Researchers: many low-cost Android phones and smart TVs from lesser-known brands come with malware preinstalled, owned by millions globally including in the US
The bane of low-cost Android devices is showing no signs of going away. — Overall, Android devices have earned a decidedly mixed reputation for security.
Context & Ripple Effects
This report closes a loop that Android security coverage has been tracing for a decade. The 2015 study finding 87% of devices unpatched established the root problem: lesser-known manufacturers never ship security updates, leaving cheap hardware permanently exposed. The new wrinkle is that on many low-cost phones and smart TVs the compromise is now installed at the factory, before the device is ever sold.
The downstream consequences are already documented: a free Lifeline Assistance phone from Assurance Wireless shipped with preinstalled Chinese malware in 2020, and by 2024 Doctor Web's Android.Vo1d botnet had conscripted ~1.3M TV boxes across nearly 200 countries. The 2025 Human Security finding that 1M+ streaming boxes, projectors, and car infotainment units are botnet nodes (per Wired) shows the TV-box side of this pipeline is still growing.
First-order effects
- Buyers of budget Android phones and TVs — including US Lifeline recipients — are running devices compromised before first boot, with no patch channel from their manufacturers to fix it.
Second-order effects
- Google's Play services and security-bulletin pipeline becomes the only remediation path for devices their makers abandoned, pushing Google toward mitigations that work regardless of vendor cooperation, like the automatic three-day reboot feature.
Third-order effects
- If factory-installed malware on white-label hardware keeps feeding botnets of this scale, the long tail of uncertified low-cost Android devices becomes a structural liability — pressuring regulators and Google to restrict which devices can legitimately ship the Android brand.
The trend: Android's security burden is migrating from patch-delivery failure to supply-chain compromise, with cheap off-brand hardware functioning as a persistent global botnet reservoir.