{"id":232027,"date":"2026-04-06T21:40:00","date_gmt":"2026-04-07T01:40:00","guid":{"rendered":"https:\/\/news-you-need.com\/index.php\/2026\/04\/06\/researchers-find-50-dangerous-android-apps-that-are-secretly-hijacking-phones-who-is-at-risk\/"},"modified":"2026-04-07T04:30:45","modified_gmt":"2026-04-07T08:30:45","slug":"researchers-find-50-dangerous-android-apps-that-are-secretly-hijacking-phones-who-is-at-risk","status":"publish","type":"post","link":"https:\/\/news-you-need.com\/index.php\/2026\/04\/06\/researchers-find-50-dangerous-android-apps-that-are-secretly-hijacking-phones-who-is-at-risk\/","title":{"rendered":"Researchers find 50 \u2018dangerous\u2019 Android apps that are secretly hijacking phones: Who is at risk"},"content":{"rendered":"<p><a href=\"https:\/\/timesofindia.indiatimes.com\/technology\/tech-news\/researchers-find-50-dangerous-android-apps-that-are-secretly-hijacking-phones-who-is-at-risk\/articleshow\/130070852.cms\">Researchers find 50 \u2018dangerous\u2019 Android apps that are secretly hijacking phones: Who is at risk<\/a><\/p>\n<p><a href=\"https:\/\/timesofindia.indiatimes.com\/technology\/tech-news\/researchers-find-50-dangerous-android-apps-that-are-secretly-hijacking-phones-who-is-at-risk\/articleshow\/130070852.cms\">https:\/\/timesofindia.indiatimes.com\/technology\/tech-news\/researchers-find-50-dangerous-android-apps-that-are-secretly-hijacking-phones-who-is-at-risk\/articleshow\/130070852.cms<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-04-06 21:40:00<\/a><\/p>\n<p>Source Domain: <a href=\"timesofindia.indiatimes.com\">timesofindia.indiatimes.com<\/a><\/p>\n<p>  If you have downloaded a phone cleaner, a puzzle game or a photo utility from the Google Play Store in recent months, there is a chance your device may have been hacked. Researchers from Cybersecurity company McAfee has claimed that it uncovered a sophisticated Android malware campaign that had been hiding inside more than 50 apps available on Google Play. Together, those apps \u2013 which have now been removed from the Android app store \u2013 were downloaded more than 2.3 million times before being removed from the platform, it said. <span class=\"id-r-component br\" data-pos=\"5\"\/><\/p>\n<p><h2>How the attack worked<\/h2>\n<\/p>\n<p>Called Operation NoVoice, the campaign involves apps that look and behave completely normally but security experts classify this as a rootkit attack which is one of the most dangerous and difficult-to-detect forms of malware. A rootkit is designed to burrow deep into a device\u2019s operating system, granting attackers administrator-level control while hiding all traces of its presence from the user and the phone&#8217;s standard security tools. <span class=\"id-r-component br\" data-pos=\"11\"\/>When a user downloaded one of the affected apps, it appeared to function exactly as advertised like cleaning junk files, running games and\/or managing photos. There were no warning signs. Behind the scenes, however, the app was quietly contacting a remote server controlled by the attackers, sending back details about the device including its hardware, operating system version and security patch level.<span class=\"id-r-component br\" data-pos=\"13\"\/>Based on that information, the attackers sent back custom exploit code tailored specifically to that particular device. If the exploit succeeded, the malware gained root-level access, which is the maximum level of control possible on an Android device. From there, it modified a core Android system library that every app on the phone relies on. The result: attacker-controlled code could run silently inside any app the user opened.<span class=\"id-r-component br\" data-pos=\"17\"\/>While most malware can be removed by performing a factory reset, Operation NoVoice was designed to survive one. Fully removing it, McAfee warns, may require&#8230;<br \/>\n<br \/><a href=\"https:\/\/timesofindia.indiatimes.com\/technology\/tech-news\/researchers-find-50-dangerous-android-apps-that-are-secretly-hijacking-phones-who-is-at-risk\/articleshow\/130070852.cms\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Researchers find 50 \u2018dangerous\u2019 Android apps that are secretly hijacking phones: Who is at risk&#8230;<\/p>\n","protected":false},"author":1,"featured_media":232028,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/static.toiimg.com\/thumb\/msid-130070845,width-1280,height-720,imgsize-465281,resizemode-6,overlay-toi_sw,pt-32,y_pad-600\/photo.jpg","fifu_image_alt":"","footnotes":""},"categories":[46],"tags":[31,70,32,57],"class_list":["post-232027","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-android","tag-exploit","tag-google","tag-malware","tag-security"],"_links":{"self":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/232027"}],"collection":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=232027"}],"version-history":[{"count":1,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/232027\/revisions"}],"predecessor-version":[{"id":232029,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/232027\/revisions\/232029"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/232028"}],"wp:attachment":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=232027"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=232027"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=232027"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}