Skip to main content

Google flags preinstalled malware as hidden threat on millions of Android phones

Maddie Stone, a security researcher on Google’s Project Zero and a former tech lead on the Android Security team, flagged preinstalled malware on millions of new Android smartphones as a hidden threat that requires more attention.

Stone shared her team’s findings at the Black Hat USA 2019 conference in Las Vegas, in a presentation in which she said that a smartphone may have as many as 400 preinstalled apps out of the box. This is a major problem because attackers are attempting to hide malware in the preinstalled apps, as it is easier to convince one manufacturer to agree to a preloaded app than to convince thousands of users to download an infected file.

Recommended Videos

“If malware or security issues come as preinstalled apps,” Stone warned, “then the damage it can do is greater, and that’s why we need so much reviewing, auditing, and analysis.”

The risk affects the Android Open Source Project, which is a lower-cost alternative to the full version of Google’s mobile operating system. AOSP is installed in cheaper smartphones to keep the price tag down, but unsuspecting customers are in danger of purchasing devices that come with preinstalled malware.

While this means that Android smartphones released by Google and partners such as Samsung are generally safe from the risk, Google’s Project Zero discovered more than 200 manufacturers who have launched devices with hidden malware. One particular malware of concern is Chamois, which upon infecting a device, generates ad fraud, installs background apps, downloads plugins and even send text messages at premium rates. In March 2018, Stone’s team found Chamois preinstalled in 7.4 million Android devices.

Google’s Project Zero has been working with device manufacturers to address the issue, and that has helped reduce the number of smartphones preinstalled with Chamois to only 700,000 between March 2018 and March 2019. Stone, meanwhile, called for security researchers to place a bigger focus on preinstalled malware as a security threat, as the attention is often directed towards malware that people are tricked into downloading themselves. Then again, even Android antivirus apps have shown to provide inadequate malware protection, according to a study from earlier this year.

Stone’s Black Hat presentation follows a study from June that claimed 43% of Android apps were found to have vulnerabilities, while 38% of iOS apps had the same issue.

Aaron Mamiit
Aaron received an NES and a copy of Super Mario Bros. for Christmas when he was four years old, and he has been fascinated…
Android’s desktop mode for phones is taking shape, and it looks familiar
Android 16 logo on Google Pixel 6a kept on the edge of a table.

Google’s mobile operating system comes with a hidden desktop mode that opens on an external screen, mimicking what you would get from a computing interface. However, it is buried within the developer mode, and it's far from polished to get any serious work done. 

The company, however, continues building a next-gen experience for Android’s native desktop mode. The overarching idea is to turn your phone and tablet into a desktop computing device. Mishaal Rahman, over at Android Authority, was able to enable this mode in the latest beta build of Android 16, though he warns that it might not be ready for the stable release in the coming months.

Read more
Samsung resumes rollout of Android 15-based One UI 7 for Galaxy phones
The welcome screen for One UI 7 on the Samsung Galaxy S24 Ultra.

Samsung had a rather rough start with the release of its heavily anticipated One UI 7 update. After a string of delays, the company finally started seeding the update for a handful of its flagship phones, but abruptly paused it, citing vague issues. Thankfully, the rollout is back on track. 

Updates tracker, Tarun Vats, shared on X that the stable One UI 7 update is now appearing for Galaxy Z Fold 6 and Galaxy S24 users in multiple regions across Asia, the Middle East, Europe, and the US.

Read more
Android 16 is finally expanding beyond Google Pixel phones
Android 16 logo on Google Pixel 6a held in hand.

The next major build of Android has reached a handful of new milestones, ahead of its public release. Google has just started the rollout of Android 16’s fourth beta update, reaching the second platform stability. 

Developers who have optimized their apps to target Android 16 can now ship their updates via the Google Play Store. The latest beta update is also the near-final version, as all the app behaviours and background functionalities have been finalized. 

Read more