Skip to main content
  1. Home
  2. Phones
  3. Android
  4. Mobile
  5. News

Google flags preinstalled malware as hidden threat on millions of Android phones

Add as a preferred source on Google

Maddie Stone, a security researcher on Google’s Project Zero and a former tech lead on the Android Security team, flagged preinstalled malware on millions of new Android smartphones as a hidden threat that requires more attention.

Stone shared her team’s findings at the Black Hat USA 2019 conference in Las Vegas, in a presentation in which she said that a smartphone may have as many as 400 preinstalled apps out of the box. This is a major problem because attackers are attempting to hide malware in the preinstalled apps, as it is easier to convince one manufacturer to agree to a preloaded app than to convince thousands of users to download an infected file.

Recommended Videos

“If malware or security issues come as preinstalled apps,” Stone warned, “then the damage it can do is greater, and that’s why we need so much reviewing, auditing, and analysis.”

The risk affects the Android Open Source Project, which is a lower-cost alternative to the full version of Google’s mobile operating system. AOSP is installed in cheaper smartphones to keep the price tag down, but unsuspecting customers are in danger of purchasing devices that come with preinstalled malware.

While this means that Android smartphones released by Google and partners such as Samsung are generally safe from the risk, Google’s Project Zero discovered more than 200 manufacturers who have launched devices with hidden malware. One particular malware of concern is Chamois, which upon infecting a device, generates ad fraud, installs background apps, downloads plugins and even send text messages at premium rates. In March 2018, Stone’s team found Chamois preinstalled in 7.4 million Android devices.

Google’s Project Zero has been working with device manufacturers to address the issue, and that has helped reduce the number of smartphones preinstalled with Chamois to only 700,000 between March 2018 and March 2019. Stone, meanwhile, called for security researchers to place a bigger focus on preinstalled malware as a security threat, as the attention is often directed towards malware that people are tricked into downloading themselves. Then again, even Android antivirus apps have shown to provide inadequate malware protection, according to a study from earlier this year.

Stone’s Black Hat presentation follows a study from June that claimed 43% of Android apps were found to have vulnerabilities, while 38% of iOS apps had the same issue.

Aaron Mamiit
Aaron received an NES and a copy of Super Mario Bros. for Christmas when he was four years old, and he has been fascinated…
Google starts testing Gmail Live, its new voice search tool for your inbox
The feature lets you ask questions about your inbox with your voice and is set to roll out later this summer.
Gmail Live screenshot on gradient background

At I/O this year, Google showcased Gmail Live, a new Gemini-powered feature that lets users search their inbox using their voice instead of typing. The feature has now moved into testing, with 9to5Google reporting that it's rolling out to a small group of Android and iOS users this week.

How Gmail Live works

Read more
Apple and Google sat for discussions to unlock 50W wireless charging for smartphones
Wireless Charger

The next major leap in wireless charging may not come from a flashy smartphone launch, but from behind closed doors where some of the biggest names in the tech industry are working together, according to an ITHome report.

Apple, Google, Xiaomi, and several other leading technology companies recently gathered in Beijing for the Wireless Power Consortium's (WPC) Qi Off-cycle Meeting, where discussions centered around the upcoming Qi 50W wireless charging standard. The four-day event, hosted by Xiaomi, focused on refining technical specifications, testing prototype hardware, and ensuring devices from different brands can work seamlessly together.

Read more
Minimal Phone 2 looks like a deliberate antidote to doomscrolling
The coming phone leans on a keyboard, calmer software, and a smaller body to fight smartphone overload.
Electronics, Phone, Mobile Phone

Minimal Phone 2 has entered waitlist mode with a clear promise. Minimal says its next phone is coming soon with a smaller, more refined design, a better keyboard, an aluminum body, and improved software.

The first Minimal Phone already tested whether people wanted an Android device that slowed phone use down without cutting off everyday tools. Its e-paper screen and physical keyboard made endless feeds less comfortable, while keeping apps, messaging, payments, and other basics within reach.

Read more