{"id":7127,"date":"2017-03-27T09:10:18","date_gmt":"2017-03-27T17:10:18","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2017\/03\/27\/news-918\/"},"modified":"2017-03-27T09:10:18","modified_gmt":"2017-03-27T17:10:18","slug":"news-918","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2017\/03\/27\/news-918\/","title":{"rendered":"Mobile Menace Monday: Preinstalled adware and sometimes worse"},"content":{"rendered":"<p><strong>Credit to Author: Nathan Collier| Date: Mon, 27 Mar 2017 16:00:52 +0000<\/strong><\/p>\n<p>BLU manufactured mobile devices have been\u00a0discovered with preinstalled adware known as Android\/Adware.YeMobi.<\/p>\n<h3>Behavior of YeMobi<\/h3>\n<p>The incriminating behavior of adware YeMobi is its ability to launch the default browser on a mobile device and use it to display ads. There is an unusual element to this as well\u2014it only displays ads while the <em>Google Play<\/em> store app is running. \u00a0As seen in the code below, if <em>com.android.vending <\/em>(the Google Play store app) is active, activity <em>MessageLoadDetail<\/em> is loaded. \u00a0Activity\u00a0<em>MessageLoadDetail<\/em> then goes onto to display ads<em>.<\/em><\/p>\n<p align=\"center\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-large wp-image-17010\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/1-600x314.jpg\" alt=\"\" width=\"600\" height=\"314\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/1-600x314.jpg 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/1-300x157.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/1-630x330.jpg 630w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/1.jpg 681w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/p>\n<h3>The rise of preinstalled malware<\/h3>\n<p>Buying a new phone only to find it comes preinstalled with adware or even more dangerous malware is frustrating.\u00a0 Trust us, it\u2019s just as frustrating not being able to remove these apps for our customers.<\/p>\n<p>With the\u00a0ease of selling online, Android devices re-imaged with custom ROMs(\u201cRead-Only Memory\u201d) containing preinstalled shady\/malicious apps are starting to appear more and more on the online marketplace. \u00a0Sellers can easily re-image an Android device with a custom ROM which replaces the default operating system\u2014typically stored in read-only memory. Sellers then turn around and sell these devices for cheap online.<\/p>\n<p>Just like when installing apps, it\u2019s important to buy your mobile device from trusted sources.\u00a0 Avoid buying devices online from untrusted\u00a0sellers\/stores; even if the price is hard to pass up.<\/p>\n<h3>Disabling YeMobi and other preinstalled apps<\/h3>\n<p>In order to keep essential operating system apps from being removed on Android devices, you <strong>cannot <\/strong>uninstall preinstalled apps. However, you can disable some preinstalled apps\u2014like Adware YeMobi. Simply go into settings &gt; apps, find the YeMobi app, open its settings, and disable it via the <em>Disable <\/em>button.<\/p>\n<p>Finding preinstalled malware on your device can be tricky\u2014a mobile scanner can assist with finding them for you. <a href=\"https:\/\/www.malwarebytes.com\/mobile\/\" target=\"_blank\">Malwarebytes Anti-Malware Mobile<\/a> detects Adware YeMobi along with other preinstalled malware\u00a0and can be found for FREE on <a href=\"https:\/\/play.google.com\/store\/apps\/details?id=org.malwarebytes.antimalware&amp;hl=en\" target=\"_blank\">Google Play<\/a>.<\/p>\n<p>As always, stay safe out there!<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/03\/mobile-menace-monday-preinstalled-adware-and-sometimes-worse\/\">Mobile Menace Monday: Preinstalled adware and sometimes worse<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/03\/mobile-menace-monday-preinstalled-adware-and-sometimes-worse\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Nathan Collier| Date: Mon, 27 Mar 2017 16:00:52 +0000<\/strong><\/p>\n<table cellpadding='10'>\n<tr>\n<td valign='top' align='center'><a href='https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/03\/mobile-menace-monday-preinstalled-adware-and-sometimes-worse\/' title='Mobile Menace Monday: Preinstalled adware and sometimes worse'><img src='https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/03\/photodune-5866871-phone-sale-xxl-500x750.jpg' border='0'  width='300px'  \/><\/a><\/td>\n<\/tr>\n<tr>\n<td valign='top' align='left'>BLU manufactured mobile devices have been discovered with preinstalled adware known as Android\/Adware.YeMobi.<\/p>\n<p>Categories: <\/p>\n<ul class=\"post-categories\">\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/cybercrime\/\" rel=\"category tag\">Cybercrime<\/a><\/li>\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/cybercrime\/mobile\/\" rel=\"category tag\">Mobile<\/a><\/li>\n<\/ul>\n<p>Tags: <a href=\"https:\/\/blog.malwarebytes.com\/tag\/adware\/\" rel=\"tag\">adware<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/android\/\" rel=\"tag\">Android<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/google-play\/\" rel=\"tag\">Google Play<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/mobile\/\" rel=\"tag\">Mobile<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/preinstalled\/\" rel=\"tag\">preinstalled<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/system-app\/\" rel=\"tag\">system app<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/triple-m\/\" rel=\"tag\">triple m<\/a><\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/03\/mobile-menace-monday-preinstalled-adware-and-sometimes-worse\/' title='Mobile Menace Monday: Preinstalled adware and sometimes worse'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2017\/03\/mobile-menace-monday-preinstalled-adware-and-sometimes-worse\/\">Mobile Menace Monday: Preinstalled adware and sometimes worse<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[10468,10462,4503,11268,10554,11762,11763,10556],"class_list":["post-7127","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-adware","tag-android","tag-cybercrime","tag-google-play","tag-mobile","tag-preinstalled","tag-system-app","tag-triple-m"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/7127","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=7127"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/7127\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=7127"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=7127"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=7127"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}