Search
Close this search box.
Search
Close this search box.

Malicious Google Play Apps Infect 330K Android Devices

Malicious Apps on Google Play

In the city of New Delhi, researchers have discovered a concerning Android backdoor called ‘Xamalicious’. This backdoor has managed to infect a significant number of devices, around 338,300, through malicious apps found on Google Play.

According to Bleeping Computer, McAfee, a company specializing in computer security software, recently uncovered a total of 14 infected apps on Google Play. Surprisingly, three of these apps had managed to accumulate an impressive 100,000 installs each.

Even though the apps have been taken down from Google Play, users who downloaded them since mid-2020 might still have Xamalicious infections on their phones. These infections need to be manually cleaned up and scanned.

Some of the most well-liked apps from Xamalicious are Essential Horoscope for Android with 100,000 installs, 3D Skin Editor for PE Minecraft with 100,000 installs, Logo Maker Pro with 100,000 installs, Auto Click Repeater with 10,000 installs, Count Easy Calorie Calculator with 10,000 installs, Dots: One Line Connector with 10,000 installs, and Sound Volume Extender with 5,000 installs.

Furthermore, a specific set of 12 harmful applications containing the Xamalicious threat are being spread through unauthorized third-party app stores. These apps infect users by downloading APK (Android package) files, as stated in the report.

Based on McAfee telemetry data, a significant number of infections were found on devices located in the United States, Germany, Spain, the UK, Australia, Brazil, Mexico, and Argentina.

Xamalicious is a backdoor that targets Android devices. It is designed to be hidden within apps built using the Xamarin framework, making it harder to detect through code analysis.

Upon installation, the app requests Accessibility Service access, which enables it to carry out privileged operations like navigation gestures, hiding on-screen objects, and granting additional permissions.

After being installed, it establishes a connection with the C2 server to obtain the second-stage DLL payload (‘cache.bin’) if specific criteria related to geography, network, device configuration, and root status are satisfied.


Subscribe to Our Newsletter

Related Articles

Top Trending

claressa shields net worth
Claressa Shields Net Worth 2025: Boxing and MMA Star's Impressive Wealth
all james bond actors in order
All James Bond Actors in Order: Every James Bond Actor Who Played The Iconic Role
Legal Requirements for Buying Property in Portugal as a Foreigner
8 Essential Legal Requirements for Buying Property in Portugal as a Foreigner
what dinosaur has 500 teeth meme
What Dinosaur Has 500 Teeth Meme: Unveiling the Toothiest TikTok Sensation with Nigersaurus
Tax-Saving Strategies for Students and Recent Graduates in Ireland
15 Tax-Saving Strategies for Students and Recent Graduates in Ireland

LIFESTYLE

good morning meme
Good Morning Meme: The Best Funny Morning Memes And GIFs
Ways to Make Money from Your Hobbies
10 Ways to Make Money from Your Hobbies and Turn Passion into Profit
Best Colombian Cities to Visit Live and Work
5 Best Cities in Colombia for Digital Nomads, Expats, and Workers
rare carat engagement rings
Ultimate Guide To Rare Carat Engagement Rings For Every Bride
Best Countries for Working Women in 2025
10 Best Countries for Working Women in 2025—U.S. Fails to Rank Top 10

Entertainment

claressa shields net worth
Claressa Shields Net Worth 2025: Boxing and MMA Star's Impressive Wealth
all james bond actors in order
All James Bond Actors in Order: Every James Bond Actor Who Played The Iconic Role
brittany mahomes net worth
Brittany Mahomes Net Worth: Unveiling The Financial Status Of Patrick Mahomes' Wife
odell beckham jr brother
Odell Beckham Jr.’s Brother: Everything You Need to Know
Ryan Reynolds Justin Baldoni lawsuit hurt feelings
Ryan Reynolds to Justin Baldoni: ‘Hurt Feelings’ Isn’t a Lawsuit!

GAMING

Level Up Quickly & Securely in WoW
Level Up Quickly & Securely in WoW – Get Boosted Today
Top Kahoot Hacks
Top Kahoot Hacks: Hack Scripts on GitHub Revealed!
Best Multiplayer Games for Couples
10 Best Multiplayer Games for Couples in 2025 – Play Together & Bond
Pro Tips to Level Up Faster in Any Game
10 Pro Tips to Level Up Faster in Any Game: Master Your Skills In 2025
How To Play Battle Royale Games Smarter
10 Smart Survival Strategies To Play Battle Royale Games Smarter In 2025

BUSINESS

Tax-Saving Strategies for Students and Recent Graduates in Ireland
15 Tax-Saving Strategies for Students and Recent Graduates in Ireland
Plumbing Companies in the USA for Home Renovation Projects
Top 10 Plumbing Companies in the USA for Home Renovation Projects
Key Themes Shaping U.S. Logistics and Supply Chains
9 Key Themes Shaping U.S. Logistics and Supply Chains in 2025 and Beyond
Key Differences Between Bitcoin and Altcoins
5 Key Differences Between Bitcoin and Altcoins: Differences You Must Know
U.S. Ports Driving the Nation’s Freight Movement
Top 5 U.S. Ports Driving the Nation’s Freight Movement Forward

TECHNOLOGY

Surprising Industries Being Disrupted By Web3
10 Surprising Industries Being Disrupted By Web3
LG Launches Exaone Deep
LG Launches Exaone Deep: Korea’s First Reasoning AI Model
android 16 battery indicator ui updates
Android 16's New Battery Indicator & UI Tweaks Make Your Phone Shine
Top Kahoot Hacks
Top Kahoot Hacks: Hack Scripts on GitHub Revealed!
China Dark Factories Automation Revolution
China’s Dark Factories: AI-Driven, Workerless Manufacturing Boom

HEALTH

London Vs New Turkey Hair Transplants
Is London the New Turkey for Hair Transplants?
Elton John Health Update Vision Loss
Elton John’s Heartbreaking Health Update: Struggling with Vision Loss
Role of Cutting-Edge Therapies in Managing Chronic Illnesses
The Role of Cutting-Edge Therapies in Managing Chronic Illnesses
Books Every Professional Should Read for Mental Wellness
10 Books Every Professional Should Read for Mental Wellness
Dealing With Anxiety
Dealing With Anxiety: 6 Proven Methods to Help Yourself