Android/Trojan.Dropper.xHelper

ThreatDown is now the name of the Malwarebytes line of business products. References to Malwarebytes below reflect the amazing technology used to first identify the threat.

Short bio

Android/Trojan.Dropper.xHelper is Malwarebytes’ detection name for a Trojan.Dropper targeting Android devices.

Type of infection

Android/Trojan.Dropper.xHelper drops an encrypted DEX file with a .jar extension on the affected devices. Android/Trojan.Dropper.xHelper is most likely being spread by web redirects.

Malicious behavior

Users may notice an icon in the notifications entitled “xhelper” and after a few minutes the Trojan starts adding even more icons to the notifications. Other users may spot the presence of a simple xhelper entry in the Apps Info.

Protection

Malwarebytes for Android protects against Android/Trojan.Dropper.xHelper.

Home remediation

Malwarebytes for Android is able to remove Android/Trojan.Dropper.xHelper.