backlit Keyboards

    7 Best Backlit Keyboards for Every Budget

    May 12, 2025
    Facebook X (Twitter) Instagram Pinterest LinkedIn
    Trending
    • Benefits of Sukanya Samriddhi Yojana for Savings
    • 10 Best Automated Penetration Testing Tools
    • 7 Best Backlit Keyboards for Every Budget
    • Top 11 “Best Buy” Alternatives for Your Electronics Needs in 2025
    • Dark Oxygen: Redefining Our Understanding of Oxygen Production in the Deep Ocean
    • YouTube Audio Downloader: Your Music Liberation Tool 🎵
    • A Deeper Look at What It Is Like Working at a Prop Firm
    • 17 Best Android App Development Software of 2025
    Facebook X (Twitter) Instagram Pinterest LinkedIn
    Read Us 24×7
    • Home
    • Technology
      Best Automated Penetration Testing Tools

      10 Best Automated Penetration Testing Tools

      May 13, 2025
      Backlit Keyboards

      7 Best Backlit Keyboards for Every Budget

      May 12, 2025
      Dark Oxygen

      Dark Oxygen: Redefining Our Understanding of Oxygen Production in the Deep Ocean

      May 9, 2025
      Android App Development Software

      17 Best Android App Development Software of 2025

      April 24, 2025
      Why Choose an AI Learning Tablet TalPad T100 Explained

      Why Choose an AI Learning Tablet TalPad T100 Explained

      April 16, 2025
    • Business
      Sukanya Samriddhi Yojana

      Benefits of Sukanya Samriddhi Yojana for Savings

      May 13, 2025

      A Deeper Look at What It Is Like Working at a Prop Firm

      May 1, 2025
      FintechZoom.IO

      FintechZoom.IO: Revolutionizing Fintech in 2025

      April 7, 2025
      Crypto Management

      Unhosted: Revolutionizing Crypto Management with Advanced Wallet Technology

      March 20, 2025
      Bank of America Hit With Lawsuit From UBS

      Bank of America Hit With Lawsuit From UBS: What You Need to Know

      January 14, 2025
    • Entertainment
      YouTube Audio Downloader

      YouTube Audio Downloader: Your Music Liberation Tool 🎵

      May 9, 2025
      Firestick

      10 Amazing Benefits of Owning a Firestick You Need to Know

      April 24, 2025
      nhentainet

      nhentai.net – Why It’s Attracting Global Attention?

      April 20, 2025
      chatgpts-ghibli-art-generator-goes-viral-why-is-everyone-obsessed

      ChatGPT’s Ghibli Art Generator Goes Viral – Why is Everyone Obsessed?

      March 29, 2025
      Taylor Swift's Producer Suggests New Album on the Horizon

      Taylor Swift’s Producer Suggests New Album on the Horizon

      March 28, 2025
    • Lifestyle
    • Travel
    • Tech Q&A
    Read Us 24×7
    Home » McAfee Warns of Xamalicious: Android Users, Remove These 13 Apps Now
    Technology

    McAfee Warns of Xamalicious: Android Users, Remove These 13 Apps Now

    Sayan DuttaBy Sayan DuttaDecember 29, 20235 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Reddit Email WhatsApp
    McAfee Warns of Xamalicious
    Share
    Facebook Twitter LinkedIn Pinterest Email Reddit WhatsApp

    If you are an Android user, you might want to check your device for any malicious apps that could compromise your security and privacy. According to a recent report by McAfee, a leading cybersecurity company, 13 apps on the Google Play Store are infected with a malware called Xamalicious. This malware can steal your personal information, such as contacts, photos, and messages, and also perform remote tasks, such as sending SMS, making calls, and accessing the camera.

    Google Android Warning: Malware Infected Apps

    McAfee’s Mobile Research Team uncovered an Android backdoor named “Android/Xamalicious” that exploits the Xamarin open-source framework. Employing social engineering tactics, it seeks accessibility privileges and then communicates with a command-and-control server. 

    Upon approval, it downloads a second-stage payload, injecting it dynamically as an assembly DLL at runtime. This enables full device control, facilitating actions like ad clicks and app installations for financial gains without user consent. 

    The use of Xamarin conceals malicious activities, and obfuscation techniques further evade detection. McAfee detected around 25 malicious apps linked to Xamalicious, removed by Google. This threat, present since mid-2020, may have compromised at least 327,000 Google Play devices.

    13 ‘Malicious’ Apps Identified by McAfee

    Upon further analysis, McAfee found that there were 13 more apps on the Google Play Store that had the same malware signature. These apps were:

    • Essential Horoscope for Android
    • 3D Skin Editor for PE Minecraft
    • Logo Maker Pro
    • Auto Click Repeater
    • Count Easy Calorie Calculator
    • Sound Volume Extender
    • LetterLink
    • Numerology: Personal Horoscope & Number Predictions
    • Step Keeper: Easy Pedometer
    • Track Your Sleep
    • Sound Volume Booster
    • Astrological Navigator: Daily Horoscope & Tarot
    • Universal Calculator

    All these apps have been removed from the Google Play Store by Google after McAfee reported them. However, they might still be present on some users’ devices.

    Technical Details:

    Xamalicious utilizes Xamarin’s framework, staying hidden during the APK build process. The backdoor, distinct from previous Xamarin-abusing malware, employs .NET code compiled into a DLL, LZ4 compressed, and embedded in the /assemblies directory. After obtaining accessibility permissions, communication with the command-and-control server ensues, collecting device data for evaluation. Notably, Xamalicious incorporates multiple obfuscation techniques and custom encryption methods. Data transmission to the server is secured using JSON Web Encryption (JWE) tokens with hardcoded RSA key values, allowing decryption during analysis.

