Thursday, February 27, 2025
HomeAdwareAndroid Devices Infected with Undeletable Adware that Sits on System Partition

Android Devices Infected with Undeletable Adware that Sits on System Partition

Published on

SIEM as a Service

Follow Us on Google News

Researchers observed that 14.8% of all Android users attacked by malware or adware still have infection left in the system partition.

The problem is because of smartphones or tablets sold by certain brands in the lower segment contain malicious ad codes embedded in the firmware of the device.

Two main Strategies of Undeletable Adware

For Android devices, the most common malware is Lezok and Triada. They get directly embedded in key library “libandroid_runtime” that used by every app.

“A system partition infection entails a high level of risk for the users of infected devices, as a security solution cannot access the system directories, meaning it cannot remove the malicious files,” researchers said.

  • The malware gains root access on the device and installs adware in the system partition.
  • The code for displaying ads (or its loader) gets into the firmware of the device even before it ends up in the hands of the consumer.

The number of affected users varies between 1 to 5 percent of users with low-cost devices and reaches 27 percent in extreme cases.

Wide range of threats Observed

The Agent trojan is obfuscated and hides behind the GUI of the system or setting utility and delivers the payload that runs arbitrary files on the device.

Next, the Sivu Trojan which masquerades as an HTMLViewer app has two modules one uses root permission to push notifications and the second one is the backdoor allowing remote control of the smartphone.

The Plague adware is another type that calls itself as Android services and installs apps to show ad notifications.

Trojan Agent.pa mimic as CIT TEST app communicates with C&C server to run apps, open URLs, download and run arbitrary DEX files, install/uninstall apps, show notifications, and start services.

Penguin, Necro, Facmod, Guerrilla, Virtualinst and Secreted, or some other malware that often resides in the system partition.

“Some smartphones contain adware modules pre-installed by the manufacturers themselves. A few vendors openly admit to embedding adware under the hood of their smartphones; some allow it to be disabled, while others do not, describing it as part of their business model to reduce the cost of the device for the end-user,” reads Kaspersky statement.

This research shows that some mobile device sells the phones with built-in ad scripts to maximize the profit which causes inconvenience to the device owners. The pre-installed advertising scripts are hard to remove without damaging the system.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates.

Read More

Top 5 Best Adware Removal Tool to Block Annoying Ads in 2019

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Lotus Blossom Hacker Group Uses Dropbox, Twitter, and Zimbra for C2 Communications

The Lotus Blossom hacker group, also known as Spring Dragon, Billbug, or Thrip, has...

Squidoor: Multi-Vector Malware Exploiting Outlook API, DNS & ICMP Tunneling for C2

A newly identified malware, dubbed "Squidoor," has emerged as a sophisticated threat targeting government,...

Unpatched Vulnerabilities Attract Cybercriminals as EDR Visibility Remains Limited

Cyber adversaries have evolved into highly organized and professional entities, mirroring the operational efficiency...

Threat Actors Attack Job Seekers of Fortune 500 Companies to Steal Personal Details

In Q3 2024, Cofense Intelligence uncovered a targeted spear-phishing campaign aimed at employees working...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Lotus Blossom Hacker Group Uses Dropbox, Twitter, and Zimbra for C2 Communications

The Lotus Blossom hacker group, also known as Spring Dragon, Billbug, or Thrip, has...

Squidoor: Multi-Vector Malware Exploiting Outlook API, DNS & ICMP Tunneling for C2

A newly identified malware, dubbed "Squidoor," has emerged as a sophisticated threat targeting government,...

Unpatched Vulnerabilities Attract Cybercriminals as EDR Visibility Remains Limited

Cyber adversaries have evolved into highly organized and professional entities, mirroring the operational efficiency...