A WAVE of malware-infected Android phones are flooding the market, cybersecurity researchers have revealed.

Millions of devices have been injected with an information stealing malware before they even leave the factory, according to a new investigation by Japanese security company Trend Micro.

Some of these pre-installed apps, which have become a breeding ground for hackers, allow cyber criminals to "rent out" devices for up to five minutes at a time

1

Some of these pre-installed apps, which have become a breeding ground for hackers, allow cyber criminals to “rent out” devices for up to five minutes at a timeCredit: Getty Images – Getty

Android fans have been warned against buying cheap devices after experts discovered these phones are being targeted by cyber criminals.

The trend has become more common in recent years, as the market tries to produce cheaper phones.

As more manufacturing aspects of the smartphone supply chain become outsourced, the pipeline has become much easier for third-party threat actors to infiltrate.

Once selling firmware – the software that comes built into the phone – became unprofitable, many developers began offering it for free.

Android and iPhone users urged to delete apps that don't follow 'rule of 4'
FBI warns all phone users over bank-emptying Wi-Fi and charging ports

But with this came an array of more than 80 “silent plugins”, according to researchers.

Some of these pre-installed apps, which have become a breeding ground for hackers, allow cyber criminals to “rent out” devices for up to five minutes at a time.

It doesn’t sound like long, but sometimes that’s all fraudsters need to steal login credentials or other sensitive information.

The infection turns these devices into tools for stealing and selling text messages, social media accounts, bank details and even monetisation through advertisements and click fraud.

Most read in Tech

Hackers may even decide to install other malware onto the device.

While just a few of these plugins have become widespread – after being sold on social media and the dark web – millions of phones have been infected worldwide.

The supply chain attack is mostly targeting cheaper smartphones, but it is also affecting smartwatches and smart TVs.

These devices have been found worldwide, but are most concentrated in Eastern Europe and Southeast Asia, the team found.

This pre-installed Android malware scheme is not new, and has been quietly snowballing for some time.

Google has been aware of the issue for years, but there’s little the company can do about it.

The tech giant has limited control over Android’s complex supply chain.

Cheaper phones tend to come with between 100 and 400 pre-installed apps.

All it takes is one infected app for the entire device and its owner to be at risk of data fraud.

Major cinema chain to close five locations within weeks
My chunky baby is four months old but wears clothes for a toddler

It’s not as easy as removing a dodgy app from Google’s Play Store.

So the only way Android fans can really protect themselves is to buy higher-end devices and sticking to brands like Samsung and Google, which are supposed to have better supply chain security. 

Best Phone and Gadget tips and hacks

Looking for tips and hacks for your phone? Want to find those secret features within social media apps? We have you covered…


We pay for your stories! Do you have a story for The Sun Online Tech & Science team? Email us at [email protected]


This post first appeared on Thesun.co.uk

Leave a Reply

Your email address will not be published. Required fields are marked *

You May Also Like

Jeff Bezos forced to CANCEL rocket launch over last minute problems – 15 months after his last mission exploded

JEFF Bezos’ first Blue Origin rocket launch in over 15 months was…

Google warns billions of users to check hidden settings now – it’s too dangerous to ignore and only takes one minute

GOOGLE is warning billion of users over five Chrome settings and features…

Pair of sphinxes depicting King Tutankhamun’s grandfather are discovered in Egypt

A pair of giant limestone sphinxes have been unearthed by archaeologists excavating…

Scientists rank the pain of stinging insects – and the worst is like ‘the flow an active VOLCANO’

If you think your job is painful, try being stung by 78…