I found pre-installed (unremovable) malware on my phone, and ESET doesn't seem to be checking system apps... (Ulefone Armor 24)

4 days ago by Don't forget to stay hydrated.πŸ‰πŸ‰πŸ‰πŸ‰πŸ‰ to c/mildlyinfuriating

TL;DR: If it's also integrated into firmware, it has full-device access. If it's just this specific app, per Kaspersky, it still has "elevated privileges" and can install crap. It cannot be disabled without breaking the UI.

Doing a scan without copying the apk:

As you can see from main screenshot, the APK would have been accessible for scanning.
I copied it to Download directory as that one gets real-time monitoring, but it will pick it up elsewhere after a scan as well.

Anyway:
VirusTotal report

Found 4 months ago by Kaspersky

And I found my device in list on blog post from Sophos. Unfortunately, they only provide a partial list, as they mention this affects "nearly 50 models".

From listed domains, with help of strings I found launcher(dot)szprize(dot)cn, although it doesn't seem to resolve to anything at the moment.

Also something interesting from Kaspersky:

When integrated into the firmware, the malware behaves differently depending on several factors. It will not activate if the language set on the device is one of Chinese dialects, and the time is set to one of Chinese time zones. It will also not launch if the device doesn’t have Google Play Store and Google Play Services installed.

Now what?

I've been using it for nearly 2 years, so there's that...

I am thinking of contacting the retailer I bought this device from, as it's still in sale. But I am not sure if they will care about it. Also, the only way I seem to be able to contact them is via tech support, so there's the chance of just getting a copy-pasted answer.

As for my particular unit, I'll probably try to update the software to newest version to see if it's still (visibly) present.
Unfortunately, updates on these devices are unstable as fuck, so I'll have to deal with that. I also hope it won't make me loose access to MediaTek EngineerMode band selection as that's something I quite want to keep using.
Or perhaps try to return it under warranty.

Since QuickStep also controls navigation (both gestures and 3-button) it can't even be disabled even if I used alternative launcher.

Zachariah 59 points 4 days ago

mildly infuriating

path: 0 24323573, hotness: undefined, score: 59, children: 0
urheber 29 points 4 days ago

Help I just bought an armor 21...

(You can contact ulefone, and ask for the firmware for your device, they will send it to you!) I did that, rooted my phoen and removed all google BS with an ADB tool. I hope I'm safe Edit:

LITERALLY CRASHED AND STOPPED WORKING AFTER WRITING THIS COMMENT.

Edit: Doesnt turn on

Edit: Bootloops.

path: 0 24329225, hotness: undefined, score: 29, children: 4
x00z 8 points 4 days ago

I admire your honesty.

Good luck.

path: 0 24329225 24334161, hotness: undefined, score: 8, children: 0
WhyJiffie 5 points 4 days ago

you can't just remove everything by google that way. the google mobile services package is intehrated to the system in such a way, that uninstalling or even just disabling some of the core google packages will make it bootloop. I don't know the specifics, but if you want to tinker, have a look at the opengapps installer. see what it is exactly doing in the package for your android version, and try to undo them manually with root. be aware though that its an unofficial project, manufacturers don't use it, but trying to remove opengapps results in the same situation, so its installer can help you make sense of how is it installed.

path: 0 24329225 24335441, hotness: undefined, score: 5, children: 1
urheber 2 points 3 days ago

Gid, it worked just fine for a week after removing an abundance of spyware!

(Works again, I'm currently on the device) It was just haunted, dotn worry

path: 0 24329225 24335441 24337504, hotness: undefined, score: 2, children: 0
diaphragmwp 3 points 4 days ago

Is it new enough for GSI? Try some GSI build, like this. Won't work if it's one of the "32-bit mode" bs phones.

path: 0 24329225 24331457, hotness: undefined, score: 3, children: 0
Waterpumpee 26 points 4 days ago

change all your passwords you used with that device. then depends, can you afford a new phone? Go with a more known brand. If you can't, start learning mandarin πŸ˜…

path: 0 24323469, hotness: undefined, score: 26, children: 7
testaccount789 19 points 4 days ago

Yeah.
It sucks as usual manufacturers don't make such crazy devices. This thing has a 22,000mAh battery and quite strong light at the back. And yes, it's a quite heavy brick (647g or 1.43lbs).

