- My Forums
- Tiger Rant
- LSU Recruiting
- SEC Rant
- Saints Talk
- Pelicans Talk
- More Sports Board
- Fantasy Sports
- Golf Board
- Soccer Board
- O-T Lounge
- Tech Board
- Home/Garden Board
- Outdoor Board
- Health/Fitness Board
- Movie/TV Board
- Book Board
- Music Board
- Political Talk
- Money Talk
- Fark Board
- Gaming Board
- Travel Board
- Food/Drink Board
- Ticket Exchange
- TD Help Board
Customize My Forums- View All Forums
- Show Left Links
- Topic Sort Options
- Trending Topics
- Recent Topics
- Active Topics
Started By
Message
Google Warning: Tens Of Millions Of Android Phones Come Preloaded With Dangerous Malware
Posted on 8/10/19 at 7:29 pm
Posted on 8/10/19 at 7:29 pm
Forbes
quote:
Millions of shiny new Android smartphones are being purchased with dangerous malware factory-installed, according to Google’s own security research team. There have been multiple headlines about the millions of harmful apps being installed from the Play Store, but this is something new. And the danger to unsuspecting users, trusting that new boxed devices are safe and clean, is that some of that preinstalled malware can download other malware in the background, commit ad fraud, or even take over its host device.
Android is a thriving open-source community, which is great for innovation but not so great when threat actors seize the opportunity to hide malware in basic software loads that come on boxed devices. New phones can have as many as 400 apps factory-installed, many of which we just ignore. But it transpires that many of those apps have not been vetted. The apps themselves will work as billed, providing a useful capability or service, so we can be forgiven for not considering the risk that might lurk within.
Google’s Maddie Stone, a security researcher with the company’s Project Zero, shared her team’s findings at Black Hat on Thursday. “If malware or security issues come as preinstalled apps,” she warned, “then the damage it can do is greater, and that’s why we need so much reviewing, auditing and analysis.”
The risk impacts Android’s Open-Source Project (AOSP), a lower-cost alternative to the full-fat version. AOSP is installed on lower-cost smartphones where cheaper software alternatives help keep prices down. This means owners of Android-badged devices from the likes of Samsung and Google itself are safe from this particular risk.
For an attacker, Stone warned, the benefit of supply chain compromise is that they “only have to convince one company to include their app, rather than thousands of users.” The Google team didn’t disclose any details of the brands of phones involved, but more than 200 device manufacturers fell foul of the testing, with malware allowing the devices to be attacked remotely.
Of particular concern were two particularly virulent malware campaigns: Chamois and Triada. Chamois generates various flavors of ad fraud, installs background apps, downloads plugins and can even send premium rate text messages. Chamois alone was found to have come installed on 7.4 million devices. Triada is an older variant of malware, one that also displays ads and installs apps.
Google is working to help device manufacturers screen for such vulnerabilities, and between March 2018 and March 2019, Stone claims such screening helped reduce the instances of devices infected by Chamois from 7.4 million to “only” 700,000. “The Android ecosystem is vast,” she warned, “with a diversity of OEMs and customizations—if you are able to infiltrate the supply chain out of the box, then you already have as many infected users as how many devices they sell—that’s why it’s a scarier prospect.”
In the meantime, the usual advice applies around downloading and installing apps from the Play Store. A healthy dose of skepticism does not go amiss when the app is from an unknown source. Not much users can do if those threats come preinstalled, though, and that’s why this revelation is so dangerous. For this one we need to rely on manufacturers to do the right thing and follow Google’s advice in screening software fully to eradicate such risks.
Posted on 8/10/19 at 7:33 pm to AUFan2015
Don't buy cheap phones?
quote:
The risk impacts Android’s Open-Source Project (AOSP), a lower-cost alternative to the full-fat version. AOSP is installed on lower-cost smartphones where cheaper software alternatives help keep prices down. This means owners of Android-badged devices from the likes of Samsung and Google itself are safe from this particular risk.
Posted on 8/10/19 at 10:13 pm to AUFan2015
People shite on Apple because they have premium pricing, but they've never had shite like this happen.
Although I don't see this at Google's fault at all. It's the manufacturers.
Although I don't see this at Google's fault at all. It's the manufacturers.
Posted on 8/10/19 at 10:50 pm to tlsu15
Google, they just be jealous at the thought of someone else harvesting your data.
Posted on 8/10/19 at 11:07 pm to awestruck
Apple owners laughing they asses off
Posted on 8/10/19 at 11:35 pm to AUFan2015
Tens of millions?
Guarantee this article was posted by an iPhone bot.

Guarantee this article was posted by an iPhone bot.
Posted on 8/11/19 at 2:47 pm to umop_apisdn
quote:
Guarantee this article was posted by an iPhone bot.
The article showed up on my phone's news feed yesterday and caught my attention since I use a Pixel. As soon as I got to the paragraph about it only affecting burner phones I X'd out.
Clickbait, typical Forbes.
This post was edited on 8/11/19 at 2:48 pm
Posted on 8/11/19 at 10:03 pm to gobuxgo5
Posted on 8/12/19 at 6:25 am to Korkstand
In today's world, this translates to:
"Cheap android phones dont have our Google data harvesting software so dont use them. They will make your dick shrink like Yellow-5"
"Cheap android phones dont have our Google data harvesting software so dont use them. They will make your dick shrink like Yellow-5"
Posted on 8/12/19 at 10:24 am to tlsu15
quote:
People shite on Apple because they have premium pricing, but they've never had shite like this happen.

Posted on 8/12/19 at 10:46 am to CarRamrod
quote:
look at the retard.
Apple puts out iPhones with Malware installed? Do tell..
Posted on 8/12/19 at 11:00 am to TigerGman
Do you really want to go down this road?
Posted on 8/12/19 at 11:09 am to CarRamrod
quote:
Do you really want to go down this road?
Sure. Take your best shot.
Posted on 8/12/19 at 11:42 am to TigerGman
do you even read threads you post in?
Posted on 8/12/19 at 11:44 am to Korkstand
quote:
quote:
Apple owners laughing they asses off
Keep laughing

Posted on 8/12/19 at 12:15 pm to CarRamrod
quote:
do you even read threads you post in?
I'll take that as a no they haven't.
Thanks.
Posted on 8/12/19 at 12:30 pm to Korkstand
quote:
Keep laughing
It has little chance of ever doing anything besides being at a DEFCON now. Apple's closed system for better and worse allows them complete control of any app on the market. You need to get an app on the market and now that they know to look at anything accessing the contacts app, it's pretty much dead in the water.
This thread is addressing something that is effecting phones in the wild.
This post was edited on 8/12/19 at 12:31 pm
Posted on 8/12/19 at 12:36 pm to AUFan2015
you can smell the desperation of the apple fanboys in here
Posted on 8/12/19 at 12:50 pm to tlsu15
(no message)
This post was edited on 8/8/20 at 9:08 am
Posted on 8/12/19 at 12:59 pm to TexasTiger39
quote:
If you believe the two largest phone operating systems haven't been subjected to several security breaches a day for the past decade, you are naive at best.
Thought we were talking about phones coming pre installed with Malware...
Popular
Back to top
