We found a phone with pre-installed malware via the Lifeline Assistance program
blog.malwarebytes.com
blog.malwarebytes.com
The Chinese company behind this seems to solely target the North American market and makes medical devices, IoT devices, and other things.
According to their homepage, their LA based office employs engineers from "United Bell Lab, Oracle, Motorola and other well-known international companies".
What else are they root-kitting? With this particular Android one they are freely able to brick devices at will, if it was ever necessary.
People either freak out and shoot the messenger (either because they misunderstand how deep the technical illiteracy goes amongst the aging population or they are a member technical illiterate aging population and resist any effort to be educated), or they directly profit from it (companies that are part of China's spy effort, domestic or foreign), or they're just so goddamned dense they give excuses like "well I've never seen it, so it doesn't exist".
Also, as a side note: we probably should start considering advertising platforms a form of malware as well. Given how many systems run a WebView to display their content, and ad systems run Javascript, and it's a pipedream to ever think Javascript in a browser can ever be made to be secure (even if all it does is leak metadata and perform tracking); ads are, fundamentally, a way to inject malware and should be considered a national security issue.
And yes, I'm aware two of the largest tech companies are ad platforms that have side gigs (Google and Facebook); I, frankly, don't care. If your business revolves around a criminal enterprise that is claimed to be legal purely because of a loophole, then you should go out of business once that loophole is closed.
Absolutely! They've been used as malware vectors numerous times in the past. One of infinite reasons to block them unconditionally and make no exceptions.
Maybe there's a useful analogue in tort law: https://en.m.wikipedia.org/wiki/Attractive_nuisance_doctrine
You've got a thing, and your thing is fine, but negligently allowing others to harm themselves (or in this case, third parties) with said thing can be a problem.
For instance, an ad network could decide to serve only static content and not accept any third-party js, greatly reducing the odds of someone coming along and using the network as a vector for malware. But the network has no incentive to do this because they make more money the other way. If they're made to cover some of the externalities of their product, they gain an incentive to not serve malware.
Running an ad network that accepts and distributes dynamic content is like leaving loaded firearms scattered around your property (in a jurisdiction without special safe-storage laws, I guess - the analogy isn't perfect).
Perhaps because "national security" tends to involve a foreign adversary?
Apparently, stalking is a booming business: https://www.bbc.com/news/technology-50166147
What makes this malware while other pre-installed adware from other companies is just "built-in"ads?
Why does Google or Amazon get to "use ads to subsisidize their devices" while this company is using "pre-installed malware"?
Does this "malware" exfiltrate personal data in violation of a the privacy policy? What does it do (besides annoy the user and show ads) that is malicious?
Modern proprietary operating systems come with non-removable adware. That is the world we live in. I don't like. I don't use these operating systems. But they all do it.
While there is malware distributed outside of Google Play, unless you can point to an actually malicious thing this software did, I have give it a pass.
Remember, the world has already decided that nonconsensual updates, ads, tracking, etc is normal if bundled with the OS and therefore not malware.
You could also use adb to pull other files, though not all, from the phone for inspection.
You would think they would be partially liable for malware on their phones?
They make money counting on low income Americans going over their free rate tier, and advertising.
This seems right as it means you can sue the seller, they can sue their supplier if they too were sold a product that didn't meet the description of what they were sold.
That way the seller, who can afford to spend on expertise to make sure products are up to scratch, bears responsibility.
It's not perfect, but it makes sense this way IMO.
So they seem to be saying UNIMAX may be the actual manufacturer of ANS phones.