38 popular Android devices ship with malware already installed

   #1  

vreihen

Verified VCDS User
Verified
Joined
Sep 6, 2014
Messages
5,043
Reaction score
6,395
Location
The Land of OCC, NY, USA
VCDS Serial number
C?ID=31688
With apparent supply chain security problems like this, I wonder why the batteries are exploding..... :p

https://bgr.com/2017/03/13/android-malware-spyware-check-point-report/

38 popular Android devices ship with malware already installed

Mike Wehner @MikeWehner
March 13th, 2017 at 9:02 PM

Keeping malware off of your mobile device should be a top priority for anyone who purchases a new smartphone or tablet, but what if the battle against bad actors has been lost before you even open the box? That’s exactly what security firm Check Point says is happening right now, and it just released a report claiming that it detected malware on 36 different Android devices being used by multiple large tech companies.

The devices on which the malicious code was detected are thought to have been compromised at some point between manufacturing and eventual sale to the end user. “The malicious apps were not part of the official ROM supplied by the vendor,” Check Point’s Mobile Threat Prevention team explains in a blog post, adding that the malware must have been added “somewhere along the supply chain.”

In Check Point’s investigation, the devices that were shown to have preinstalled malware come from many different manufacturers. They include: Galaxy Note 2, 3, 4, 5, and 8, Asus Zenfone 2, LG G4, Nexus 5 and 5X, and Xiaomi Mi 4i and Redmi.

For better or worse, the malware found to be installed on the devices is fairly well known in mobile security circles and includes Loki, a malicious advertising bot, and Slocker, which uses the Tor network to send data back to its creator while avoiding detection. This is obviously a very serious situation, and it’s certainly not the first time Android devices were found to have security issues right out of the box. Check Point hasn’t revealed what company the devices belonged to, but that might not actually matter in the grand scheme of things, as it appears preinstalled malware is becoming something of a trend on Google’s mobile OS.
 
   #2  

Uwe

Benevolent Dictator
Administrator
Joined
Jan 29, 2014
Messages
49,302
Reaction score
33,825
Location
USA
VCDS Serial number
HC100001
The malicious apps were not part of the official ROM supplied by the vendor,”
So carrier bloatware is now carrier malware?

-Uwe-
 
   #3  

Greg Elmassian

Verified VCDS User
Verified
Joined
Oct 3, 2016
Messages
24
Reaction score
23
Location
Carlsbad, California, USA
VCDS Serial number
C?ID=53943
root your phone... don't buy anything you cannot root... then lock it down with the right apps like permission manager, titanium backup, etc.

Greg
 
   #4  

vreihen

Verified VCDS User
Verified
Joined
Sep 6, 2014
Messages
5,043
Reaction score
6,395
Location
The Land of OCC, NY, USA
VCDS Serial number
C?ID=31688
root your phone... don't buy anything you cannot root... then lock it down with the right apps like permission manager, titanium backup, etc.

Sounds too much like work to me! i just want to pick up the phone and dial, not take on a second career managing phone security.

My first cell phone was a GE Carfone XR, sort of like this one only permanently mounted and not portable:

s-l1600.jpg


Three watts, dual NAM, *923885# to program it, and no Darth Vader digital sound because it used easy-to-tap analog AMPS cellular service. If they didn't shut down analog AMPS/CDMA, I'd still be using it today.....
 
   #5  

Uwe

Benevolent Dictator
Administrator
Joined
Jan 29, 2014
Messages
49,302
Reaction score
33,825
Location
USA
VCDS Serial number
HC100001
^ Not compatible with VCDS-Mobile though. :p
 
   #6  

vreihen

Verified VCDS User
Verified
Joined
Sep 6, 2014
Messages
5,043
Reaction score
6,395
Location
The Land of OCC, NY, USA
VCDS Serial number
C?ID=31688
It couldn't even send a text message or save a name with the 9 memory speed dials...in other words the PERFECT phone. (It even honked the car horn for an incoming call!) Well, it would have been better if it came rotary dial..... :)
 
Back
Top