I didn't find anything better to compare the thickness to, so here it is next to a 1RU switch and a dumphone:

They have even larger phones, but this is already a second time they've had malware, so I don't know about that...

path: 0 24323469 24323711, hotness: undefined, score: 19, children: 6
socsa 22 points 4 days ago

If it makes you feel any better, that's probably not a 22AH battery either. Stop buying phone on Temu.

path: 0 24323469 24323711 24324744, hotness: undefined, score: 22, children: 5
testaccount789 10 points 4 days ago

There's quite a few devices like this (from other brands as wall). On a full charge with heavy use it lasts me 5 days. The capacity also checked out with a USB tester, although I only tested it during charging from something like 5%.

I could also try a discharge test, but that's going to take around 8 hours (10W max output). If you trust whoever did this test, they got 57 hours of screen on time for video streaming: https://www.devicespecifications.com/...
That has to fit somewhere.

Anyway, I got it on Alza. I wouldn't trust shops like that with anything above, say, EUR 50. Especially not Temu, though I haven't used them personally. The most expensive stuff I got on Aliexpress was around that sum. Two Heltec ESP32 boards with LoRa and RTL-SDR v3 (with the antenna kit).

path: 0 24323469 24323711 24324744 24325353, hotness: undefined, score: 10, children: 0
Agent641 5 points 4 days ago

The battery life on Ulefone devices is one thing they don't actually skimp on. I have one and it will go days without a charge. Performs as advertised. And switched off, left in a drawer for 6 months, it didn't drop a single percentage of battery charge.

path: 0 24323469 24323711 24324744 24331548, hotness: undefined, score: 5, children: 3
socsa 2 points 4 days ago

I don't doubt the battery is big, but a 20AH 1S battery pack is still somewhat larger than the phone in that picture .

path: 0 24323469 24323711 24324744 24331548 24332677, hotness: undefined, score: 2, children: 2
carrylex 21 points 4 days ago

Buying cheap stuff from some obscure company at the other end of the planet sounds like it will make situations like this inevitable...

path: 0 24325965, hotness: undefined, score: 21, children: 8
testaccount789 16 points 4 days ago

Eeeeh, some of these are far from cheap. For example, the Armor 34 Pro that I was interested in is EUR 750.
Unique hardware, that's why. Otherwise I'd have gotten Moto G54 5G. Actually, I tested both, I just liked the Armor 24 more hardware-wise.

Lots of modern electronics feels too boring as it's all the same. Phones, laptops, TVs, they especially feel like copied homework.

path: 0 24325965 24326110, hotness: undefined, score: 16, children: 7
carrylex 4 points 4 days ago

Armor 34 Pro

Okay I just had a look at that and wtf is this smartphone, battery and projector abomination?

How about just buying projector instead? Because that thing will never fit into your pocket anyway...

Moto G54

Yeah that's at least a normal phone.

path: 0 24325965 24326110 24333710, hotness: undefined, score: 4, children: 4
Sylvartas 5 points 4 days ago

The first amazon listing I can find for the armor 34 pro has "andriod 15" on the back of the phone lmao

path: 0 24325965 24326110 24333710 24335843, hotness: undefined, score: 5, children: 0
testaccount789 2 points 4 days ago

I daily drive the Armor 24 which is just a bit thinner. I am a man, so it does fit into most of my pockets (I hear women's clothing has chronic lack of pockets).

