Technology
Beware of a new Android threat targeting your photos and texts without even opening them
What is malware?
Kurt ‘CyberGuy’ Knutsson discusses how to protect yourself from malware and ransomware.
Another day, another malware threat is trying to get your data.
Well, brace yourself, because there’s a virus that’s been around for a while that’s out there that’s gotten even worse.
It’s called XLoader, and it’s after your photos and texts on your Android device. Yes, you heard that right.
Your precious memories and messages are in danger of being snatched by this malicious software.
CLICK TO GET KURT’S FREE CYBERGUY NEWSLETTER WITH SECURITY ALERTS, QUICK VIDEO TIPS, TECH REVIEWS, AND EASY HOW-TO’S TO MAKE YOU SMARTER
Android phone. (Kurt “CyberGuy” Knutsson)
What is malware?
Malware is technically any software that’s designed to disrupt the system of its intended target. With malware, the person or entity behind the attack can gain access to your data, leak sensitive information, block you out and take control of other aspects of your privacy and security.
MORE: TIPS TO FOLLOW FROM ONE INCREDIBLY COSTLY CONVERSATION WITH CYBERCROOKS
What is the XLoader malware strain?
According to McAfee, the XLoader malware — also known as MoqHao — has been around since 2015, targeting Android users in the U.S., Europe and Asia. Once it’s on your device (which it’s gotten much better at doing), it’s able to run in the background, taking your sensitive data, whether it be photos, text messages, contact lists, hardware details and more.
Hacker typing on a laptop. (Kurt “CyberGuy” Knutsson )
MORE: BEWARE OF NEW ANDROID MALWARE HIDING IN POPULAR APPS
How does XLoader get onto your device?
One of the reasons XLoader is such a major threat is because, unlike its previous strains and other malware, it can get on your device that much easier than before. Generally, malware gets onto your device via a phishing scam. However, because people are more skeptical about opening or clicking on suspicious files or links — and because there are integrated apps that help warn you of these files — it’s more difficult for these traditional phishing scams to be effective, but XLoader has gotten clever.
First, you receive a text from an unknown sender
Like ordinary malware, XLoader often spreads through malicious links sent via text messages. This is a unique type of phishing scam known as “smishing.” However, scammers are aware that most people don’t click on texts from people they don’t know. So, another way they attempt to be successful at this is by first gaining access to a phone number that has your number in their contacts, and they target you that way. You won’t think twice when you receive a text from someone you know. Once it gets past this step, XLoader can get onto your Android device in two ways:
1: You click on the link which leads to downloading the APK file
Next, the unsuspecting victim would see a link in the text message. The link may look less suspicious than typical malware links because they are typically shortened and look less spammy and more legitimate, like a link that someone you know would send you.
A RANSOMWARE REALITY CHECK AS US IS A TOP TARGET OF ATTACKS
If you end up clicking on this link, it will direct you to download an Android APK file (standard file format for Android), which are files that are used to sideload apps outside the official Google Play Store. This method, therefore, bypasses Google’s security measures and increases the risk of malware infections. It can happen in a matter of seconds, and if you click “install,” then the XLoader malware will be on your phone before you know it.
Once the malicious APK is downloaded and installed, XLoader can launch on its own without any further action from the user, silently running in the background and performing its malicious activities.
2: You launch the app yourself, but fall for a Google Chrome decoy
If you decide you want to launch the app directly on your own, XLoader is already there waiting for you by impersonating Google Chrome. When you click “launch,” the XLoader malware displays a very familiar-looking Chrome pop-up that will first ask you to grant it permissions by clicking “allow” or “deny.” If you click “Allow” (thinking it’ll lead you to the “app”), you’ll be unknowingly giving it access to your SMS.
Afterward, it will even display a pop-up that says, “Choose Chrome to prevent spam,” giving you two options — your default SMS app or Chrome. Because these decoy pop-ups replicate Google’s style completely, it gives the user a false sense of security that it can be trusted.
Once it’s there, it can grab your photos, texts and other sensitive data on your Android, most of the time, without you even realizing it.
