Skip to main content

Google flags preinstalled malware as hidden threat on millions of Android phones

Maddie Stone, a security researcher on Google’s Project Zero and a former tech lead on the Android Security team, flagged preinstalled malware on millions of new Android smartphones as a hidden threat that requires more attention.

Stone shared her team’s findings at the Black Hat USA 2019 conference in Las Vegas, in a presentation in which she said that a smartphone may have as many as 400 preinstalled apps out of the box. This is a major problem because attackers are attempting to hide malware in the preinstalled apps, as it is easier to convince one manufacturer to agree to a preloaded app than to convince thousands of users to download an infected file.

“If malware or security issues come as preinstalled apps,” Stone warned, “then the damage it can do is greater, and that’s why we need so much reviewing, auditing, and analysis.”

The risk affects the Android Open Source Project, which is a lower-cost alternative to the full version of Google’s mobile operating system. AOSP is installed in cheaper smartphones to keep the price tag down, but unsuspecting customers are in danger of purchasing devices that come with preinstalled malware.

While this means that Android smartphones released by Google and partners such as Samsung are generally safe from the risk, Google’s Project Zero discovered more than 200 manufacturers who have launched devices with hidden malware. One particular malware of concern is Chamois, which upon infecting a device, generates ad fraud, installs background apps, downloads plugins and even send text messages at premium rates. In March 2018, Stone’s team found Chamois preinstalled in 7.4 million Android devices.

Google’s Project Zero has been working with device manufacturers to address the issue, and that has helped reduce the number of smartphones preinstalled with Chamois to only 700,000 between March 2018 and March 2019. Stone, meanwhile, called for security researchers to place a bigger focus on preinstalled malware as a security threat, as the attention is often directed towards malware that people are tricked into downloading themselves. Then again, even Android antivirus apps have shown to provide inadequate malware protection, according to a study from earlier this year.

Stone’s Black Hat presentation follows a study from June that claimed 43% of Android apps were found to have vulnerabilities, while 38% of iOS apps had the same issue.

Editors' Recommendations

Aaron Mamiit
Aaron received a NES and a copy of Super Mario Bros. for Christmas when he was 4 years old, and he has been fascinated with…
When is my phone getting Android 14? Here’s everything we know
Android 14 logo on the Google Pixel 8 Pro.

Android 14 is out now, and as usual, the first to get it was Google's own Pixel phone family. Not to be undone, Samsung pushed out its version of Android 14 — One UI 6 — after a relatively short beta period and has seemingly now completed its Android 14 rollout. Nothing, the new phone company on the block, has done the same. Now, we're just waiting for more news from Motorola, who has become the stick in the mud holding everyone up.

If you're rocking an Android phone that is still stuck on an old build, here's everything we know about official Android 14 rollout plans for all major brands available in the U.S. market. We recommend using your device's Find on page function to pinpoint your device on this list.

Read more
Android 15 has two hidden features you’re going to love
The Android 15 logo on a smartphone.

Android 15 is this year's big Android update, and based on what we've seen so far, it's going to be pretty tame. Just like Android 14, Android 15 isn't trying to overhaul or reimagine Android. Instead, it's all about fine-tuning things.

However, that doesn't mean there's nothing cool going on. I've been playing with the Android 15 developer preview for a little while now, and in doing so, I've stumbled across two underrated features that I think a lot of people are going to love.
Notification cooldown is a lifesaver

Read more
I thought I’d hate this cheap Android phone. It proved me wrong
A person holding the Nuu B30 Pro.

I like phones like the Nuu B30 Pro. Not because it’s a Samsung Galaxy S24 Ultra rival or that it does something spectacular we’ve never seen before -- it’s because it is way better than I thought it was going to be.

I admit that I may have judged the Nuu B30 Pro a little harshly before using it, but I’m also happy to admit my flash judgment was wrong. Here’s why you shouldn’t write the Nuu B30 Pro off as just another cheap Android phone to ignore.
Why did I hastily judge the Nuu B30 Pro?

Read more