I am just that tiny bit of market who likes very unusual things. Unihertz also has some Blackberry-style phones (Titan series), but they don't sell around here, and it's not a brand trustworthy enough for me to import it with basically no warranty.
By the way, Unihertz seems to fund new models via Kickstarter, which I find a bit funny.

path: 0 24325965 24326110 24333710 24333961, hotness: undefined, score: 2, children: 2
punchmesan 1 point 3 days ago

Not that I care, but there's a funny contradiction here. You don't consider Unihertz a trustworthy brand, but you do (or did) consider Ulefone a trustworthy brand? Even a cursory, 30-second search for Ulefone doesn't find anything good to say about them aside for the novel hardware. Did they have a better reputation at the time?

path: 0 24325965 24326110 24333710 24333961 24339862, hotness: undefined, score: 1, children: 1
phoenixz 1 point 4 days ago

I get you. I have an armour 29 pro, the hardware is insanely cool, the software... Meh at best. Still, I'm using it daily and I love the phone but now I feel like I need to fun a bunch of scans on this one too

path: 0 24325965 24326110 24329040, hotness: undefined, score: 1, children: 1
testaccount789 1 point 4 days ago

In this specific case, throwing /system_ext/priv-app/PriLauncher3QuickStep/PriLauncher3QuickStep.apk at VirusTotal would light it up.
But as I found, ESET won't care about system files.
Sophos' Intercept X did find it, but I had to enable scanning of system files in settings. Though I am not sure how reliable they are for AV.
Oh, and if it finds something, it will block you from opening that app. In this case, that being main part of the UI, I couldn't access recent apps and homescreen. So for the chance it flags Settings, it would probably be good to enable ADB in advance (and trust your computer).

Edit: Sophos also mentions PriLauncher.apk. Also if it's in the firmware, you're out of luck. (And you won't know)

path: 0 24325965 24326110 24329040 24333643, hotness: undefined, score: 1, children: 0
possiblylinux127 21 points 4 days ago

Can you post some more details such as device type and country of origin

Esit: I somehow skipped over the title. Is there a reason you went with ulefone? They seem to be shady Chinese company with poor reviews

path: 0 24334859, hotness: undefined, score: 21, children: 1
testaccount789 4 points 3 days ago

Is there a reason you went with ulefone?

Unique hardware, and manual band selection (within MTK Engineer Mode).
For the band selection my only options are basically some manufacturer who didn't bother to remove factory test tools (rare) or a Linux phone (e.g. PostmarketOS).

path: 0 24334859 24341794, hotness: undefined, score: 4, children: 0
Swedneck 12 points 3 days ago

and this is why i make sure any phone i buy is supported by a reputable project like lineageos.

path: 0 24338217, hotness: undefined, score: 12, children: 1
testaccount789 5 points 3 days ago

Yeah...
This time I specifically went with MediaTek to have access to band selection, but MediaTek is basically all of the nails in the coffin when it comes to custom ROMs.
Other option for this would be a closed-source app like NSG with root access (meh).
Or a full-fledged Linux phone so I could just use mmcli like a normal person. That seems to exist at least on PostmarketOS: https://wiki.postmarketos.org/wiki/Modem (unless it's limited in function somehow). I did test it with DWM-222 modem.

MTK Engineer Mode usually gets removed, which isn't surprising as it includes tools like TX-test (for both WiFi and cellular modem) and someone on XDA posted a screenshot of it having IMEI change option. Both of those are likely illegal (probably not for WiFi as that's in license-free band).

path: 0 24338217 24341742, hotness: undefined, score: 5, children: 0
abc 11 points 3 days ago

Don't buy Chinese phones.

path: 0 24338487, hotness: undefined, score: 11, children: 0
semperverus 10 points 4 days ago

Develop a root method for your phone, gain sudo access, and remove it via command line

path: 0 24327193, hotness: undefined, score: 10, children: 9
MonkderVierte 3 points 4 days ago

There's no sudo on Android.

path: 0 24327193 24330599, hotness: undefined, score: 3, children: 8
testaccount789 6 points 4 days ago

There is if you use Termux (on a rooted device).

