{
    "success": true,
    "data": {
        "id": 1656495,
        "msgid": "2-3-million-android-users-hit-by-no-voice-malware-targeting-whatsapp-1775656331",
        "date": "2026-04-05 13:14:00",
        "title": "2.3 Million Android Users Hit by 'No Voice' Malware Targeting WhatsApp",
        "author": "Thalatie Kaprina Yani",
        "source": "MEDIA_INDONESIA",
        "tags": "",
        "topic": "Technology",
        "summary": "McAfee researchers have uncovered a large-scale Android malware campaign dubbed Operation NoVoice, which infiltrated over 50 apps on the Google Play Store and was downloaded more than 2.3 million times worldwide. The malware disguises itself as legitimate apps while secretly seeking root access to steal sensitive data, particularly from WhatsApp, allowing attackers to clone user sessions on their own devices. It persists even after factory resets, highlighting the need for timely security updates and cautious app downloads to protect against such sophisticated threats.",
        "content": "<p>A research team from McAfee has recently revealed a large-scale\nAndroid malware campaign they have named Operation NoVoice. This malware\nwas detected infiltrating more than 50 apps previously available on the\nGoogle Play Store, ranging from mobile cleaning apps and puzzle games to\nphoto gallery utilities.<\/p>\n<p>Although these apps have now been removed, data indicates that the\nmalicious apps had been downloaded over 2.3 million times by users\nworldwide.<\/p>\n<p>The primary danger of NoVoice lies in its ability to masquerade as\nnormal apps that genuinely function as described. Users would not\nsuspect anything because the apps continue to perform their tasks while\nconducting covert operations in the background.<\/p>\n<p>Additionally, the malware employs a tactic of playing silent audio\ntracks continuously. This is done to keep system services running in the\nbackground without triggering suspicion from the operating system or the\nuser.<\/p>\n<p>Once installed, the NoVoice malware connects to a central server to\ntransmit detailed information about the victim\u2019s device, including\nhardware version and security patch level.<\/p>\n<p>Based on this data, attackers send custom exploit code tailored to\nthe device. The main goal of the attack is to obtain high-level access,\nknown as \u201croot\u201d access.<\/p>\n<p>With this access, attackers can modify the core Android system\nlibraries. This allows hackers to spy on data from messaging apps,\nfinancial applications, and social media without the phone owner\nrealising it at all.<\/p>\n<p>One of the primary targets of this malware is the WhatsApp app. When\na user opens WhatsApp on an infected device, the malware extracts\nsensitive data needed to replicate the user\u2019s session, including the\nencryption database, Signal protocol keys, and account identity.<\/p>\n<p>This information is then sent to the attackers\u2019 server, enabling them\nto clone the victim\u2019s WhatsApp session on the hackers\u2019 own devices.<\/p>\n<p>Even more concerning, NoVoice has robust defence mechanisms. The\ninfection can survive even after a user performs a factory reset. This\noccurs because the malicious components infiltrate parts of the software\nthat are typically untouched by the standard reset process.<\/p>\n<p>This makes infected devices behave like digital \u201czombies\u201d, where the\nmalware continues to operate in the background even after the phone has\nbeen cleaned. To completely eliminate the infection, users often need to\nperform a full firmware reinstallation.<\/p>\n<p>Nevertheless, this malware primarily targets devices with outdated\noperating systems or those that have not received the latest security\nupdates. In response to these findings, a Google spokesperson issued an\nofficial statement regarding user protection.<\/p>\n<p>\u201cAs an additional layer of defence, Google Play Protect automatically\nremoves these apps and blocks new installations. Users should always\ninstall the latest available security updates for their devices.\u201d<\/p>\n<p>Experts recommend that Android users promptly update their systems\nand exercise greater caution when downloading apps, even from official\nstores like Google Play. It is highly advisable to check the developer\u2019s\nname, number of downloads, and user reviews before installing new\napps.<\/p>\n<p>Furthermore, using robust mobile security software can help detect\nsuspicious behaviour and block malware before it can take root in the\nsystem.<\/p>\n<p>Check the list of apps on your phone immediately and ensure your\nAndroid security system is updated to the latest version.<\/p>",
        "url": "https:\/\/jawawa.id\/newsitem\/2-3-million-android-users-hit-by-no-voice-malware-targeting-whatsapp-1775656331",
        "image": ""
    },
    "sponsor": "Okusi Associates",
    "sponsor_url": "https:\/\/okusiassociates.com"
}