Google Chrome decoy. (McAfee)
6 ways to protect your Android from XLoader and other malware
Now that you know what XLoader is and how it gets onto your Android device, be sure not to click on any links in text messages that are unusual. If the text came from someone in your contacts, reach out to them directly (via phone call or messaging on another app) and confirm that they meant to send you it before clicking on it. Here are some other ways to protect yourself from XLoader and other malware attempts.
1. Avoid sideloading apps and shortened URLs: Refrain from sideloading apps (installing apps from unofficial sources) and clicking on shortened URLs in messages, as these are common vectors for malware distribution.
2. Be careful granting permissions: Exercise caution when granting permissions to apps. The question is whether an app truly needs access to certain device functions or data.
3. Limit the apps you have on your phone: Sometimes, having a lot of apps on your phone can make it easy for you to be exposed to malware. These apps can let in malicious code over time, and the more apps you have to keep track of and update, the more likely your Android will be vulnerable.
4. Only download reputable apps: Additionally, when you download apps, make sure they are from reliable and legitimate developers. Check reviews and do some research before just hitting “install.”
5. Don’t neglect software updates: Your phone has a way of keeping itself safe with software and security updates. Don’t forget to do them.
6. Have good antivirus software on all your devices: The best way to protect yourself from malware like this Xloader virus is to install antivirus protection on all your devices. Having antivirus software on your devices will make sure you are stopped from clicking on any potential malicious links that may install malware on your devices, allowing hackers to gain access to your personal information. Get my picks for the best 2024 antivirus protection winners for your Windows, Mac, Android & iOS devices.
Kurt’s key takeaways
Malware is, unfortunately, inevitable. As we become more educated about how to prevent these threats, the hackers creating them are always working on ways to outsmart us, while the malware itself becomes more sophisticated. This new strain of XLoader is just one example of that. And, while it’s currently focused on targeting Android users, it’ll likely be just a matter of time before it begins targeting Macs and other devices.
The best way to protect yourself, therefore, is to stay up-to-date with the latest cybersecurity trends and ensure your devices have good antivirus protection. Additionally, continue best practices for protecting yourself from suspicious links and downloads.
How stressed are you these days with malware like XLoader or other types of viruses trying to steal your data? Should more be done to stop these crooks? Let us know by writing us at Cyberguy.com/Contact
For more of my tech tips and security alerts, subscribe to my free CyberGuy Report Newsletter by heading to Cyberguy.com/Newsletter
Ask Kurt a question or let us know what stories you’d like us to cover.
Answers to the most asked CyberGuy questions:
Copyright 2024 CyberGuy.com. All rights reserved.
Technology
Microsoft is disabling Office 2019 for Mac next month
Microsoft’s Office 2019 apps for Mac will stop working next month, because the company isn’t renewing a certificate that validates Office licenses. Owners of Office 2019 for Mac are being warned they’ll have to purchase Office 2024 or a Microsoft 365 subscription if they want to continue editing documents.
Microsoft previously promised that “all your Office 2019 apps will continue to function,” when it announced end of support in 2023. The company then quietly updated that support note last month to remove the mention of apps continuing to function, replacing it with “Rest assured that all your Office 2019 apps won’t lose any data.”
Starting on July 13th, Office 2019 for Mac and Office 2021 for Mac will both run in “reduced functionality mode,” allowing people to open files but not edit, save, or create new documents. The reduced functionality will impact Word, Excel, PowerPoint, Outlook, and OneNote.
While Microsoft is providing a certificate update for Office 2021 as it’s still supported until October 13th, 2026, the company is leaving Office 2019 for Mac users out in the cold as support for these apps ended a few years ago. “Office 2019 for Mac reached end of support on October 10, 2023, and no longer receives updates,” says Microsoft. “Because Office 2019 cannot be updated to the required version, this issue cannot be resolved by updating or reinstalling Office 2019 for Mac.”
JimmyTech points out that old versions of Microsoft 365 apps on Mac and iOS will also be affected by this certificate issue, but a simple update will fix it for those users.