Termux has been the most important app on my phone. I just get the familiar CLI for everything. For example, MTP has been unreliable in my experience, there's probably lots of apps in Play Store to send/receive files of questionable quality.
And then with Termux I can just rsync over SSH as usual.
Or browse files with SSHFS.

path: 0 24327193 24330599 24333590, hotness: undefined, score: 6, children: 2
MonkderVierte 1 point 3 days ago

Being pedantic, termux is a vm, sudo not native.

Edit: i was too shallow in my understanding of the ways of Termux.

path: 0 24327193 24330599 24333590 24346411, hotness: undefined, score: 1, children: 1
testaccount789 3 points 3 days ago

Nope. You need root access to use sudo. It just runs a shell natively under Android. But you can run QEMU inside Termux.

Without root, you get this:

No 'su' binary found
SU_SEARCH_PATHS: /system/bin/su /debug_ramdisk/su /system/xbin/su /sbin/su /sbin/bin/su /system/sbin/su /su/xbin/su /su/bin/su /magisk/.core/bin/su
sudo requires a 'su' binary that supports the '-c', '--shell', '--preserve-environment' and '--mount-master' options
path: 0 24327193 24330599 24333590 24346411 24346586, hotness: undefined, score: 3, children: 0
semperverus 4 points 4 days ago

There is with tools like magisk and some others that have popped up.

path: 0 24327193 24330599 24333552, hotness: undefined, score: 4, children: 1
MonkderVierte 1 point 3 days ago

Sudo in the broader sense, yes.

path: 0 24327193 24330599 24333552 24346419, hotness: undefined, score: 1, children: 0
Swedneck 3 points 3 days ago

what? are you being pedantic because it's actually "su"?

path: 0 24327193 24330599 24338193, hotness: undefined, score: 3, children: 1
MonkderVierte 1 point 3 days ago

Different tool for different tasks.

path: 0 24327193 24330599 24338193 24346332, hotness: undefined, score: 1, children: 0
xep 2 points 3 days ago

Yes, you must root first.

path: 0 24327193 24330599 24340598, hotness: undefined, score: 2, children: 0
Tollana1234567 8 points 4 days ago

bloatware is very hard to remove from a phone.

path: 0 24329101, hotness: undefined, score: 8, children: 0
Mwa 6 points 4 days ago

ReInstall the ROM + KERNEL?

path: 0 24324498, hotness: undefined, score: 6, children: 8
testaccount789 10 points 4 days ago path: 0 24324498 24325364, hotness: undefined, score: 10, children: 7
Mwa 4 points 4 days ago

then i think you have no option

path: 0 24324498 24325364 24325666, hotness: undefined, score: 4, children: 6
lemongarlic 7 points 4 days ago

This is really a vote with your wallet situation. Don't buy android devices without the option to root and/or bootloader unlock.

path: 0 24324498 24325364 24325666 24325902, hotness: undefined, score: 7, children: 3
testaccount789 6 points 4 days ago

option to root and/or bootloader unlock

This one wouldn't be a problem. Ulefone apparently doesn't lock it down. From unlock wall of shame: https://github.com/...

Enable OEM unlocking in settings, reboot to bootloader, fastboot flashing unlock, and that's it.
But they don't release any source code and use MediaTek, so there's no use of it. 😐

path: 0 24324498 24325364 24325666 24325902 24326198, hotness: undefined, score: 6, children: 1
Mwa 1 point 3 days ago

this is probably my bare minimum for my devices ngl

path: 0 24324498 24325364 24325666 24325902 24341863, hotness: undefined, score: 1, children: 0
testaccount789 4 points 4 days ago

I can try to update to the latest updates and see if it's still there. Problem with these devices is the updates tend to break more things than fix. This phone got Android 15 update like half a year back and there was bunch of people reporting that the power button doesn't work to lock the phone anymore...
If yes, or should I say, me being able to detect it, I'll try to do a warranty claim.

