Factory resets aren’t helping. Neither are mobile antivirus solutions. Malware keeps reinstalling itself.

Over the past six months, a new Android malware strain has made a name for itself after popping up on the radar of several antivirus companies, and annoying users thanks to a self-reinstall mechanism that has made it near impossible to remove.

Named xHelper, this malware was first spotted back in March but slowly expanded to infect more than 32,000 devices by August (per Malwarebytes), eventually reaching a total of 45,000 infections this month (per Symantec).

The malware is on a clear upward trajectory. Symantec says the xHelper crew is making on average 131 new victims per day and around 2,400 new victims per month. Most of these infections have been spotted in India, the US, and Russia.

Installed via third-party apps

According to Malwarebytes, the source of these infections is “web redirects” that send users to web pages hosting Android apps. These sites instruct users on how to side-load unofficial Android apps from outside the Play Store. Code hidden in these apps downloads the xHelper trojan.

The Good News

The good news is that the Trojan doesn’t carry out destructive operations. According to both Malwarebytes and Symantec, for most of its operational lifespan, the Trojan has shown intrusive popup ads and notification spam. The ads and notifications redirect users to the Play Store, where victims are asked to install other apps — a means through which the xHelper gang is making money from pay-per-install commissions.

“Unremovable”

Furthermore, even if users spot the xHelper service in the Android operating system’s Apps section, removing it doesn’t work, as the Trojan reinstalls itself every time, even after users perform a factory reset of the entire device.

How xHelper survives factory resets is still a mystery; however, both Malwarebytes and Symantec said xHelper doesn’t tamper with system services system apps. In addition, Symantec also said that it was “unlikely that Xhelper comes preinstalled on devices.”

Next steps

We need to wait and see. The malware protection companies have identified the App. It is always important to run protection on every device. We have solutions for all types of devices. Call us for more information.