Microsoft regularly ends support of software and there’s always the risk you could run into issues running older apps or versions of Windows. It’s still surprising to not see Microsoft make an exception here though, particularly because this certificate issue breaks the main functionality of an app you’ve paid a one-time license fee for.
Technology
Android fake call detection warns you about scams
NEWYou can now listen to Fox News articles!
You know that little moment when your phone rings and the name on the screen makes you drop everything?
Maybe it says your spouse, your daughter, your boss or your best friend. You answer because you trust the name. Then the voice sounds familiar too.
That is exactly what makes the latest phone scams so dangerous.
Android’s fake call detection can warn you when a caller may be pretending to be someone saved in your contacts. (Silas Stein/Picture Alliance)
Scammers no longer have to call from a strange number. They can spoof a trusted contact’s phone number. Then they can use AI voice tools to sound like someone you know. Android is now rolling out a new feature called fake call detection to help warn you when that familiar call may be a fake.
FAKE AGENT PHONE SCAMS ARE SPREADING FAST ACROSS THE US
Join CyberGuy Live: Lock Down Your Phone in 30 Minutes (Saturday, June 13, 10 am ET)
- Your phone holds your email, passwords, photos, banking apps and personal data. In this free, live online class, Kurt the CyberGuy will walk you step by step through simple phone security fixes you can do in real time. You’ll learn how to improve your privacy settings, spot the latest phone scams, use trusted security tools and walk away with a simple checklist to stay protected. Register here: CyberGuyLive.com
What is Android fake call detection?
Android fake call detection is a new protection built into Phone by Google. It is designed to spot suspected spoofed calls when both people on the call use Phone by Google.
Think of it as your phone quietly asking, “Is this call really coming from that person’s device?” If the answer looks suspicious, your phone can show a warning and advise you to hang up. That small alert could stop a scam before fear, panic or confusion takes over.
ANDROID SECURITY UPGRADES OUTSMART SCAMS AND PROTECT YOUR PRIVACY
How Android fake call detection works
The feature works automatically in the background. You do not need to answer a quiz, scan a code or press a button during the call. When a trusted contact calls you, their phone sends a silent confirmation signal to your phone. That signal helps prove the call really came from their device.
If a scammer spoofs your contact’s number, that confirmation signal may be missing. Your phone then checks with your contact’s actual device. If the real device says it is not placing a call, your screen can warn you that the call may be fake.
The system uses end-to-end encrypted RCS technology, so the check happens privately. You can also turn the feature off in Phone by Google settings.
AI DEEPFAKE ROMANCE SCAM STEALS WOMAN’S HOME AND LIFE SAVINGS
Why fake calls are getting harder to spot
For years, caller ID gave people a sense of control. If the name looked familiar, most of us felt safer picking up. That old habit now works in the scammer’s favor.
Scammers can use internet-based calling tools to spoof numbers. That means your phone may display the name of someone you trust, even though the call comes from somewhere else.
Then comes the AI voice trick. With today’s audio tools, scammers can make a fake voice sound shockingly real. They may pretend to be a family member in trouble, a bank employee warning about fraud or a manager asking for urgent help.
SCAMMERS EXPLOITED MOM’S FEARS TO STEAL HER ENTIRE LIFE’S SAVINGS
That combination makes the call feel personal and immediate. It also makes you more likely to act before you think.
Why Android is adding this protection now
Impersonation scams have become a major global problem. INTERPOL’s March 2026 Global Financial Fraud Threat Assessment cited impersonation fraud as one of the leading contributors to more than $400 billion in global losses.
In the U.S., impersonation scams remain one of the top fraud categories reported to the FTC. Losses reached $2.95 billion in 2024.
GLOBAL SCAM CRACKDOWN LEADS TO 276 ARRESTS
Those numbers tell you why this feature deserves attention. Scammers go where the money is. Right now, they know trusted voices and trusted names can open the door.
Which Android phones get fake call detection?
Google says fake call detection is rolling out globally in Phone by Google this month, starting with Pixel devices.
The feature is available on Android 12 and newer devices with Phone by Google, Contacts and Google Messages installed. It also requires RCS capability in Google Messages.
