back to article DeathRing: Cheapo Androids pre-pwned with mobile malware

A new mobile Trojan is being pre-loaded onto smartphones somewhere in the supply chain. DeathRing masquerades as a ringtone app and is impossible to remove because it’s pre-installed in the system directory, according to mobile security firm Lookout. Samples of the malware are restricted to entry-level phones purchased in …

COMMENTS

This topic is closed for new posts.
  1. Longrod_von_Hugendong
    FAIL

    This is an epic...

    Fail, and mostly the reason I avoid Andriod. I will play safely in my own walled garden thanks...

    Although, presumably you can wipe the default install and put another one on...

  2. Arnold Lieberman

    Root then delete apk

    Not something the average Jo is going to know about but easy to fix for the slightly more knowledgeable user or with any number of anti-malware apps.

    1. Michael Habel

      Re: Root then delete apk

      Not something the average Jo is going to know about but easy to fix for the slightly more knowledgeable user or with any number of anti-malware apps.

      On the face of it... I'd might agree with you... But, I find in my case, most of these "Dolts" of which you speak of... (In my little Family Circle), usually eventually come ruining to me to do a Setup, or eventually even a Custom ROM Update. When the finally figure out that Manufacturer "X" is no longer interested in supporting said "Device" any longer.

      It was more or less how I was formally introduced to cheapo ChinaPhones with MediaTek SoC Devices. Which TBH, are great on the face of it... As long as you don't try to install CM on them that is.

      I'm fairly sure that most Families have at least One of me in their Family too... Thankfully they only turn up every few Years (or so), with something mildly interesting. But, those MediaTek Devices have given, me a somewhat deeper respect for the larger Players, and why their Phablets are not only better, in every possible way. But why they end up costing more too...

  3. Michael Habel

    All the more reason to root out these chepo Chinaphones and remove the utter cruft inside them.

    Case in point a Google TV Box I recently purchased, had Quick Office in the /system/app Folder. Normally uninstallable.... Why the heck Beelink, the Guy who _reportedly_ made the MXIII thought I needed this. When the Box, never even came with so much as a Bluetooth Controller... Well I'll guess I'll never know...

    Thankfully the Box came "pre-rooted"... Which consequently sucks! As no One has since thought to port a working ClockWork Mod Recovery for it!... It was easy to remove this, and the few bits of Chinese Spyware "Quick Search.apk" amongst some other cruft outta the Box. Thus giving me a ~ca. 50MB boost.

  4. Terry 6 Silver badge

    impossible to remove because it’s pre-installed in the system directory,

    This is the underlying aspect of Android that seriously pisses me off.

    My device, that I purchased with good money comes with crapware ( or just plain unwanted software), OK. That's business. Annoying, but that's part of the price we have to pay.

    But making it permanent so that nothing I can* do will stop it clogging up my list of apps is just a stupid piece of work. If I'm going to use something, I'll use it. If not then making it impossible to shift out isn't going to change that.

    The fact that a bunch of crooks has gone one step further is hardly a surprise.

    *taking the view as an ordinary user, because I don't want to invalidate my warranty by rooting the device.

  5. g00se
    FAIL

    ALL Android is pre-pwned - because it's not open. In what way is it pre-pwned? Well you don't know, do you?

  6. AndrueC Silver badge
    WTF?

    Out of idle/morbid curiosity - what does a 'ring tone app' actually do?

  7. Tsung

    "Lookout says DeathRing is the second significant example of pre-installed mobile malware it has found on phones during 2014"

    The first was Lookout which was shoe-horned onto my mobile by EE. Of course it was the basic version, with prompts to update for £x a month and no way to remove it.

This topic is closed for new posts.