Researchers say that 14.8% of Android users targeted with malware or adware last year were left with an infected system partition, making removal difficult
A healthy percentage of Android users targeted by mobile malware or mobile adware last year suffered a system partition infection … Tweets: @kaspersky and @campuscodi Tweets: @kaspersky : Some smartphone suppliers are trying to maximize profits by pre-installing adware on the devices. https://kas.pr/n7v7 Unfortunately for users, pre-installed adware is often impossible to remove without risking damage to the system. https://twitter.com/... Catalin Cimpanu / @campuscodi : Chart in new Kaspersky report shows that up to 5% of all (of Kaspersky's) US users have malware pre-installed on their devices https://t.co/HkzR7AhjTY https://t.co/VF1jscqXgv
Context & Ripple Effects
Android adware has been getting harder to evict for years: researchers flagged root-access adware in third-party app stores back in 2015 as nearly impossible to remove, and the Accessibility Service has repeatedly been abused to force installs that survive uninstall attempts. What is new in the Kaspersky data is where the persistence now lives — not in sideloaded apps but in the system partition itself.
The supply side explains part of it. Some smartphone suppliers pre-install adware for profit margin, which is why Kaspersky's chart shows up to 5% of its own US users carrying factory-shipped malware — a distribution channel no app-store review can catch.
First-order effects
- Affected users cannot clean their devices with a standard uninstall or even a security scan-and-remove cycle; removal risks bricking the system partition, so the practical fix shifts from antivirus software to reflashing or replacing hardware.
- Suppliers caught shipping pre-installed adware face direct reputational exposure through Kaspersky's reporting, since the vendor can name the channel rather than just the malware family.
Second-order effects
- Antivirus vendors like Kaspersky are pushed to differentiate on detection of firmware-level and pre-installed threats, where traditional signature-based scanning of apps finds nothing — and where they must be careful about flagging devices their partners built.
- The economics keep working: the earlier Chinese ad firm earning $300K a month from 10M+ infected devices showed how small per-device ad payouts scale into real revenue, giving suppliers a template for monetizing the install at the factory instead of via an app.
Third-order effects
- If pre-installation becomes a normalized supplier practice, trust migrates up the stack: buyers weigh device provenance alongside software updates, and Google faces pressure over whether its certification program meaningfully constrains what ships in the system partition of certified handsets.
- The pattern across this coverage — hidden apps abusing accessibility features rising to nearly half of Android malware plus system-partition persistence — points toward mobile malware being defined less by what it does than by how permanently it embeds itself.
The trend: Mobile malware is migrating from removable apps toward persistent, supply-chain-embedded infection — pre-installed and system-partition level — outpacing the uninstall-and-scan model that defined Android cleanup for a decade.