{"id":22728,"date":"2018-06-11T09:00:40","date_gmt":"2018-06-11T13:00:40","guid":{"rendered":"https:\/\/www.kaspersky.com\/blog\/?p=22728"},"modified":"2019-11-15T06:36:00","modified_gmt":"2019-11-15T11:36:00","slug":"preinstalled-android-malware","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com\/blog\/preinstalled-android-malware\/22728\/","title":{"rendered":"A good reason to avoid cheap Android smartphones"},"content":{"rendered":"<p>Having decided to buy an Android smartphone, one faces a crazy variety of choices. The number of manufacturers is growing, and there are thousands of opinions about which particular device to choose.<\/p>\n<p>Customers are so overwhelmed with all these choices that for most of them, price becomes the main \u2014 and sometimes the only \u2014 deciding factor. And that\u2019s where smartphones from less-known manufacturers come in: They promise the same features and quality for half the price of what well-known brands offer. Understandably, it\u2019s hard not to be attracted by these generous offerings.<\/p>\n<p>You know what, though? It\u2019s not that simple. Quite often, when you buy a smartphone like that, you also get some hidden extras \u2014 for example, some preinstalled <a target=\"_blank\" href=\"https:\/\/encyclopedia.kaspersky.com\/glossary\/malware\/?utm_source=kdaily&amp;utm_medium=blog&amp;utm_campaign=termin-explanation\" rel=\"noopener noreferrer\">malware<\/a>. Here\u2019s what\u2019s going on.<\/p>\n<p><strong><\/strong><\/p>\n<h2>Trojan in a poke<\/h2>\n<p><\/p>\n<p>Android\u2019s big advantage is that it\u2019s a very flexible mobile platform, which makes it popular among developers. Google develops the core software, but any manufacturer can customize it and fill a smartphone with its own <a target=\"_blank\" href=\"https:\/\/www.techopedia.com\/definition\/27568\/native-mobile-app\" rel=\"noopener noreferrer nofollow\">native apps<\/a> to make its products stand out.<\/p>\n<p>Some of that native software is system apps \u2014 apps installed by the manufacturer in the \/system\/app or even the \/system\/priv-app (priv for \u201cprivileged\u201d) folder in an Android device, that cannot be uninstalled by the user. All well and good, but when you add a profit motive, the picture gets a bit murky.<\/p>\n<p>In theory, a manufacturer can fill the system\/app (or \/priv-app) folder with whatever it thinks customers might find useful. In practice, manufacturers use the opportunity to earn an extra buck, for example, by charging app developers to preinstall their apps. And sometimes, willingly or not, smartphone manufacturers fill the folder with malware.<\/p>\n<p>Preloaded malware can show you ads you can\u2019t avoid, or collect your personal data to sell to third parties \u2014 or combine the two intrusions, showing you ads based on that data. It all helps decrease the final price of the device. Nice business model!<\/p>\n<p>A preloaded Trojan that allowed criminals to overlay ads over the OS <a target=\"_blank\" href=\"https:\/\/techcrunch.com\/2018\/05\/24\/some-low-cost-android-phones-shipped-with-malware-built-in\/\" rel=\"noopener noreferrer nofollow\">was found<\/a> on devices made by relatively big developers such as ZTE, Archos, Prestigio and myPhone. Another investigation found that <a target=\"_blank\" href=\"https:\/\/thenextweb.com\/mobile\/2017\/10\/11\/dear-oneplus-please-stop-spying-on-my-phone\/\" rel=\"noopener noreferrer nofollow\">OnePlus<\/a> and <a target=\"_blank\" href=\"https:\/\/www.theverge.com\/2017\/7\/31\/16072786\/amazon-blu-suspended-android-spyware-user-data-theft\" rel=\"noopener noreferrer nofollow\">BLU<\/a> smartphones were preloaded with spying software that was collecting sensitive personal data and sending it to the manufacturers\u2019 servers.<\/p>\n<p>Funnily enough, most of the manufacturers we mentioned are listed as <a target=\"_blank\" href=\"https:\/\/www.android.com\/certified\/partners\/\" rel=\"noopener noreferrer nofollow\">certified partners<\/a> on the Android official website. That means that preinstalling malware is becoming something of a common practice, and you can\u2019t simply rely on a well-known manufacturer\u2019s honor.<\/p>\n<p><strong><\/strong><\/p>\n<h3>Buy \u2014 but verify<\/h3>\n<p><\/p>\n<p>To minimize the risk of purchasing an infected device, or at least to identify a device that will show you advertising in practically every app and collect your personal data without your permission after the purchase, we highly recommend the following:<\/p>\n<ul>\n<li>Do your research: Chances are, the phone you\u2019re looking at has already been discussed on the Web \u2014 especially if owners are complaining about preinstalled malware.