New Android Malware xHelper Persists Through Resets

Xhelper Featured

A new strain of Android malware called xHelper is making the rounds. What makes it notable is how persistent it is, with some going so far as to say it’s unremovable! But what does xHelper do, and is it truly impenetrable?

What Is xHelper?

xHelper is a new strain of adware that’s infecting Android devices. So far, the infection numbers are relatively low, in malware standards. 45,000 units have been infected in total, and it has mostly hit users in the United States, Russia, and India.

xHelper isn’t too dangerous, but it is very annoying. It’s a strain of adware that constantly pops up advertisements on the victim’s phone. It doesn’t extract data or lock down the phone in any way, but the ads do give the distributor money if clicked.

Right now, nobody really knows how the infection starts. Symantec, one of the largest security corporations in the world, believes it’s installed via third-party apps downloaded from outside of Google Play.

Why Is xHelper “Unremovable?”

The problems starts when victims try to remove the malware. Uninstalling the app only has it come back to life. If the user uninstalls it and then tells Android to disallow app installations from third-party sources, the app manages to install itself anyway.

Xhelper Antivirus

The scariest part is when the user attempts a factory reset. xHelper persists through a wipe and returns once the phone reboots. Not even Symantec fully understands how it can survive through what is otherwise known as the “nuclear option.”

Users even report that paid antiviruses can’t fully get rid of xHelper. They can detect the infection, but removing it only causes it to return at a later date. The Internet has been buzzing with people trying to find a solution.

How xHelper Adapts

The main reason xHelper can get around an antivirus is due to its updates. The developers consistently update the malware to get around antivirus detection. As such, people with older versions of antiviruses will find it ineffective. Newer versions will have a better chance of stopping xHelper until the malware is patched to get around it.

Keeping Clear of xHelper

xHelper’s forte is how persistent it is. As such, your main defense – just like any other piece of malware – is not allowing it on your system in the first place. Unfortunately, its annoying habit of living past deletions means you can’t take risks and hope the antivirus will take care of it.

Xhelper Security

For the time being, only download apps from the Google App store. Even then, only download apps that have been around for a long time and that already have many downloads. The Google App store has been less than trustworthy with letting malware onto the store, and the adaptive nature of xHelper means that it can be engineered until it gets passed Google’s shields.

Some users have reported success by flashing a ROM instead of performing a factory reset. This does a clean sweep of the phone’s operating system, which may be the key to scrubbing out xHelper for good.

Not Very Helpful

xHelper’s adware-based attacks aren’t anything to write home about, but its persistence baffles even the most advanced antivirus developers. It’s a pain to get rid of, so avoid infection at all costs.

Does this new strain of malware scare you? Let us know below.

Subscribe to our newsletter!

Our latest tutorials delivered straight to your inbox

Simon Batt Avatar

Read next

When the SS Great Eastern laid the first working transatlantic telegraph cable in 1866, a message that had taken ten days by steamship suddenly crossed the ocean in minutes, and the financial markets of London and New York were forced, within a single trading week, to invent the modern concept of synchronised global price.
The Big Ear telescope was scanning at 1420.4056 megahertz on the night of 15 August 1977, the exact frequency at which hydrogen atoms vibrate across the universe, because Giuseppe Cocconi and Philip Morrison had argued years earlier that any species trying to be found would broadcast on that channel — and then, for 72 seconds, something did.
In 2016, archaeologists dated two rings of snapped stalagmites in France’s Bruniquel Cave to 176,500 years ago, evidence that Neanderthals had walked 336 metres into darkness with fire and built architecture deep underground long before modern humans reached Europe
Otto von Bismarck was 74 when Germany adopted the world’s first national old-age social insurance program in 1889, setting the pension age at 70 after years of fighting socialists with bans, laws, and a promise few workers would live long enough to use
When cosmonaut Valeri Polyakov stepped out of his Soyuz capsule in March 1995 after 437 consecutive days aboard Mir, doctors recorded him at several centimetres above his pre-flight height, and his spine had become so unaccustomed to gravity that the recovery team carried him to a chair rather than risk the compression of letting him walk.
When Bell Labs engineer Karl Jansky pointed a rotating antenna at the sky in 1932 looking for sources of transatlantic radio static, he kept picking up a faint hiss that peaked every 23 hours and 56 minutes, and he eventually realized he had become the first human to hear the center of the Milky Way.
When Harvard astronomer Cecilia Payne submitted her 1925 doctoral thesis arguing that the Sun was made almost entirely of hydrogen, the field’s senior figure Henry Norris Russell talked her into adding a line calling the result ‘almost certainly not real,’ and then published the same conclusion himself four years later to widespread acclaim.
When seismic waves from the Chicxulub impact reached what is now North Dakota roughly ten minutes after the asteroid struck, they appear to have triggered a ten-metre standing wave in an inland river that flung fish onto the bank and buried them under glass beads still falling from the sky.