SAMSUNG MESSAGES ENDING? WHAT ANDROID OWNERS MUST KNOW
There is one key limitation. Both you and the person calling you must use Phone by Google for fake call detection to work.
Phone by Google already comes as the default phone app on many Android devices. If your phone uses a different calling app, you can install Phone by Google from the Play Store and set it as your default phone app.
How Android fake call detection protects you
This feature gives you an extra warning at the exact moment you need it most. That timing is important. Scam calls often rely on emotion. The caller may say someone got arrested, a loved one had an accident or a bank account faces an urgent threat.
SSA IMPERSONATION SCAMS ARE GETTING MORE PERSONAL
When the voice sounds familiar, your guard drops. A warning on your screen can interrupt that emotional rush. It gives you a reason to stop, hang up and verify the story another way.
What Android fake call detection cannot do
This new tool helps, but it cannot protect you from every scam. It may not work if the other person does not use Phone by Google. It also may not cover calls from businesses, unknown numbers or contacts using unsupported devices. So you still need basic scam rules.
If someone asks for money, gift cards, crypto, account codes or remote access to your device, hang up. Then call the person or company back using a number you already trust.
Also, never stay on the line just because the caller tells you to. That is one of the oldest pressure tactics in the scammer playbook.
A spoofed call can look familiar on your screen, even when it is really coming from a scammer. (Kurt CyberGuy Knutsson)
How to protect yourself from AI voice scams
AI voice scams work because they sound personal, urgent and believable, so your best defense is to slow the conversation down before you act.
1) Create a family safe word
Pick a simple word or phrase that only your close family knows. It should be easy to remember but hard for a scammer to guess. Then, if someone calls with an emergency and asks for money, ask for the safe word. If they cannot give it, hang up and verify the story another way.
9 WAYS SCAMMERS CAN USE YOUR PHONE NUMBER TO TRY TO TRICK YOU
2) Pause when the call feels urgent
Scammers want you scared because fear makes people act fast. That is why fake emergency calls often sound intense, emotional and rushed. Take a breath before you do anything. A real loved one, bank or employer will let you verify what is happening.
3) Call back using a trusted number
If a call feels suspicious, hang up. Then call the person back using a number saved in your contacts or one you know is real. Do not use a number, link or instruction the caller gives you. That could send you right back to the scammer.
4) Never send money or codes during the call
Do not send gift cards, crypto, wire transfers or payment app transfers because a caller sounds convincing. Also, never share a one-time passcode, PIN or account login code over the phone. Once scammers get that information, they can move fast.
5) Turn on scam protections on your phone
Use the built-in protections already available on your device. Pixel and Samsung users can enable Scam Detection in the Phone by Google app to help flag suspicious calls. Also, consider using strong antivirus software that includes AI-powered scam protection to help detect scams in texts, online content and deepfake videos. Keep an eye on call warnings too. If your phone tells you something looks risky, treat that alert seriously. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android & iOS devices at Cyberguy.com
6) Keep your phone apps updated
Update Phone by Google, Google Contacts and Google Messages when updates are available. These tools work best when your apps and phone software stay current. Updates often include security improvements, bug fixes and new scam protections.
Here’s how to check for updates on Android:
- Open the Google Play Store app.
- Tap your profile icon in the top right corner.
- Tap Manage apps & device.
- Under Updates available, tap See details.
- Look for Phone by Google, Google Contacts and Google Messages.
- Tap Update next to each app, or tap Update all.
You can also turn on automatic app updates by opening the Google Play Store app, tapping your profile icon, then going to Settings > Network preferences > Auto-update apps. From there, choose whether to update apps over Wi-Fi, over Wi-Fi or mobile data, with limited mobile data or not at all.
Kurt’s key takeaways
If a call feels urgent or suspicious, pause before you respond and verify it another way. (Tristan Spinski/The Washington Post via Getty Images)
Android’s fake call detection is a smart step in the fight against AI-powered phone scams. It recognizes something many people already know: the name on your caller ID no longer proves the person calling you is real. This feature gives Android users another layer of protection when scammers try to hijack trust. Still, the safest move remains simple. Slow down, verify the call and never let panic make the decision for you.
