Skip to main content

Google flags preinstalled malware as hidden threat on millions of Android phones

Maddie Stone, a security researcher on Google’s Project Zero and a former tech lead on the Android Security team, flagged preinstalled malware on millions of new Android smartphones as a hidden threat that requires more attention.

Stone shared her team’s findings at the Black Hat USA 2019 conference in Las Vegas, in a presentation in which she said that a smartphone may have as many as 400 preinstalled apps out of the box. This is a major problem because attackers are attempting to hide malware in the preinstalled apps, as it is easier to convince one manufacturer to agree to a preloaded app than to convince thousands of users to download an infected file.

Recommended Videos

“If malware or security issues come as preinstalled apps,” Stone warned, “then the damage it can do is greater, and that’s why we need so much reviewing, auditing, and analysis.”

The risk affects the Android Open Source Project, which is a lower-cost alternative to the full version of Google’s mobile operating system. AOSP is installed in cheaper smartphones to keep the price tag down, but unsuspecting customers are in danger of purchasing devices that come with preinstalled malware.

While this means that Android smartphones released by Google and partners such as Samsung are generally safe from the risk, Google’s Project Zero discovered more than 200 manufacturers who have launched devices with hidden malware. One particular malware of concern is Chamois, which upon infecting a device, generates ad fraud, installs background apps, downloads plugins and even send text messages at premium rates. In March 2018, Stone’s team found Chamois preinstalled in 7.4 million Android devices.

Google’s Project Zero has been working with device manufacturers to address the issue, and that has helped reduce the number of smartphones preinstalled with Chamois to only 700,000 between March 2018 and March 2019. Stone, meanwhile, called for security researchers to place a bigger focus on preinstalled malware as a security threat, as the attention is often directed towards malware that people are tricked into downloading themselves. Then again, even Android antivirus apps have shown to provide inadequate malware protection, according to a study from earlier this year.

Stone’s Black Hat presentation follows a study from June that claimed 43% of Android apps were found to have vulnerabilities, while 38% of iOS apps had the same issue.

Aaron Mamiit
Aaron received an NES and a copy of Super Mario Bros. for Christmas when he was four years old, and he has been fascinated…
When will my phone get Android 15? Here’s everything we know
The Android 15 logo on a smartphone.

Android 15 is now available for certain Android phones. It's been in development since February, went through three phases, and is finally beginning to roll out, starting with Google's Pixel phones. If you're waiting for the latest software, well, you don't have long to wait.

If you’re wondering when your current Android smartphone will get the Android 15 update, here are all the details so far.
When is Android 15 coming out?

Read more
It just got easier to protect your Android phone from thieves
Android 15 theft protection.

With the release of Android 15 on Pixel devices, Google has introduced several new privacy and security enhancements. Among the notable additions are the improved theft protection features that are designed to make it harder for thieves to access your data. Initially, it was a bit difficult to find these settings. However, as Android Authority first noted, that's about to change.

When Android 15 launched, to find the theft protection menu on devices running Android 15, you had to follow these steps:

Read more
Motorola is already updating some phones to its Android 15 beta
The Android 15 logo on a smartphone.

Android fans can breathe a sigh of relief. The long-awaited Android 15 is finally here and is rolling out to compatible smartphones. We knew the release was coming; in fact, we reported on it rolling out to Pixel devices yesterday, and Motorola had already confirmed that it would be coming to a wide range of devices.

According to a report from GSMArena, some users have begun to see Android 15 beta show up on the Motorola Edge 50 Fusion, but it's likely that the update is also hitting other Edge 50 models. These phones are currently receiving the Android 15 beta update, but the full version will make its way to these handsets, too — possibly by the end of the year if we assume the current update is a test of stability for the OS.

Read more