    Payload Delivery:

    Upon C2 approval, Xamalicious delivers a second-stage payload, encrypting the DLL with Advanced Encryption Standard (AES). The unique AES key, derived from the device ID, brand, model, and padding, forms multiple layers of encryption. The payload, delivered in a JSON Web Token, is decrypted at the client side, named “cache.bin,” and dynamically loaded using the Assembly.Load method.

    Connection with Ad Fraud:

    The research reveals a connection between Xamalicious and the ad-fraud app “Cash Magnet,” indicating financial motivations. Xamalicious samples, like “LetterLink,” were identified as versions of Cash Magnet performing ad fraud with automated clicker activities, app downloads, and other tasks. The infiltration of legitimate apps, such as “Dots: One Line Connector,” underscores the persistence of this threat.

    Geographical Impact:

    Xamalicious has affected users globally, with a higher concentration observed in the Americas, particularly in the USA, Brazil, and Argentina. European countries like the UK, Spain, and Germany also reported infections.

    Steals Confidential Information and Performs Remote Tasks

    The main purpose of the Xamalicious malware is to steal the user’s confidential information and perform remote tasks on their device. The malware can access the user’s contacts, photos, messages, call logs, location, and device information. It can also send SMS, make calls, access the camera, record audio, and download additional malicious files.

    The malware communicates with a remote server, which can send commands to the infected device. The server can also update the malware or uninstall it remotely. The malware tries to evade detection by hiding its icon, using encryption, and changing its name.

    How to Check for Malicious Apps on Your Android Device?

    If you have downloaded any of the 13 apps mentioned above, you should uninstall them immediately and scan your device for any malware. Here are some steps you can follow to check for malicious apps on your Android device:

    Uninstalling Suspicious Apps

    • Go to Settings > Apps & notifications > See all apps.
    • Look for any apps that have the same developer name, icon, or description as the 13 apps identified by McAfee.
    • Tap on the app and select Uninstall. If the app does not have an uninstall option, it might have device administrator privileges. To revoke them, go to Settings > Security > Device admin apps and uncheck the app.
    • Repeat the process for any other suspicious apps.

    Running a Malware Scan

    • Download and install a reputable antivirus app, such as McAfee Mobile Security, from the Google Play Store.
    • Open the app and run a full scan of your device.
    • Follow the instructions to remove any malware or threats detected by the app.
    • You can also enable the app’s features, such as app lock, anti-theft, and web protection, to enhance your device’s security.
    Share. Facebook Twitter Pinterest LinkedIn Email Reddit WhatsApp
    Previous ArticleSamsung Adding Battery Protection Feature to Galaxy Phones
    Next Article Microsoft Disables MSIX Protocol Handler in Response to Malware Attacks
    Avatar for Sayan Dutta
    Sayan Dutta
    • Website
    • Facebook
    • X (Twitter)
    • Pinterest
    • Instagram
    • LinkedIn

    I am glad you came over here. So, you want to know a little bit about me. I am a passionate digital marketer, blogger, and engineer. I have knowledge & experience in search engine optimization, digital analytics, google algorithms, and many other things.

    Related Posts

    Best Automated Penetration Testing Tools
    Technology

    10 Best Automated Penetration Testing Tools

    May 13, 2025
    Backlit Keyboards
    Technology

    7 Best Backlit Keyboards for Every Budget

    May 12, 2025
    Dark Oxygen
    Technology

    Dark Oxygen: Redefining Our Understanding of Oxygen Production in the Deep Ocean

    May 9, 2025

    Table of Contents

    • Google Android Warning: Malware Infected Apps
    • 13 ‘Malicious’ Apps Identified by McAfee
      • Technical Details:
      • Payload Delivery:
      • Connection with Ad Fraud:
      • Geographical Impact:
      • Steals Confidential Information and Performs Remote Tasks
    • How to Check for Malicious Apps on Your Android Device?
      • Uninstalling Suspicious Apps
      • Running a Malware Scan

    Top Posts

    Sukanya Samriddhi Yojana

    Benefits of Sukanya Samriddhi Yojana for Savings

    May 13, 2025
    Best Automated Penetration Testing Tools

    10 Best Automated Penetration Testing Tools

    May 13, 2025
    Backlit Keyboards

    7 Best Backlit Keyboards for Every Budget

    May 12, 2025
    Best Buy Alternatives

    Top 11 “Best Buy” Alternatives for Your Electronics Needs in 2025

    May 11, 2025
    Popular in Social Media
    Anon IG Viewer

    Anon IG Viewer: Best Anonymous Viewer for Instagram

    April 3, 2025
    CFBR

    How to Use CFBR Appropriately? (Pros and Cons)

    September 24, 2024
    EU to Get WhatsApp, Messenger Interoperability with iMessage, Telegram and More

    EU to Get WhatsApp, Messenger Interoperability with iMessage, Telegram and More

    September 9, 2024
    New in Health
    9 Reasons Why People in Their 40s Should Take Daily Supplements

    9 Reasons Why People in Their 40s Should Take Daily Supplements

    April 8, 2025
    Why Put Your Tampons In The Freezer

    Why Put Your Tampons In The Freezer? (Answered)

    November 26, 2024
    WellHealthOrganic Buffalo Milk Tag

    WellHealthOrganic Buffalo Milk Tag: Unveiling Nutritional Brilliance

    November 13, 2024

    google news

    google-play-badge

    Protected by Copyscape

    DMCA.com Protection Status

    Facebook X (Twitter) Instagram Pinterest
    • Terms of Service
    • Privacy Policy
    • Contact Us
    • About
    • Sitemap
    • Write For Us
    • Submit Press Release
    Copyright © 2025 - Read Us 24x7

    Type above and press Enter to search. Press Esc to cancel.