Primed for Malware: Stop Selling Compromised Android Devices



Time and time again, researchers have found numerous compromised Android devices for sale at large online retailers like Amazon. When these devices get individually reported, we have seen some noted efforts to take them down. But this is a systemic problem and Amazon and other major online retailers must make a corresponding systemic and intentional effort to stop these devices from entering people’s homes and ultimately their networks.

As a refresher: Last year, Google wrote that one major campaign, deemed BADBOX, affected 10 million uncertified devices that were running Android’s open-source software (Android Open Source Project or AOSP). These devices span from TVs and streaming devices to digital picture frames. Even now, someone can go on Amazon and Walmart and buy one of these devices. Not all of them come from Amazon and Walmart, but it’s fair to assume since they have the lion’s share of the market.

Most well-known Android-based devices don’t come with just “stock Android.” The operating system is usually Android plus additional features that the manufacturer wanted. These custom versions of Android often come with pre-installed applications that range from useful to innocuous bloatware to actual malware. Many Android OEMs (original equipment manufacturers) pre-install apps that may not be visibly represented by an icon in your list of installed apps. This obscurity makes the issue particularly hard for users to identify any potential threats.

Since the initial BADBOX analysis, there have been more reports of large campaigns and clusters of different devices participating in malicious activities that utilize people’s home networks to engage in illegal activity. Task forces in the private sector have made an effort to take down these existing Command and Control structures, but these actors may pivot and evolve to flood the market with more devices. 

Online retailers can stop this cycle. A multi-billion dollar company like Amazon should offer more resources, like their anti-fraud efforts, given that these products may have facilitated conditions for large scale attacks and illegal activity. It would also be helpful if they communicated malware-related take downs in a more visible way to consumers who are seeking very similar devices with shared characteristics.

Identifying these devices can be tricky, but it’s not impossible because they tend to follow a pattern. For example, the FBI warned consumers this year to avoid TV streaming devices that claim to provide free sports, tv shows, and movies, a common tactic used by the makers of these malware-filled Android devices that leverages people’s exhaustion from spending money on countless streaming services. We detailed what sorts of indicators to look for on a device you’ve purchased.

But it’s not just the storefronts. There are other parts of this ecosystem that need to improve too, like increased engagement in firmware transparency and the actual manufacturers of the devices themselves being held accountable for these malware laced products.

On Prime Day, we urge retailers like Amazon to better empower users with information they need to make safe and smart decisions.



Source link

  • Related Posts

    Anthropic says Alibaba must be punished for largest Claude cloning attack

    Anthropic accused Alibaba of “brazenly” racing to make a copycat Claude, seemingly unfazed by Trump’s threats to crack down on foreign efforts to copy US frontier models despite depending on…

    Why Amazon Dropped Its OpenAI Movie, Data Center Workers Fight Back, and Meta Leaks Employee Data

    Leah Feiger: Yeah. Senator Bernie Sanders and representative Alexandria Ocasio-Cortez, AOC, they introduced the Data Center Moratorium Act, which would halt the construction of new AI data centers until there…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    Boy, 14, charged with murder over death of teenager Lilly in Wales | Wales

    Boy, 14, charged with murder over death of teenager Lilly in Wales | Wales

    Alberta referendum is a ‘dangerous bluff,’ Mark Carney warns

    Alberta referendum is a ‘dangerous bluff,’ Mark Carney warns

    Anthropic says Alibaba must be punished for largest Claude cloning attack

    Anthropic says Alibaba must be punished for largest Claude cloning attack

    Women’s T20 World Cup: India and South Africa win to take semi-final fight to final day

    Women’s T20 World Cup: India and South Africa win to take semi-final fight to final day

    Gol de Kaan Ayhan y Tuquía vuelve a separarse frente a Estados Unidos

    Gol de Kaan Ayhan y Tuquía vuelve a separarse frente a Estados Unidos

    All the Canadian Politics!