Our colleagues at BuzzFeed News, in partnership with Secure-D, a firm dedicated to computer security, have lifted the lid on the asset. 2 Android malware pre-installed on Tecno W2 brand smartphonesOriginally from China, the brand targets developing countries. The entry-level Tecno W2 phones are especially popular in African countries like Senegal, Egypt or Benin.
Triada and xHelper, 2 Ultra-Dangerous Android Malware
After research, Secure-D discovered two malware on select phones marketed by Tecno W2, Triada, and xHelper. Triada, which has been in operation since 2016, is designed to exfiltrate user data. steal bank details and subscribe users to premium online services. In the past, unscrupulous developers loaded Triada onto smartphones from low-cost manufacturers such as LEAGOO and Nomu, right after they were factory-assembled. The malware was injected by third parties during the installation of Android.
For its part, xHelper is even more dangerous. Impossible to remove, the Trojan has the ability to automatically reinstall itself without the knowledge of its victims. It is designed specifically to: show ads without permission on the screen. Xhelper will make the shortcut icon disappear from the victims’ smartphone screen to avoid detection. Most antivirus software on the market cannot detect the presence of the virus.
Tecno W2’s parent company Transsion blames an unidentified independent developer
Questioned by BuzzFeed, Tecno W2’s parent company Transsion Holdings points the finger “unidentified supplier in the supply chain process”. To develop Android layers, Many low-cost Chinese companies use third-party developersUnlike brands like Xiaomi or OnePlus, these companies do not have the tools to code their skins internally.
Sometimes, developers plant malware to generate revenue. In most cases, manufacturers are unaware of the actions of their service providers. According to the survey, these independent developers offer their services at very low prices. In fact, they are aware that the pre-installed malware will earn them more money than the contract signed with the manufacturer.
“We have always attached great importance to consumer data security and product safety. Every software installed on every device goes through a series of rigorous security checks, such as Google Play Protect, GMS BTS and our own security scanning platform, including VirusTotal tests.” says the Chinese group. Transsion also ensures that the fraudulent revenue generated by the malware is not collected by it. Moreover, The group claims to have distributed fixes To remove viruses from infected volumes.
Danger for the most deprived users
This isn’t the first time researchers have detected pre-installed malware. At the beginning of 2018, dangerous malware was detected on 40 Android smartphones, including phones designed by Doogee or Leagoo. In 2016, 28 smartphone models fell victim to a Trojan horse that was pre-installed during assembly. According to Secure-D, pre-installed malware is also hidden in terminals sold by Alcatel in Brazil and Nigeria (and manufactured by TCL). Google recently discovered malware pre-installed on 7.4 million Android smartphones. According to Google security experts, pre-installed malware has been on the rise in recent years. “If you manage to infiltrate the supply chain from the beginning, you will infect as many users as there are devices sold.” explains the Mountain View firm.
After all, malware hidden during compilation mainly targets targets poorest population. “You get all these great features for cheap, but there is a hidden cost. There are a lot of Chinese phones in Africa loaded with malware“ says Kenneth Adu-Amanfoh, president of the African Cybersecurity and Digital Rights Organization, an NGO dedicated to protecting African internet users. As the saying goes, if it’s free (or really cheap), you’re the product.
Source : BuzzFeed
Support our work ❤️
If you enjoyed this article, consider leaving a tip to help us keep publishing great content.



























