Android smartphones found with pre-installed malware

Enterprise devices arrived 'already infected with adnets and ransomware'

Certain devices from some of the largest Android smartphone manufacturers have been discovered carrying severe malware infections that were manually implanted at some point during their supply chain process, according to an investigation.

Although malware is something normally associated with users accidently downloading malicious files, it appears compromising apps were added to specific devices during their build, and were not part of the official ROM.

Thiry-eight smartphones manufactured by Samsung, Lenovo, LG, Asus, Vivo, Oppo, ZTE and Xiaomi were identified as being affected.

The Android devices, belonging to an unnamed telecommunications company and a multinational technology company, were spotted carrying the malicious apps, which were added at an unknown point during the supply chain, according to research by Check Point Mobile Threat Prevention.

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

Researchers identified six instances of malware infection that were deliberately added by a "malicious actor" to the device's ROM using escalated system privileges, meaning the apps could only be removed by a device re-flash, a complex process of restoring it to factory settings.

"As a general rule, users should avoid risky websites and download apps only from the official and trusted app stores. However, following these guidelines is not enough to ensure their security," said cyber analyst Oren Koriat, speaking in a Check Point Mobile Research blog.

The pre-installed malware was mostly designed to steal information, but included a mobile ransomware called Slocker, which uses an algorithm to encrypt every file on a device and then demand a ransom in exchange for a decrypt key.

A malicious adnet was also discovered in six mobile devices, specifically a malware called Loki that uses multiple layers of functions to achieve its goal. The malware displays illegitimate ads to users as a means of generating revenue, while stealing device data in the process.

"Pre-installed malware compromise the security even of the most careful users. A user who receives a device already containing malware will not be able to notice any change in the device's activity which often occur once a malware is installed," added Koriat. "To protect themselves from regular and pre-installed malware, users should implement advanced security measures capable of identifying and blocking any abnormality in the device's behavior."

Below is a full list of the devices discovered with pre-installed malicious apps. IT Pro has contacted all the vendors for comment.

Malware

Device

com.fone.player1Galaxy Note 2, LG G4
com.lu.compassGalaxy S7, S4
com.kandian.hdtogoappGalaxy Note 4, Galaxy Note 8
com.sds.android.ttpodGalaxy Note 2, Xiaomi Mi 4i
com.baycode.mopGalaxy A5
com.kandian.hdtogoappGalaxy S4
com.iflytek.ringdiyclientZTE x500
com.android.deketvGalaxy A5
com.changbaGalaxy S4, Galaxy Note 3, Galaxy Note Edge, Galaxy Note 4
com.example.loaderGalaxy Tab 2
com.armorforandroid.securityGalaxy Tab 2
com.android.ys.servicesOppo N3, Vivo X6 plus
com.mobogenie.daemonGalaxy S4
com.google.googlesearchAsus Zenfone 2, Lenovo S90
com.skymobi.mopoplay.appstoreLenovoS90
com.example.loaderOppo R7 plus
com.yongfu.wenjianjiaguanliXiaomi Redmi
air.fyzb3Galaxy Note 4
com.ddev.downloader.v2Galaxy Note 5
com.mojang.minecraftpeGalaxy Note Edge
com.androidhelper.sdkLenovo A850
Featured Resources

How inkjet can transform your business

Get more out of your business by investing in the right printing technology

Download now

Journey to a modern workplace with Office 365: which tools and when?

A guide to how Office 365 builds a modern workplace

Download now

Modernise and transform your sales organisation

Learn how a modernised sales process can drive your business

Download now

Your guide to managing cloud transformation risk

Realise the benefits. Mitigate the risks

Download now
Advertisement

Recommended

Visit/malware/33080/hackers-abuse-linkedin-dms-to-plant-malware
malware

Hackers abuse LinkedIn DMs to plant malware

25 Feb 2019
Visit/security/malware/28083/the-five-best-free-malware-removal-tools
Security

Best free malware removal tools 2019

23 Dec 2019
Visit/antivirus/28144/best-antivirus
antivirus

Best antivirus for Windows 10

3 Sep 2019

Most Popular

Visit/cloud/cloud-computing/354767/google-cloud-snaps-up-multi-cloud-analytics-platform-for-26bn
cloud computing

Google Cloud snaps up multi-cloud analytics platform for $2.6bn

13 Feb 2020
Visit/mobile/28299/how-to-use-chromecast-without-wi-fi
Mobile

How to use Chromecast without Wi-Fi

5 Feb 2020
Visit/cloud/microsoft-azure/354771/microsoft-azure-is-a-testament-to-satya-nadellas-strategic-nouse
Microsoft Azure

Microsoft Azure is a testament to Satya Nadella’s strategic nouse

14 Feb 2020
Visit/operating-systems/27717/how-to-fix-a-stuck-windows-10-update
operating systems

How to fix a stuck Windows 10 update

12 Feb 2020