{"id":12542,"date":"2018-06-11T12:30:10","date_gmt":"2018-06-11T20:30:10","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2018\/06\/11\/news-6311\/"},"modified":"2018-06-11T12:30:10","modified_gmt":"2018-06-11T20:30:10","slug":"news-6311","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2018\/06\/11\/news-6311\/","title":{"rendered":"A good reason to avoid cheap Android smartphones"},"content":{"rendered":"<p><strong>Credit to Author: Yaroslava Ryabova| Date: Mon, 11 Jun 2018 13:00:40 +0000<\/strong><\/p>\n<p>Having decided to buy an Android smartphone, one faces a crazy variety of choices. The number of manufacturers is growing, and there are thousands of opinions about which particular device to choose.<\/p>\n<p>Customers are so overwhelmed with all these choices that for most of them, price becomes the main \u2014 and sometimes the only \u2014 deciding factor. And that&#8217;s where smartphones from less-known manufacturers come in: They promise the same features and quality for half the price of what well-known brands offer. Understandably, it&#8217;s hard not to be attracted by these generous offerings.<\/p>\n<p>You know what, though? It&#8217;s not that simple. Quite often, when you buy a smartphone like that, you also get some hidden extras \u2014 for example, some preinstalled <a target=\"_blank\" href=\"https:\/\/securelist.com\/threats\/malware-glossary\/?utm_source=kdaily&amp;utm_medium=blog&amp;utm_campaign=termin-explanation\">malware<\/a>. Here&#8217;s what&#8217;s going on.<a target=\"_blank\" href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2018\/06\/09083817\/preinstalled-android-malware-featured.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-22729\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2018\/06\/09083817\/preinstalled-android-malware-featured.jpg\" alt=\"\" width=\"1460\" height=\"958\" \/><\/a><\/p>\n<p><strong><\/p>\n<h2>Trojan in a poke<\/h2>\n<p><\/strong><\/p>\n<p>Android&#8217;s big advantage is that it&#8217;s a very flexible mobile platform, which makes it popular among developers. Google develops the core software, but any manufacturer can customize it and fill a smartphone with its own <a target=\"_blank\" href=\"https:\/\/www.techopedia.com\/definition\/27568\/native-mobile-app\">native apps<\/a> to make its products stand out.<\/p>\n<p>Some of that native software is system apps \u2014 apps installed by the manufacturer in the \/system\/app or even the \/system\/priv-app (priv for &#8220;privileged&#8221;) folder in an Android device, that cannot be uninstalled by the user. All well and good, but when you add a profit motive, the picture gets a bit murky.<\/p>\n<p>In theory, a manufacturer can fill the system\/app (or \/priv-app) folder with whatever it thinks customers might find useful. In practice, manufacturers use the opportunity to earn an extra buck, for example, by charging app developers to preinstall their apps. And sometimes, willingly or not, smartphone manufacturers fill the folder with malware.<\/p>\n<p>Preloaded malware can show you ads you can&#8217;t avoid, or collect your personal data to sell to third parties \u2014 or combine the two intrusions, showing you ads based on that data. It all helps decrease the final price of the device. Nice business model!<\/p>\n<p>A preloaded Trojan that allowed criminals to overlay ads over the OS <a target=\"_blank\" href=\"https:\/\/techcrunch.com\/2018\/05\/24\/some-low-cost-android-phones-shipped-with-malware-built-in\/\">was found<\/a> on devices made by relatively big developers such as ZTE, Archos, Prestigio and myPhone. Another investigation found that <a target=\"_blank\" href=\"https:\/\/thenextweb.com\/mobile\/2017\/10\/11\/dear-oneplus-please-stop-spying-on-my-phone\/\">OnePlus<\/a> and <a target=\"_blank\" href=\"https:\/\/www.theverge.com\/2017\/7\/31\/16072786\/amazon-blu-suspended-android-spyware-user-data-theft\">BLU<\/a> smartphones were preloaded with spying software that was collecting sensitive personal data and sending it to the manufacturers&#8217; servers.<\/p>\n<p>Funnily enough, most of the manufacturers we mentioned are listed as <a target=\"_blank\" href=\"https:\/\/www.android.com\/certified\/partners\/\">certified partners<\/a> on the Android official website. That means that preinstalling malware is becoming something of a common practice, and you can&#8217;t simply rely on a well-known manufacturer&#8217;s honor.<\/p>\n<p><strong><\/p>\n<h3>Buy \u2014 but verify<\/h3>\n<p><\/strong><\/p>\n<p>To minimize the risk of purchasing an infected device, or at least to identify a device that will show you advertising in practically every app and collect your personal data without your permission after the purchase, we highly recommend the following:<\/p>\n<ul>\n<li>Do your research: Chances are, the phone you&#8217;re looking at has already been discussed on the Web \u2014 especially if owners are complaining about preinstalled malware.<\/li>\n<li>As is often the case, if something looks too good to be true, perhaps it is too good to be true. It may be wise to avoid smartphones that are radically less expensive than comparable models \u2014 it&#8217;s not unlikely that their manufacturers are using some shady practices to recoup the money that isn&#8217;t on the price tag.<\/li>\n<li><a target=\"_blank\" href=\"https:\/\/support.google.com\/googleplay\/answer\/7165974?hl=en\">Check the certification status<\/a> of your Android device to be sure that its firmware has been tested by Google. Certification doesn&#8217;t guarantee that there&#8217;s no malware preinstalled, but certified devices are significantly less likely to be infected before sale.<\/li>\n<li>Install a <a target=\"_blank\" href=\"https:\/\/app.appsflyer.com\/com.kms.free?pid=smm&amp;c=ww_kdaily\">reliable antivirus<\/a> utility that will inform and protect you the moment it encounters a malicious program. With malware sometimes installed before a buyer unboxes a new purchase, your smartphone can be infected no matter how safe your behavior.<\/li>\n<\/ul>\n<p> <input type=\"hidden\" class=\"category_for_banner\" value=\"kisa-generic\" \/> <br \/><a href=\"https:\/\/www.kaspersky.com\/blog\/preinstalled-android-malware\/22728\/\" target=\"bwo\" >https:\/\/blog.kaspersky.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Yaroslava Ryabova| Date: Mon, 11 Jun 2018 13:00:40 +0000<\/strong><\/p>\n<p>Did you see that new fully loaded Android smartphone, the one that looks too good for the price? Well, it may include some unwanted extras.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10425,10378],"tags":[10468,10462,8816,3764,714,11094,10438,10752],"class_list":["post-12542","post","type-post","status-publish","format-standard","hentry","category-kaspersky","category-security","tag-adware","tag-android","tag-apps","tag-malware","tag-security","tag-smartphones","tag-threats","tag-vulnerabilities"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/12542","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=12542"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/12542\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=12542"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=12542"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=12542"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}