At least 36 high-end smartphones from popular companies such as Samsung, LG, Xiaomi, Asus, Nexus, Oppo, and Lenovo were found to have pre-loaded malware.
This malware was detected by Check Point in a scan conducted on Android devices. The security firm discovered two malware families on the infected devices: Loki and SLocker.
According to a Friday publication by Check Point researchers, these malicious apps were not part of the official ROM firmware provided by smartphone manufacturers, but were installed later somewhere along the path from manufacturing plants to the distribution chain, and before the devices reached the consumer.
The Loki trojan was first seen in February 2016. The malware attacks devices within the core processes of the Android operating system to gain root privileges. The trojan also includes spyware features, and intercepts the list of applications used, browsing history, contact list, call history, and location data.
On the other hand, SLocker is a mobile ransomware that locks its victims' devices for ransom and communicates through Tor in order to hide the identity of its creators.
Below is the list of infected smartphones:
- Galaxy Note 2
- LG G4
- Galaxy S7
- Galaxy S4
- Galaxy Note 4
- Galaxy Note 5
- Xiaomi Mi 4i
- Galaxy A5
- ZTE x500
- Galaxy Note 3
- Galaxy Note Edge
- Galaxy Tab S2
- Galaxy Tab 2
- Oppo N3
- Vivo X6 plus
- Nexus 5
- Nexus 5X
- Asus Zenfone 2
- LenovoS90
- Oppo R7 plus
- Xiaomi Redmi
- Lenovo A850
The backdoor offers unrestricted access to infected systems. The hacker can download, install and activate malicious applications on Android, delete user data, uninstall security software and disable system applications to call premium phone numbers.
The incident highlights the risks of acquiring devices from untrusted distribution chains, and experts are concerned about security after reporting over 20 incidents where retailers managed to pre-install malware on new Android devices.
How to remove malware:
Malware applications are installed in the ROM of devices, using system privileges, and thus are difficult to get rid of.
To remove malware from infected systems, you will need to root your device and uninstall the malware, or you will need to reinstall the firmware/ROM through a process called “Flashing.”
Flashing is a complex process, and it is especially recommended for novice users to turn off the device and seek help from a certified technician or mobile service provider.
The full list of malicious applications is available in Check Point.
