In this day and age, where unnecessary expenses are a diminishing luxury, we often think about what is more economical and less about what is more quality. Something that can also apply to our electronic devices. However, if you think it's time to switch to a more affordable Android, you may need to think again.
A study conducted by Avast Threat Labs shows that many low-priced Android phones were released with malware pre-installed.
According to the research, more than 100 countries, including the US, Russia and the UK, have been affected by adware and malware present on hundreds of low-cost Android devices, which include names such as ZTE, myPhone and Archos.
This adware called “Cosiloon” has been active for three years and was first detected by Dr. Web in 2016. Also, its removal is extremely difficult, since the adware is located in the device firmware.
So far, Avast has discovered its presence on 18,000 devices. Google has been notified of the malware by Avast, and the tech giant “has taken steps to mitigate the malicious capabilities of multiple variants across various device models, using advanced techniques.”
Modifications have been made to Google Play Protect to prevent apps with such malware from being released in the future. Google has also contacted firmware developers and urged them to take the necessary steps to address the issue.
Adware displays a plethora of advertisements as pop-ups, which appear in the user's browser, covering the screen. The malware has two important parts: the Dropper and the payload.
According to the report, two dropper variants were identified for transferring the problematic payloads to smartphones.
More than 100 payloads have been found on affected devices, of which only two are visible as apps on the home screen. One payload was hidden in an app called 'Google Contacts'. Other variants were found in the system apps list with names like “MediaService”, “VPlayer” and “eVideo2Service”.
If you are in the category of affected users, you can download Avast antivirus or you can read Avast's blog post
