Skip to main content

Android malware keeps returning even after factory reset through Google Play

 

Cybersecurity firm Malwarebytes revealed a form of Android malware that keeps returning even after performing a factory reset on a smartphone.

Recommended Videos

Malwarebytes discovered the Android trojan named the xHelper in May 2019. The malware is capable of installing itself on an Android device without notifying the owner, then receives remote commands and downloads additional malware into the infected smartphone or tablet.

Please enable Javascript to view this content

Unfortunately, it appears that xHelper is still evolving. Amelia, an Android device owner, reached out to the Malwarebytes support forum to seek help for a curious case.

Amelia was able to remove two variants of xHelper and a trojan agent from her Android device through Malwarebytes’ app. However, xHelper kept coming back less than an hour after it was removed, even after Amelia performed a factory reset on her phone.

In Malwarebytes’ investigation, the first suspect for the returning xHelper was pre-installed malware, which was a possibility because Amelia’s phone was made by an unnamed, lesser-known manufacturer. However, after Amelia was guided through the process of checking if this was the case, xHelper did not go away.

Malwarebytes then noticed that the source of installation for xHelper was Google Play. When the service was deactivated, the re-infections of the malware stopped.

The firm determined that Google Play itself was not infected with malware, but it was triggering the re-installation of xHelper. They then discovered an Android application package hidden inside the phone’s files that serves as a trojan dropper. Directories and files, including the APK, remain on an Android device even after a factory reset, unlike apps, which is how xHelper keeps infecting the phone. The method for installing the APK through something triggered by Google Play, however, is still under investigation.

Malwarebytes, which detailed a step-by-step guide for removing xHelper malware, tagged Amelia’s case as a “new era in mobile malware,” as a factory reset is usually the last, but effective, option in cleaning an infected device. Fortunately, Amelia “was as persistent as xHelper itself” in searching for the truth behind the case.

Hackers are continuously evolving, taking advantage of technology and current events for their attacks. As always, people should remain vigilant against cybersecurity threats and are recommended to reach out to experts for any suspected security risks.

Aaron Mamiit
Aaron received an NES and a copy of Super Mario Bros. for Christmas when he was four years old, and he has been fascinated…
iPad Air (2025) vs. iPad Air (2022): is it time to upgrade?
iPad Air (2025) vs. iPad Air (2022).

A brand new iPad Air is available now. The iPad Air (2025) closely resembles the iPad Air (2024), but how does it compare to the iPad Air (2022)? We have the answers if you’re considering whether it’s time to upgrade.
iPad Air (2025) vs iPad Air (2022): specs

iPad Air (2025)
iPad Air (2022)

Read more
Best Buy’s Apple Sales Event: This weekend’s best deals on iPads, iPhones, MacBooks, and more
The iPhone 14 Plus's camera module.

Apple fans, here's your chance at rare discounts on the brand's devices: Best Buy just launched a huge Apple Sales Event. With iPhone deals, iPad deals, MacBook deals, AirPods deals, and more up for grabs, you better hurry in choosing what to purchase because we think stocks are already flying off the shelves.

You can take a look at everything that's available in Best Buy's Apple Sales Event through the link below, but we've also rounded up our favorite offers to help you make a quick decision. It's important that you don't take up too much time in selecting where to spend your money, as every second wasted is one step closer to missing out on the offer you've got your eyes on.

Read more
Apple confirms long delay for AI-boosted Siri assistant
Invoking Siri on iPhone.

Apple’s efforts with putting advanced AI capabilities across its ecosystem, the way Google has implemented them with Gemini, have a lot of ground left to cover. Among them is the Siri virtual assistant, which has remained a laggard and still hasn’t received the features Apple showcased at its developers conference last year.

Now, the company has officially confirmed that an overhauled Siri, one that can access locally stored user data and interact with apps, has been delayed until next year. Internally known as ”LLM Siri,” the next-gen makeover might not fully arrive until next year, but the delay could extend well into 2027.

Read more