Skip to main content
  1. Home
  2. Phones
  3. Android
  4. Mobile
  5. News

Newly discovered Android malware Xavier clandestinely steals your data

Add as a preferred source on Google

A new variant of Android malware is making rounds in the Google Play store and it is bad news all around. According to Trend Micro, a Trojan dubbed Xavier, which is embedded in more than 800 applications on Android’s app store, clandestinely steals and leaks personal data.

Mobile malware is not new to the Android platform, but Xavier is a little more clever. It downloads codes from a remote server, executes them, and uses a string encryption, Internet data encryption, emulator detection, and a self-protect mechanism to cover its tracks.

Recommended Videos

It is derived from AdDown, a family of malware that has been around for two years. But unlike most offshoots, Xavier features the troubling addition of encryption and a secure connection. Once it loads a file and obtains an initial configuration from a remote server, it detects, encrypts, and transmits information about the victim’s device — including the manufacturer, language, country of origin, installed apps, email addresses, and more — to a remote server.

According to Trend Micro, Xavier makes its remote capabilities tough to pin down by detecting whether it is running on an Android emulator, a type of software that mimics a device’s hardware components. It checks the device’s name, manufacturer, device brand, operating system version, hardware ID, SIM card operator, resolution, and does not run if it encounters an unexpected field.

Trend Micro’s analysis identified Xavier in apps from southeastern nations such as Vietnam, the Philippines, Indonesia, Thailand, Taiwan, and others, many of which appear to be innocuous on the surface. They range from utilities like photo editors to wallpaper and ringtone changers, and are typically free.

Trend Micro’s report follows the discovery of two other forms of Android malware earlier this year. In May, researchers at Check Point identified Judy, an auto-clicking adware which could have infected as many as 36.5 million Android devices. In March, Palo Alto Networks uncovered malware designed for Windows PCs in 132 apps on Google’s Play Store.

Google’s taking a proactive approach to the problem. The search giant has targeted security on Android over the past year, most recently with the introduction of the Google Play Protect platform. It says it has worked with 351 wireless carriers to shorten the time it takes to test security patches before deploying them to users — an effort that resulted in a reduction of the software approval process from six to nine weeks to just a week.

Google’s also doled out $1 million to independent security researchers and pursued an aggressive strategy of encryption. As of December, 80 percent of Android 7.x (Nougat) users secure their data with passwords, patterns, or PIN codes.

Adrian Ludwig, director of Android security at Google, pointed to social engineering — attacks that fool a user into installing an app that compromises his or her device’s security — as one of the biggest challenges facing app developers today. “People don’t want to think about security,” he told members of the press at the RSA conference in February. “They just want it to be that way.”

Kyle Wiggers
Kyle Wiggers is a writer, Web designer, and podcaster with an acute interest in all things tech. When not reviewing gadgets…
The Pixel 11 gives me three reasons to ditch my iPhone 17, and I’m afraid they’ll work
Google’s latest entry-level flagship makes my iPhone 17 look a lot less compelling.
Electronics, Mobile Phone, Phone

As someone who reviews smartphones for a living, upgrading every year isn't optional. It's part of the job, and as an iPhone user, it's an easy call. This year, I expected to move from my baseline iPhone 17 to Apple's next baseline model, the iPhone 18. Except Apple might not even launch it this September.

Pegatron, one of Apple's suppliers, indicated on an August 12 earnings call that the standard iPhone 18 isn't coming next month (via Deccan Chronicle). Only the Pro, Pro Max, and the rumored foldable "Ultra" are expected, with the base model pushed to early 2027. That alone would derail my plans. But it's just one domino in a longer line for Apple: the Pixel 11.

Read more
Cracking your Galaxy Z Fold 8 Ultra screen could cost $639, so handle it carefully
Samsung's new numbers put an exact, and fairly painful, figure on just how much pricier.
Computer, Electronics, Tablet Computer

Cracking your foldable's screen has always been an expensive mistake, but Samsung just put an actual price on it this year, and believe me, it’s more expensive than I initially thought it would be. 

The company confirmed official repair pricing for the entire Galaxy Z Fold 8 lineup, and fixing the inner display alone can cost more than some budget phones do new. Given that more people are buying into the category, making these revised repair costs all the more important to know before you take the plunge.

Read more
I’ve waited far too long for Pixels to get this stupidly simple gesture
Just ship the double-tap-to-lock gesture already Google.
Electronics, Mobile Phone, Phone

Every time I switch from any Android phone to a Pixel, there's one small gesture missing that always annoys me. From a modern Galaxy phone or even a device from Xiaomi, I can double-tap an empty part of the home screen and immediately turn the display off. Samsung has offered a double-tap to turn off the screen since Android 11. On a Pixel, I still have to reach for the power button.

To be fair, Google isn't the only offender, and Motorola's stock Android phones, like the Razr Fold, also skip such a basic feature. But this might be changing soon. Android Authority has discovered updated code strings inside Android 17 QPR2 Beta 3 pointing to Google’s long-in-development double-tap-to-sleep feature. Better still, Google appears to have expanded it beyond the lock screen and onto the home screen, which is exactly where I want it.

Read more