Skip to main content
  1. Home
  2. Phones
  3. Android
  4. Mobile
  5. News

Android malware keeps returning even after factory reset through Google Play

Add as a preferred source on Google
 

Cybersecurity firm Malwarebytes revealed a form of Android malware that keeps returning even after performing a factory reset on a smartphone.

Recommended Videos

Malwarebytes discovered the Android trojan named the xHelper in May 2019. The malware is capable of installing itself on an Android device without notifying the owner, then receives remote commands and downloads additional malware into the infected smartphone or tablet.

Unfortunately, it appears that xHelper is still evolving. Amelia, an Android device owner, reached out to the Malwarebytes support forum to seek help for a curious case.

Amelia was able to remove two variants of xHelper and a trojan agent from her Android device through Malwarebytes’ app. However, xHelper kept coming back less than an hour after it was removed, even after Amelia performed a factory reset on her phone.

In Malwarebytes’ investigation, the first suspect for the returning xHelper was pre-installed malware, which was a possibility because Amelia’s phone was made by an unnamed, lesser-known manufacturer. However, after Amelia was guided through the process of checking if this was the case, xHelper did not go away.

Malwarebytes then noticed that the source of installation for xHelper was Google Play. When the service was deactivated, the re-infections of the malware stopped.

The firm determined that Google Play itself was not infected with malware, but it was triggering the re-installation of xHelper. They then discovered an Android application package hidden inside the phone’s files that serves as a trojan dropper. Directories and files, including the APK, remain on an Android device even after a factory reset, unlike apps, which is how xHelper keeps infecting the phone. The method for installing the APK through something triggered by Google Play, however, is still under investigation.

Malwarebytes, which detailed a step-by-step guide for removing xHelper malware, tagged Amelia’s case as a “new era in mobile malware,” as a factory reset is usually the last, but effective, option in cleaning an infected device. Fortunately, Amelia “was as persistent as xHelper itself” in searching for the truth behind the case.

Hackers are continuously evolving, taking advantage of technology and current events for their attacks. As always, people should remain vigilant against cybersecurity threats and are recommended to reach out to experts for any suspected security risks.

Aaron Mamiit
Aaron received an NES and a copy of Super Mario Bros. for Christmas when he was four years old, and he has been fascinated…
RISION’s new pocket-sized cameras turns your phone into a nitfty thermal imaging tool
This tiny $119 camera gives your phone Predator vision
RISION Magic Pro in action

If you've ever had to look for any sort of heat leaks or hot wires, chances are that you've probably used a dedicated handheld camera. But RISION has just launched a tiny new camera tool to make the job easier (and more pocketable). It reminds me of the InfiRay we checked out a while back.

RISION has introduced the Magic and Magic Pro, two compact thermal cameras that plug directly into supported USB-C phones, tablets, and Windows computers. Each module weighs 24 grams, draws power from the connected device, and requires no separate battery. Support covers compatible iPhones, Android devices, and Windows PCs.

Read more
Samsung may finally kill the foldable crease next year, and make the screen stronger while it’s at it
The Galaxy Z Fold 9 could attack the crease from inside the glass
The Galaxy Z Fold 4's screen crease.

Samsung has spent generations refining hinges, reinforcing display layers, and promising increasingly subtle creases. But soon, it might eliminate the crease by physically carving away part of the glass where the screen folds.

Samsung Display is developing a foldable OLED cover layer known as Center-Etched Thin Glass, or CTG, alongside its suppliers. The technology selectively etches the central folding section of the ultra-thin glass, leaving that area thinner than the rest of the panel. Industry sources believe it could appear in some Galaxy Z9 foldables as early as 2027. It is also known as Hybrid UTG, since a single glass layer would carry two different thicknesses.

Read more
DuckDuckGo’s new iPhone feature stops tracking IDs from hitching a ride in shared links
Copy Clean Link removes unnecessary URL parameters before you paste a page into a message, email, or post
The DuckDuckGo logo.

DuckDuckGo has added a small iPhone feature that can stop tracking identifiers from following links into your chats, emails and social posts.

The browser’s new Copy Clean Link option strips unnecessary parameters before placing an address on the clipboard. It arrived in a July iOS update and appears when users hold the address bar. The supplied report shows it working with pages from X, Reddit and YouTube.

Read more