Skip to main content

Warning! This Android malware pretends your phone is off so it can hijack it

Android Malware
Image used with permission by copyright holder
A particularly nasty piece of Android malware has been discovered by security experts AVG. It’s being called PowerOffHijack, and it’s capable of fooling you into thinking a phone is turned off, but instead it remains covertly active – and potentially spying on your every move.

How does it work? According to AVG’s research, the malware takes over when you hit the power on/off key, and while it’ll still present the usual options and shutdown animation, the phone will stay on. Behind a black screen, the malware could enable the device to make calls, send out messages, or even access the camera app. All without your knowledge or permission.

While AVG goes into considerable, and very techy, detail about how the malware does all these things, but what we care about is the likelihood of PowerOffHijack being found on our own phones.

Speaking to VentureBeat, AVG said the malware is affecting Android versions up to 5.0 Lollipop, and around 10,000 installations have been tracked so far, with the majority coming from China. It’s apparently being spread through apps downloaded from stores other than Google Play, which isn’t accessible in China.

However, here’s some good news. The malware only affects phones that have been rooted, so anyone with a stock Android device running standard software – yes, that includes Google’s hardware like the Nexus 6 – is quite safe from the threat. If you’re not sure if your phone is rooted, then there is a very high chance it’s not, due to the complicated process needed to gain root access.

If you have rooted your phone, and are concerned it has picked PowerOffHijack up, then AVG says its own anti-virus software will detect it. Alternatively, it states the best way to ensure your phone is switched off is to remove the battery – which is all very well unless you own a phone where the battery’s fixed in place.

Editors' Recommendations

Andy Boxall
Senior Mobile Writer
Andy is a Senior Writer at Digital Trends, where he concentrates on mobile technology, a subject he has written about for…
Google just announced 9 new features for your Android phone and watch
Samsung Galaxy S23 showing Google Photos

Google has announced some big new features coming to Android and Wear OS devices during the Mobile World Congress 2023 event in Barcelona, Spain. These new features are beginning to roll out starting today, February 27, with others to come later.
New Android features available starting February 27

Google Drive users will now be able to do freehand annotation on Android phones and tablets. This means you are now able to use a stylus or your fingers to annotate PDFs directly in the Google Drive app on Android.

Read more
CES 2023: This Android phone can send satellite text messages to your iPhone
CES 2023 promo for Bullitt's satellite connectivity.

One of the most remarkable features of the iPhone 14 and iPhone 14 Pro is support for satellite connectivity, allowing users to call for emergency services and send SOS messages when they can’t find a cellular or Wi-Fi connection. Motorola will bring that functionality to the Android smartphone ecosystem within the next three months, according to an announcement at CES 2023. The company has partnered with the British brand Bullitt and will introduce the connectivity perk on one of its upcoming Defy series phones.

To enable satellite communication, Bullitt has created custom connectivity hardware for the phone, which works in tandem with a custom app called Bullitt Satellite Messenger. Again, the idea is to cover zones where users lose out on cellular networks or Wi-Fi coverage, especially in cases of emergencies in remote areas. The messaging part is enabled by Bullitt Satellite Messenger, which needs a subscription service that costs $5 per year.

Read more
These 80+ apps could be running adware on your iPhone or Android device
Illustration of an infected iPhone

Cybersecurity company Human has uncovered another adware campaign engaging in ad fraud that is targeting iOS and Android devices. In the simplest terms, ad fraud allows a bad actor to either visibly spam an app with ads, or to manipulate the code in such a way that the ads are invisible to the user while the bad actor extracts advertising money from a marketer.

In each iteration, it’s fraudulent. Ad fraud has been widespread in the industry for a while, and the latest investigation uncovered a cache of over 75 Android apps listed in the Google Play Store and nearly a dozen apps on Apple’s App Store that are engaged in various forms of ad fraud.

Read more