Bitdefender has uncovered malicious software integration activities in the firmware of Android smartphones on MediaTek platforms, produced in China under various brands. The malicious activity focuses on ad injection and click fraud, as well as maintaining a botnet from these devices, forming a distributed network for organizing DDoS attacks and proxying traffic.
The pre-installed malware primarily targets budget devices, such as the Doogee S200 X and Cubot KINGKONG X, but is also found in counterfeit copies of the Samsung Galaxy (S25 Ultra, S24 Ultra, and Note 18 Ultra) and devices styled like the iPhone. Problematic devices have been recorded in over 150 countries, with the highest numbers detected in Mexico, France, Italy, the USA, Germany, Brazil, and Spain.
Malicious components are delivered disguised as system applications, such as com.android.system.lite, com.android.sys.gmsprot, com.android.sys.bcprot, and com.android.sys.prot, signed with the platform's digital signature and executed with android.uid.system privileges, allowing the installation of applications and management of permissions. The code integrated into the firmware downloads additional applications that directly implement malicious activity and delegates additional permissions, such as access to notifications and SMS. A total of 32 such additional applications have been identified, combining malicious features with a sound editor, weather widget, file manager, app blocker, and OCR.
The primary malicious functionality is integrated into the library libeasy.so, which provides functions for downloading additional malicious modules from external servers. The service for interacting with the controllers servers is camouflaged as an API for checking the weather forecast. Since the malicious components are part of the system partition, removing them requires re-flashing the device or disabling the components via the ADB utility.
Source: opennet.ru
