Skip to main content

Chinese malware found on U.S. government-subsidized phones

Cybersecurity firm, Malwarebytes says it has found pre-installed Chinese malware on some U.S. government-subsidized phones. The phones are offered to low-income families at significant discounts under the FCC’s Lifeline Assistance program that was first introduced three decades ago.

In particular, Malwarebytes has investigated an Android-based model dubbed the UMX U686CL that is being sold by Assurance Wireless, a subsidiary of Virgin Mobile. The phone is manufactured by a China-based company and is priced at $35 which also includes free calls, texts, and data.

The report claims the UMX U686CL came infested with two malware apps. One called Wireless Update was armed with unrestricted privileges and capable of installing apps in the background without any user consent. Being a system-level app, Malwarebytes says it is not possible to uninstall Wireless Update as it could adversely affect the rest of the phone’s functions.

Further, Malwarebytes discovered that Wireless Update was programmed under the same name as Adups, a Chinese company that has been caught in the past “collecting user data, creating backdoors for mobile devices and developing auto-installers.”

Adups was responsible for the massive 2016 Android breach which impacted over 700 million phones and prompted probes from Google as well as the Department of Homeland Security.

The second malware was deeply integrated within the Settings app which means removing it could render the entire phone inoperative. It housed a trojan called Hidden Ads that is configured to display ads even when you’re in other apps. Hidden Ads’ source code was riddled with encrypted Chinese characters, because of which Malwarebytes says it couldn’t pinpoint its exact purpose.

“As I have highlighted in this blog and blogs past, pre-installed malware continues to be a scourge for users of mobile devices. But now that there’s a mobile device available for purchase through a U.S. government-funded program, this henceforth raises (or lowers, however you view it) the bar on bad behavior by app development companies,” said Nathan Collier, Senior Malware Intelligence Analyst at Malwarebytes in a blog post.

Sprint has denied the allegations and in an email response, told Digital Trends that the company is “aware of this issue and in touch with the device manufacturer Unimax to understand the root cause, however, after our initial testing we do not believe the applications described in the media are malware.”

FCC has declined to comment directly on the report and in a statement sent to Digital Trends over email added that “the FCC is not the “provider” of the service. Through the Lifeline program, the FCC funds voice and broadband service to qualifying Lifeline consumers but we do not provide the service ourselves. Lifeline funds do not support the cost of the handset or any other end-user device.”

Editors' Recommendations

Shubham Agarwal
Shubham Agarwal is a freelance technology journalist from Ahmedabad, India. His work has previously appeared in Firstpost…
Samsung just killed one of its most important Android phones
Galaxy Fold open.

Today marks a milestone in the era of foldable smartphones as Samsung officially puts its legendary first-generation Galaxy Fold out to pasture.

After four years on the market, the original Galaxy Fold will no longer receive regular security updates. To be fair, the first Fold was already living on borrowed time, as it was left out of last year’s Android 13 update. However, when Samsung launched the expensive foldable, it promised a full four years of security updates for the device.

Read more
2023’s newest folding phone is already putting Samsung to shame
Hinge view of OnePlus Open foldable phone.

OnePlus’ first foldable smartphone — the OnePlus Open — has had a far smoother sailing compared to Samsung’s debut. Of course, OnePlus relied heavily on sister company Oppo’s foldable experience to deliver a knockout device. The end product feels significantly more refined from an aesthetic perspective and raw camera prowess compared to Samsung’s latest offering.

But getting the hardware is only half the job done when it comes to foldable devices. Surprisingly, the OnePlus Open delivers a UI experience more polished than I had anticipated. I’ve been pushing the device for the past few weeks, and more than neat tricks, I’ve been surprised by the sheer fluidity of the OxygenOS experience on this one. The experience is particularly rewarding for app multitasking, and notably, it involves fewer barriers compared to what Samsung serves with One UI 6.
An incredible multitasking experience

Read more
OnePlus has big news for September 25 — but it’s not a folding phone
OnePlus-11-Marble-Odyssey-Edition display view.

Within a span of two days this week, we got the launch dates of new iPhones and Google’s Pixel 8 series phones. Today, OnePlus also made a major announcement, albeit one that has little to do with hardware — or its highly anticipated foldable phone.

It is still a remarkable one, however. OnePlus will release Android 14-based OxygenOS 14 on September 25. That also means the stable build of Android 14 will arrive for supported Google Pixel phones before that date, and likely for some Samsung phones as well.
OnePlus will finally start public testing of Android 14 in the coming days for the OnePlus 11, the OnePlus 11R, and the OnePlus Nord 3. The company has been refining the latest iteration of OxygenOS for the past few weeks as part of a closed beta program. Soon, OnePlus will kickstart the OxygenOS 14 Open Beta program ahead of the stable release. 
However, OnePlus won’t be the only brand soak-testing Android 14 ahead of its wide release later this year. Google has seeded multiple public beta builds of Android 14 over the past few months for its Pixel phones, and Samsung has also started testing One UI 6 based on Android 14 for a select bunch of high-end Galaxy phones.

Read more