<\/li>\n<li>As is often the case, if something looks too good to be true, perhaps it is too good to be true. It may be wise to avoid smartphones that are radically less expensive than comparable models \u2014 it\u2019s not unlikely that their manufacturers are using some shady practices to recoup the money that isn\u2019t on the price tag.<\/li>\n<li><a target=\"_blank\" href=\"https:\/\/support.google.com\/googleplay\/answer\/7165974?hl=en\" rel=\"noopener noreferrer nofollow\">Check the certification status<\/a> of your Android device to be sure that its firmware has been tested by Google. Certification doesn\u2019t guarantee that there\u2019s no malware preinstalled, but certified devices are significantly less likely to be infected before sale.<\/li>\n<li>Install a <a target=\"_blank\" href=\"https:\/\/app.appsflyer.com\/com.kms.free?pid=smm&amp;c=ww_kdaily\" rel=\"noopener noreferrer nofollow\">reliable antivirus<\/a> utility that will inform and protect you the moment it encounters a malicious program. With malware sometimes installed before a buyer unboxes a new purchase, your smartphone can be infected no matter how safe your behavior.<\/li>\n<\/ul>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"kisa-generic\">\n","protected":false},"excerpt":{"rendered":"<p>Did you see that new fully loaded Android smartphone, the one that looks too good for the price? Well, it may include some unwanted extras.<\/p>\n","protected":false},"author":2455,"featured_media":22729,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[2683],"tags":[572,105,109,36,97,45,422,268],"class_list":{"0":"post-22728","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-threats","8":"tag-adware","9":"tag-android","10":"tag-apps","11":"tag-malware-2","12":"tag-security-2","13":"tag-smartphones","14":"tag-threats","15":"tag-vulnerabilities"},"hreflang":[{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/preinstalled-android-malware\/22728\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/preinstalled-android-malware\/13517\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/preinstalled-android-malware\/11282\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/preinstalled-android-malware\/15583\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/preinstalled-android-malware\/13834\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/preinstalled-android-malware\/13055\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/preinstalled-android-malware\/16309\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/preinstalled-android-malware\/15823\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/preinstalled-android-malware\/20756\/"},{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/preinstalled-android-malware\/5035\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/preinstalled-android-malware\/10599\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/preinstalled-android-malware\/10430\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/preinstalled-android-malware\/9282\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/preinstalled-android-malware\/16944\/"},{"hreflang":"zh","url":"https:\/\/www.kaspersky.com.cn\/blog\/preinstalled-android-malware\/9711\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/preinstalled-android-malware\/20596\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/preinstalled-android-malware\/16680\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/preinstalled-android-malware\/20452\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/preinstalled-android-malware\/20444\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com\/blog\/tag\/android\/","name":"Android"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/22728","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/users\/2455"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/comments?post=22728"}],"version-history":[{"count":4,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/22728\/revisions"}],"predecessor-version":[{"id":29707,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/22728\/revisions\/29707"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media\/22729"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media?parent=22728"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/categories?post=22728"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/tags?post=22728"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}