Should the government do more to stop scammers from using AI voices to impersonate the people you trust? Let us know by writing to us at CyberGuy.com
Sign up for my FREE CyberGuy Report
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
- Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
- For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com – trusted by millions who watch CyberGuy on TV daily.
- Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.
Copyright 2026 CyberGuy.com. All rights reserved.
Technology
Congress just gave DHS another $70 billion
Congress narrowly voted to fund President Donald Trump’s mass deportation agenda, giving the Department of Homeland Security $70 billion over the next three years.
The house voted 214 to 212 in favor of the reconciliation bill Tuesday, following the Senate’s 52-47 vote last Friday morning. The vote fell largely along party lines. Sen. Lisa Murkowski (R-AK) was the only Senate Republican to vote against it. Rep. Tim Walberg (R-MI), initially voted against the bill — meaning it would have failed — but changed his vote after huddling with House Majority Leader Steve Scalise (R-LA) and Appropriations Chair Tom Cole (R-OK), according to The Hill. No Democrats voted in favor of the funding bill, which was done through a budget reconciliation process to avoid a Democratic filibuster.
In a speech on the House floor ahead of the Tuesday vote, Rep. Mary Gay Scanlon (D-PA) criticized Republicans for using the budget reconciliation process to avoid negotiating with Democrats, and emphasized ICE’s lack of popularity with the American people.
“At its core, this Republican reconciliation budget bill is a statement about priorities, and the priorities represented in this budget bill could not be more out of step with the needs and values of the American people,” Scanlon said.
Scanlon noted that DHS has yet to spend $100 billion of the nearly $200 billion it received under Trump’s One Big Beautiful Bill Act. She added that Trump has not only expanded ICE’s reach by increasingly going after legal immigrants but also weaponized DHS against its critics. The bill, she said, will “supercharge” Trump’s abuses.
After the House markup last Friday, Rep. Rosa DeLauro (D-CT), ranking member of the House Appropriations Committee, noted that the bill not only lacks sufficient reforms but also cuts funding for cybersecurity and TSA, whose workers went weeks without pay during the DHS shutdown.
The funding bill comes at a time of deep unpopularity for ICE. One recent poll found that just 33 percent of voters approve of how the agency is doing its job.
And it comes amid yet another threat from border czar Tom Homan to flood New York City with ICE agents. In an interview with Fox News on Monday, Homan said he would send “more ICE agents than you’ve ever seen” to New York City if the state government passed a bill limiting cooperation with DHS.
“Providing a quarter trillion dollars to an administration promising that the public ‘ain’t seen shit yet’ when it comes to mass deportation is a historic mistake,” Todd Schulte, president of the immigration reform group FWD.us, said in a statement. “Supercharging the funding for these already out of control systems will come with terrible human consequences and continue to be met with increasing opposition from voters.”
Correction, June 9th: A previous version of this story said Rep. Tim Walberg voted against the funding bill. He initially voted against it but then changed his vote to support it.
Update, June 9th: This story has been updated to include comment from FWD.us president Todd Schulte.
-
Milwaukee, WI1 minute ago50 electric school buses to transport MPS kids starting this fall
-
Atlanta, GA7 minutes agoAtlanta Dream hold off Chicago Sky 82-75, Rhyne Howard becomes youngest player to hit rare WNBA milestone
-
Minneapolis, MN13 minutes agoOperation Metro Surge cost Minneapolis $700 million, city leaders say
-
Indianapolis, IN16 minutes agoPerson fatally shot on north side of Indianapolis
-
Pittsburg, PA21 minutes ago12+ things to do this weekend, from Pogopalooza and PizzaFest to the Beers of the Burgh Festival
-
Augusta, GA28 minutes ago
World Cup: Where to find a crowd to catch all the action
-
Washington, D.C31 minutes agoPermanent jewelry and pop-ups: Forever Adorned brings custom pieces to your stack
-
Cleveland, OH36 minutes agoOhio House passes Amanda Dean’s Law