Live data from Hacker News

US government-funded phones come pre-installed with unremovable malware

blog.malwarebytes.com

11–20 of 37 posts

Re: US government-funded phones come pre-installed with unremovable malware

#11
post #7

Chinese malware on a Chinese phone given to US citizens at a massive discount.. Sounds like a brilliant cyber-espionage tactic.

What intelligence would be gained from the poorest 10% of the US? I'd imagine it is more useful to marketers than actual intelligence agencies (which is in fact who is doing it).

These seem like imaginings based on too little thought and too much paranoia. But whenever "China" comes up, even if it is just a company located there, we get these exact same popular statements without justification.

Re: US government-funded phones come pre-installed with unremovable malware

#12

The article shows how to uninstall it. How does that make it unremovable? The uninstall procedure is fully stock, just a slightly different path than most are used to. Most people hold the icon and drag it to the uninstall text. This goes into the app's info screen from where you can click uninstall.

The article definitely a little confusing. It starts with an edit that gives new info about how to remove "Android/Trojan.HiddenAds.WRACT" which is auto-installed by the Settings app replacement they call "Android/Trojan.Dropper.Agent.UMX" preinstalled on the phone.

> But uninstall the Settings app, and you just made yourself a pricey paper weight.

Re: US government-funded phones come pre-installed with unremovable malware

#13
post #7

Chinese malware on a Chinese phone given to US citizens at a massive discount.. Sounds like a brilliant cyber-espionage tactic.

What intelligence would be gained from the poorest 10% of the US? I'd imagine it is more useful to marketers than actual intelligence agencies (which is in fact who is doing it). These seem like imaginings based on too little thought and too much paranoia. But whenever "China" comes up, even if it is just a company located there, we get these exact same popular statements without justification.

Those people can vote.

Re: US government-funded phones come pre-installed with unremovable malware

#14
post #9

Most corporate issued phones and computers come with lots of pre installed malware too. Apple bakes this into MacOS too (MDM).

A computer program knowingly installed by the owner of the device, functioning to the expected specifications of the owner of the device, is just called software.

Re: US government-funded phones come pre-installed with unremovable malware

#15
post #7

Chinese malware on a Chinese phone given to US citizens at a massive discount.. Sounds like a brilliant cyber-espionage tactic.

What intelligence would be gained from the poorest 10% of the US? I'd imagine it is more useful to marketers than actual intelligence agencies (which is in fact who is doing it). These seem like imaginings based on too little thought and too much paranoia. But whenever "China" comes up, even if it is just a company located there, we get these exact same popular statements without justification.

The scenarios are obvious and virtually limitless. For example:

This low-income person drives to Langley, VA every night at 11pm. He might be a janitor at the CIA. We already know he's poor because he has this phone. Can we find out more and potentially bribe him to leave this ordinary-looking pen in a conference room?

Re: US government-funded phones come pre-installed with unremovable malware

#16
post #4

Earlier quoted context omitted.

If the government is giving you a free phone, I'd hope its because you couldn't otherwise afford one. https://www.fcc.gov/general/lifeline-program-low-income-cons...

With a hand-me-down phone from a friend, the device is still free, and you're getting the subsidy on the monthly service charges.

Poverty clusters. Its quite possible (likely even) there’s no friend with a phone to give.

Re: US government-funded phones come pre-installed with unremovable malware

#17

Earlier quoted context omitted.

What intelligence would be gained from the poorest 10% of the US? I'd imagine it is more useful to marketers than actual intelligence agencies (which is in fact who is doing it). These seem like imaginings based on too little thought and too much paranoia. But whenever "China" comes up, even if it is just a company located there, we get these exact same popular statements without justification.

The scenarios are obvious and virtually limitless. For example: This low-income person drives to Langley, VA every night at 11pm. He might be a janitor at the CIA. We already know he's poor because he has this phone. Can we find out more and potentially bribe him to leave this ordinary-looking pen in a conference room?

Seems like a stretch. If you really want to find the CIA's janitor just drive a passive cellular monitor near it and grab everyone's IMEI and cross-check it. Plus if someone has a full time job with security clearance working for the USG they likely aren't getting a free phone anyway.

Re: US government-funded phones come pre-installed with unremovable malware

#18
post #7

Chinese malware on a Chinese phone given to US citizens at a massive discount.. Sounds like a brilliant cyber-espionage tactic.

If the devices have Bluetooth or similar, couldn’t they function as some distributed monitoring network for other Bluetooth devices, building a database over time of devices?

Maybe I’m just being paranoid.

Re: US government-funded phones come pre-installed with unremovable malware

#19

> The only difference between the two codes are their variable names. The more discernible variant of this malware uses Chinese characters for variable names. Therefore, we can assume the origin of this malware is China. I mean... that’s possible and not an unlikely scenario - I guess. But it’s hardly anything but an anecdote. If I was a Russian or American hacker, I would have Chinese variable names swapped out with…

For what it's worth, if the image they used is representative of the other variable names they found, then that line of reasoning doesn't make sense - the names are just gibberish characters in Chinese, and some even have random radicals and other characters thrown in. This seems more like the type of strings you get when you take a bunch of random valid UCS-2 code points.

Pretty sure I've seen Chinese or other "strange" characters as an artifact of certain code obfuscation in the past.
Post reply on HN