Skip to main content

Newly discovered Android malware Xavier clandestinely steals your data

nfc smart unlock
Image used with permission by copyright holder
A new variant of Android malware is making rounds in the Google Play store and it is bad news all around. According to Trend Micro, a Trojan dubbed Xavier, which is embedded in more than 800 applications on Android’s app store, clandestinely steals and leaks personal data.

Mobile malware is not new to the Android platform, but Xavier is a little more clever. It downloads codes from a remote server, executes them, and uses a string encryption, Internet data encryption, emulator detection, and a self-protect mechanism to cover its tracks.

Recommended Videos

It is derived from AdDown, a family of malware that has been around for two years. But unlike most offshoots, Xavier features the troubling addition of encryption and a secure connection. Once it loads a file and obtains an initial configuration from a remote server, it detects, encrypts, and transmits information about the victim’s device — including the manufacturer, language, country of origin, installed apps, email addresses, and more — to a remote server.

According to Trend Micro, Xavier makes its remote capabilities tough to pin down by detecting whether it is running on an Android emulator, a type of software that mimics a device’s hardware components. It checks the device’s name, manufacturer, device brand, operating system version, hardware ID, SIM card operator, resolution, and does not run if it encounters an unexpected field.

Trend Micro’s analysis identified Xavier in apps from southeastern nations such as Vietnam, the Philippines, Indonesia, Thailand, Taiwan, and others, many of which appear to be innocuous on the surface. They range from utilities like photo editors to wallpaper and ringtone changers, and are typically free.

Trend Micro’s report follows the discovery of two other forms of Android malware earlier this year. In May, researchers at Check Point identified Judy, an auto-clicking adware which could have infected as many as 36.5 million Android devices. In March, Palo Alto Networks uncovered malware designed for Windows PCs in 132 apps on Google’s Play Store.

Google’s taking a proactive approach to the problem. The search giant has targeted security on Android over the past year, most recently with the introduction of the Google Play Protect platform. It says it has worked with 351 wireless carriers to shorten the time it takes to test security patches before deploying them to users — an effort that resulted in a reduction of the software approval process from six to nine weeks to just a week.

Google’s also doled out $1 million to independent security researchers and pursued an aggressive strategy of encryption. As of December, 80 percent of Android 7.x (Nougat) users secure their data with passwords, patterns, or PIN codes.

Adrian Ludwig, director of Android security at Google, pointed to social engineering — attacks that fool a user into installing an app that compromises his or her device’s security — as one of the biggest challenges facing app developers today. “People don’t want to think about security,” he told members of the press at the RSA conference in February. “They just want it to be that way.”

Kyle Wiggers
Former Digital Trends Contributor
Kyle Wiggers is a writer, Web designer, and podcaster with an acute interest in all things tech. When not reviewing gadgets…
Google is getting ready to remove lots of Android apps from the Play Store
Samsung Galaxy S23 showing Google Play Store

Starting next month, Google will require apps on the Play Store to provide a "stable, engaging, responsive user experience." If they don't, the company plans to eventually remove those apps from the store.

This policy is part of Google's latest spam policy update and is designed to eliminate apps with "limited functionality and content," such as text-only apps and single wallpaper apps. The new rules take effect on Saturday, August 31.

Read more
Google is making it easier to ditch your iPhone for an Android phone
Samsung Galaxy S24 Ultra and iPhone 15 Pro in hand.

Switching phones is never a smooth process, even if you’re switching between two different Android phones. However, when you’re trying to switch from an iPhone to Android or vice versa, it can be extra complicated -- and you can lose data and apps that you rely on. This is especially the case with Apple-to-Android transfers because the iPhone has a much stronger ecosystem lock-in with things like iMessage, iCloud backups, and exclusive apps like Overcast and Hyperlapse.

The good news is that with its Data Transfer Tool (also called Pixel Migrate on Pixel devices), Google may be trying to mitigate some of the phone-switching problems that arise -- specifically, losing access to your Live Photos. According to an APK teardown from Android Authority, Google’s Data Transfer Tool will finally resolve the problem of migrating iOS Live Photos to Android. It will do this by converting them over as Motion Photos.

Read more
The Google app on your Android phone is getting a helpful new feature
Google app on Android beta showing Notifications.

The Google app for Android phones is getting a helpful new feature to make search even better. The latest beta has a dedicated "Notifications" feed in its bottom bar. The feature was first introduced on the mobile version of Google for Android earlier this year. The app feature was first noticed by 9to5Google.

The app now includes a Notifications option at the bottom, next to Discover, Search, and Saved items. The Notifications section displays a continuous list of alerts from Google Search, weather conditions, flight information, sports scores, movies and TV shows, and more. The notifications are grouped under “Today” and “Earlier." This feature should prove handy if you miss a notification from the Google app, as it provides a more focused view than Android's system-level history.

Read more