Skip to main content
  1. Home
  2. Phones
  3. Android
  4. Mobile
  5. News

Newly discovered Android malware Xavier clandestinely steals your data

Add as a preferred source on Google

A new variant of Android malware is making rounds in the Google Play store and it is bad news all around. According to Trend Micro, a Trojan dubbed Xavier, which is embedded in more than 800 applications on Android’s app store, clandestinely steals and leaks personal data.

Mobile malware is not new to the Android platform, but Xavier is a little more clever. It downloads codes from a remote server, executes them, and uses a string encryption, Internet data encryption, emulator detection, and a self-protect mechanism to cover its tracks.

Recommended Videos

It is derived from AdDown, a family of malware that has been around for two years. But unlike most offshoots, Xavier features the troubling addition of encryption and a secure connection. Once it loads a file and obtains an initial configuration from a remote server, it detects, encrypts, and transmits information about the victim’s device — including the manufacturer, language, country of origin, installed apps, email addresses, and more — to a remote server.

According to Trend Micro, Xavier makes its remote capabilities tough to pin down by detecting whether it is running on an Android emulator, a type of software that mimics a device’s hardware components. It checks the device’s name, manufacturer, device brand, operating system version, hardware ID, SIM card operator, resolution, and does not run if it encounters an unexpected field.

Trend Micro’s analysis identified Xavier in apps from southeastern nations such as Vietnam, the Philippines, Indonesia, Thailand, Taiwan, and others, many of which appear to be innocuous on the surface. They range from utilities like photo editors to wallpaper and ringtone changers, and are typically free.

Trend Micro’s report follows the discovery of two other forms of Android malware earlier this year. In May, researchers at Check Point identified Judy, an auto-clicking adware which could have infected as many as 36.5 million Android devices. In March, Palo Alto Networks uncovered malware designed for Windows PCs in 132 apps on Google’s Play Store.

Google’s taking a proactive approach to the problem. The search giant has targeted security on Android over the past year, most recently with the introduction of the Google Play Protect platform. It says it has worked with 351 wireless carriers to shorten the time it takes to test security patches before deploying them to users — an effort that resulted in a reduction of the software approval process from six to nine weeks to just a week.

Google’s also doled out $1 million to independent security researchers and pursued an aggressive strategy of encryption. As of December, 80 percent of Android 7.x (Nougat) users secure their data with passwords, patterns, or PIN codes.

Adrian Ludwig, director of Android security at Google, pointed to social engineering — attacks that fool a user into installing an app that compromises his or her device’s security — as one of the biggest challenges facing app developers today. “People don’t want to think about security,” he told members of the press at the RSA conference in February. “They just want it to be that way.”

Kyle Wiggers
Kyle Wiggers is a writer, Web designer, and podcaster with an acute interest in all things tech. When not reviewing gadgets…
How to set up selfie video sign-in for your Google account
Your face can now serve as a way to get back into your Google account. Here's how to set it up.
Google account selfie sign in tutorial featured

Losing access to a Google account is rarely a quick fix, but Google has been actively working to make things easier. Last year, the company introduced a feature called Recovery Contacts that lets you designate a trusted friend or family member to verify your identity if you ever get locked out. Now, Google has introduced a new option, one that uses your face to get you back in instead of a phone call to a friend.

Like Recovery Contacts, the new selfie video authentication feature requires some setup before you can use your face to sign into your Google account. This involves recording the reference video that Google will use to verify your identity whenever you attempt to log in this way. Here's how to set up selfie video sign-in for your Google account.

Read more
Samsung stirred the wide foldable race, but I’m more excited for an upcoming exotic rival
Samsung went bold and wide, but Xiaomi's rumored Mix Fold 5 has my attention
Computer, Electronics, Tablet Computer

Samsung’s Galaxy Z Fold 8 brought a major redesign to the company's foldable lineup. We now have a shorter, almost passport-like body that opens into a 7.6-inch display with a more media-friendly 4:3 aspect ratio. This feels like a more natural fit than Samsung's squarer last-gen foldables. It also has a more portable 201 grams heft and a decent 4,800mAh battery capacity.

All of this makes it one of Samsung's most interesting foldables yet. However, an upcoming Xiaomi device may take the same wide-screen formula and blend it with a Chinese phone's typical madness.

Read more
Apple could cut off app access on financed iPhones over missed payments
Code spotted in the iOS 27 beta points to a system that could restrict most apps until an overdue payment is resolved.
Apple iPhone 17 Pro in Cosmic Orange next to the iPhone 17 Pro Max in Deep Blue

Apple reportedly plans to launch a Klarna-backed financing program next week that will let you pay off an iPhone, iPad, Mac, or Apple Watch in monthly installments over two to three years. While Apple hasn't shared any details about the rumored "Apple Upgrade" program yet, code spotted in an iOS 27 beta release suggests the company has already built a system to deal with customers who fall behind on payments.

A built-in switch lenders can flip to lock most apps

Read more