Cheap Android TV Streaming Box May Have a Dangerous Backdoor
wired.com
wired.com
These things have been the default expectation for Android devices of unknown provenance for quite some time, at least among the technically savvy.
I wouldn't trust a laptops Windows install that's been shipped from some random AliExpress account either.
I suspect iOS, due to Apple's policy of "no external app sources" and other similar decisions, much as HN's audience derides them, as a consequence is most resistant to this sort of a thing.
No such luck with these random Android devices, generally. You are generally obligated to use the system image provided by the untrustworthy vendor.
You can get a rootkit on every boot as part of your UEFI, and that's a bonus.
Or the Windows default install without all the modifications to the registry and group policy editor and privacy settings to turn off all the bloat and telemetry.
I mean, seriously, does Microsoft _really_ need to know every time I open an application?
and refers to the same investigation: https://github.com/DesktopECHO/T95-H616-Malware
In fact when the article that brought this to light (a security consultant interviewed by Bleepingcomputer), there was zero technical details, only the linked github account showing steps to delete/remove some random apps.
I would love to find any actual technical analysis/writeup of anything malicious here.