A few weeks ago Google confirmed that there was malware pre-installed on a number of Android devices due to a supply-chain attack. The latest installment was discovered by security researchers from Dr.Web who have been investigating this situation for several years as it was already theorized by security researchers back in July 2017 that these infections originated as part of a supply-chain attack. In this instance, these devices were pre-installed with Triada, a form of Android malware that has been studied and reported on by Kaspersky and most recently Google in its attempt to surface this critical information to users and the wider community.
Back in 2016 when Triada was analyzed by Kaspersky, it had been described as one of the most complex and sophisticated mobile malware families to date due to having the capabilities of injecting itself into the processes of other applications by compromising the core Zygote process for which each Android application is initiated. It also attempts to hide its presence by removing the downloaded modules from disk and modifying other processes to hide itself from other running applications.
The malware is also quite modular and easily configurable by the author in an attempt to monetize the injection in any way that’s suitable. While many mobile malware focus on ad fraud, Triada was focused on monetizing the botnet through sending premium-rate SMS messages at that time. Kaspersky also noted that other malware families, including Ztorg, had been used as a downloader to inject Triada onto the mobile devices. PrizeRAT, much like Triada, has also been observed to be pre-installed on mobile devices as investigated by Sophos. Triada and other mobile malware are generally installed on devices through malicious applications that were downloaded from Google Play, downloaded from untrusted third-party application stores, sideloaded by users, or included on the system image by default such as in this latest report by Forbes.
The ecosystem of low-cost Android smartphones has been suffering security and privacy setbacks for several years after numerous and continuous reports detailed various forms of device compromises, nearly all of which were compromised out-of-the-box with little ability for the user to remediate the situation without replacing their device entirely due to inaction by the manufacturer. Kryptowire reported that a number of BLU devices contained malicious code that siphoned user’s personal data and communications back to China. While a couple of days later, we reported on a potential backdoor installed on a similar set of BLU devices among many other manufacturers, including Leagoo devices. More recently, the German Federal Office for Information Security put out a statement warning about a backdoor in many Android smartphone models, which continue to mirror those mentioned in previous reports. Several years ago, Google introduced stronger standards and more rigorous evaluations the device image prior to a device being allowed to use Google applications. However, those standards do not necessarily address general backdoors not known to be associated to catalogued malware families.
Our smartphones have continued to be a bastion for sensitive information about their owners and their activity, which also extends into the corporate domain. As BYOD policies continue unfettered, the sensitive information on these devices might not be only limited to the user’s personal information. Malware such as Triada, as reported by Google and Kaspersky, and the RAT as reported by Sophos, pose clear risks to users and all data accessed and stored on those devices.



