/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researchers: many low-cost Android phones and smart TVs from lesser-known brands come with malware preinstalled, owned by millions globally including in the US

The bane of low-cost Android devices is showing no signs of going away.  —  Overall, Android devices have earned a decidedly mixed reputation for security.

Ars Technica Dan Goodin

Context & Ripple Effects

This report closes a loop that Android security coverage has been tracing for a decade. The 2015 study finding 87% of devices unpatched established the root problem: lesser-known manufacturers never ship security updates, leaving cheap hardware permanently exposed. The new wrinkle is that on many low-cost phones and smart TVs the compromise is now installed at the factory, before the device is ever sold.

The downstream consequences are already documented: a free Lifeline Assistance phone from Assurance Wireless shipped with preinstalled Chinese malware in 2020, and by 2024 Doctor Web's Android.Vo1d botnet had conscripted ~1.3M TV boxes across nearly 200 countries. The 2025 Human Security finding that 1M+ streaming boxes, projectors, and car infotainment units are botnet nodes (per Wired) shows the TV-box side of this pipeline is still growing.

First-order effects

  • Buyers of budget Android phones and TVs — including US Lifeline recipients — are running devices compromised before first boot, with no patch channel from their manufacturers to fix it.

Second-order effects

  • Google's Play services and security-bulletin pipeline becomes the only remediation path for devices their makers abandoned, pushing Google toward mitigations that work regardless of vendor cooperation, like the automatic three-day reboot feature.

Third-order effects

  • If factory-installed malware on white-label hardware keeps feeding botnets of this scale, the long tail of uncertified low-cost Android devices becomes a structural liability — pressuring regulators and Google to restrict which devices can legitimately ship the Android brand.

The trend: Android's security burden is migrating from patch-delivery failure to supply-chain compromise, with cheap off-brand hardware functioning as a persistent global botnet reservoir.

Discussion

  • @dangillmor@mastodon.social Dan Gillmor on mastodon
    If you bought a cheap Android phone or Android-based TV set-top box, it may be “laced with malware” — https://arstechnica.com/...
  • @aparanjape Amit Paranjape on x
    Potentially millions of Android TVs and phones come with malware preinstalled The bane of low-cost Android devices is showing no signs of going away. https://arstechnica.com/...
  • @eff @eff on x
    AllWinner and RockChip Android TV boxes are sold preloaded with malware capable of hijacking the devices for any purpose, including coordinated cyberattacks. “It's an impressive and unsettling operation,” EFF's Bill Budington told @TechCrunch. https://techcrunch.com/...