Malware which signed users up to subscription services without their permission has been found on thousands of mobiles sold in Africa.
Anti-fraud firm Upstream found the malicious code on 53,000 Tecno handsets, sold in Ethiopia, Cameroon, Egypt, Ghana and South Africa.
Manufacturer Transsion told Buzzfeed it was installed in the supply chain without its knowledge.
Upstream said it was taking advantage of the “most vulnerable”.
“The fact that the malware arrives pre-installed on handsets that are bought in their millions by typically low-income households tells you everything you need to know about what the industry is currently up against,” said Geoffrey Cleaves, head of Upstream’s Secure-D platform.
The Triada malware found by the firm on the Android smartphones installs malicious code known as xHelper which then finds subscription services and submits fraudulent requests on behalf of users, doing so invisibly and without the user’s knowledge.
If the request is successful, it consumes pre-paid airtime, the only way to pay for digital services in many developing countries.
In total, Upstream found what it described as “suspicious activity” on more than 200,000 Tecno smartphones.
According to research firm IDC, Transsion Holdings is one of China’s leading phone manufacturers and in Africa it is the top-selling mobile manufacturer.
In response Tecno Mobile said that the issue was “an old and solved mobile security issue globally” to which it issued a fix in March 2018.
“For current W2 consumers that are potentially facing Triada issues now, they are highly recommended to download the over-the-air fix through their phone for installation or contact Tecno’s after-sales service support for assistance in any questions,” the firm told the BBC in a statement.
It added that it is attached “great importance to consumers’ data security and product safety”.
“Every single software installed on each device runs through a series of rigorous security checks, such as our own security scan platform,” it added.
At the beginning of the year, security firm Malwarebytes warned that similar pre-installed apps were found on another Chinese Android phone – the UMX U686CL. This handset was offered to low-income families in the US via a government scheme.
And in 2016, researcher Ryan Johnson found that more than 700 million Android smartphones had malware installed.
Google, which developed the Android operating system, is aware of the issue.
In a blog written last year, it blamed third-party vendors, used by manufacturers to install features such as face unlock, for pre-installing Triada malware.
It said it had worked with manufacturers to remove the threat from devices.
- Military personnel attached to Speaker’s office withdrawn effective Jan. 14
- Family of 7 killed by fire at Gomoa Budumburam
- ‘I felt embarrassed and frustrated when I failed terminal exams 3 times’ – Failed suicide victim
- You are a motivated beggar with a sense of entitlement – A Plus tells Psalm Adjeteyfio
- Withdrawal of Speaker’s military attachment not meant to deprive him of protection – National Security Ministry
- 4 highway robbers arrested, 4 others on the run
- Fella Makafui wows fans with new photos
- Get away from shore – US and Japan warn on tsunami
- We must have a proper value system as Ghanaians – Kunbuor
- I must leave an impact, not just a celebrity – Kofi Kinaata
Worker unions fear more job losses as local companies halt production over benchmark values
74-year-old exonerated after spending 27 years in prison for murder she didn’t commit
Bawumia urges African central banks to connect payments switches to PAPSS
Tourism industry players decry impact of increases in fuel prices on operations
Fitch downgrades Ghana from B to B- with negative outlook
Forestry Commission builds military camp to check illegal activities in forests in Western North Region
Punish attackers of Radio Ada – Information Ministry to Police
AFCON Day 7 Wrap: Nigeria advance to next round, Salah scores in Egypt win
Withdrawal of Speaker’s military attachment not meant to deprive him of protection – National Security Ministry
MPs on public boards can create conflict of interest – Clara Kasser-Tee
Group warns against tribal, religious sentiments ahead of NPP flagbearership race
Get away from shore – US and Japan warn on tsunami
Thousands gather at Ireland for killed teacher
Nnamdi O. Madichie and Robert Ebo Hinson: AFCON’s ‘disrespect’ and so what
Desist from disseminating unsubstantiated information – Head of Local Government Service to media