Following an investigation conducted by Malwarebytes in January into devices that had malware pre-installed, the company recently discovered another device that contained malware from the get-go.

As Malwarebytes' initial investigation revealed, Virgin Mobile 's UMX U686CL device , which was distributed as part of the government- funded Lifeline Assistance program , contained two pre-installed malicious programs: a Wireless Update app and a Settings app .
A month after the disclosure, UMX (Unimax) Communications released an update that removed the apps from the device and claimed it was a vulnerability.
Recently, however, Malwarebytes researcher Nathan Collier reported that another phone model provided through the Lifeline Assistance program was discovered to contain pre-installed malware. It is the ANS (American Network Solutions) UL40 running Android 7.1.1.
As with the UMX U686CL, the ANS UL40 comes with infected Settings and Wireless Update apps from the get-go, although these are different versions of the malware. The Settings app downloads Android/Trojan.Downloader.Wotby.SEK, while the Wireless Update app downloads variants of Android/PUP.Riskware.Autoins.Fota.

Digging further, the security researcher discovered that the digital certificate for the Settings app on ANS UL40 is associated with TeleEpoch Ltd, the company that registered the “UMX” brand in the United States.
Further investigation revealed that the ANS L51 was another ANS device that was shipped with pre-installed malware and that it had the same malware variants detected on the UMX U683CL.
As Malwarebytes revealed, it believes that ANS will remove the malware from flagged devices as soon as possible, as did UMX, however it has also released a series of steps that users can take to ensure that HiddenAds does not infect their phones again.