I hate these locked down devices. I want to be able to run whatever I want like on desktops. It's a computer, dammit.

path: 0 24324498 24325364 24325666 24325781, hotness: undefined, score: 4, children: 1
khannie 2 points 4 days ago

there was bunch of people reporting that the power button doesn't work to lock the phone anymore...

Allow me to introduce you to my favourite app....

https://f-droid.org/...

It's front and centre on my home screen. Just so handy.

If you can, I would upgrade just for the security updates.

path: 0 24324498 24325364 24325666 24325781 24330600, hotness: undefined, score: 2, children: 0
WhyJiffie 5 points 4 days ago

From listed domains, with help of strings I found launcher(dot)szprize(dot)cn, although it doesn't seem to resolve to anything at the moment.

it could have other records, like TXT records or something else. It is usable as a channel for one way communication

path: 0 24335301, hotness: undefined, score: 5, children: 0
FireWire400 3 points 4 days ago

Can you remove it via adb shell (if you know what package its part of)?

path: 0 24323388, hotness: undefined, score: 3, children: 1
testaccount789 7 points 4 days ago

I don't think so. It's also responsible for system navigation. (If I force stop it 3-button nav and gestures stop working)

path: 0 24323388 24323480, hotness: undefined, score: 7, children: 0
Agent641 3 points 4 days ago

I have a Ulefone Armour 27T pro and it's really good except for the preindtalled bloatware and that fucking duraspeed thing which, even when disabled and uninstalled via adb, still seems to fuck up my WhatsApp and textra notifications. It's so infuriating that I don't use it as my everyday phone anymore. Very disappointed

path: 0 24331588, hotness: undefined, score: 3, children: 4
testaccount789 1 point 4 days ago

Yeah, DuraSpeed. That even kills alarms if you try to use them.
To be fair, so did my previous Xiaomi Poco. And my Motorola also had a ton of bugs after its very last update (which almost feels intentional).

When did I not have issues? Custom ROM. Upgrading that phone from Android 8 to Android 11 (PixelExperience) even made it miles faster. Oh, and whoever ported it to that phone also made sure to include Moto actions.
There was just one problem. Due to some incompatibility, they couldn't get encryption to work. Trying to enable it would brick the phone.

But I guess it makes sense that someone who is fueled by passion rather than money does a better job.

path: 0 24331588 24333502, hotness: undefined, score: 1, children: 3
Agent641 1 point 3 days ago

Did you use a custom ROM on the Ulefone? If so, which one?

path: 0 24331588 24333502 24341393, hotness: undefined, score: 1, children: 2
testaccount789 1 point 3 days ago

No, sorry for the confusion, I was speaking about the Motorola. I can't find anything for Ulefone.

path: 0 24331588 24333502 24341393 24341540, hotness: undefined, score: 1, children: 1
Agent641 2 points 3 days ago

Damn, neither can I, and I've tried.

Guess it will just live in my lab as a thermal camera and microscope 🀷

path: 0 24331588 24333502 24341393 24341540 24341804, hotness: undefined, score: 2, children: 0
stoy 1 point 4 days ago
path: 0 24323073, hotness: undefined, score: 1, children: 0
DudeImMacGyver -5 points 4 days ago

Wipe it.

path: 0 24323240, hotness: undefined, score: -5, children: 7
kungen 23 points 4 days ago

That won't remove it if it's a factory app...?

If you're living in a country with good consumer rights, I'd return it.

And people wonder how Temu and such can sell tablets so cheap... they're making their money back in many different ways.

path: 0 24323240 24323355, hotness: undefined, score: 23, children: 6
DudeImMacGyver 6 points 4 days ago

Guess I didn't read it properly, I didn't realize it was baked in. Might be able to flash it but the real answer is, just don't buy shit off Temu.

path: 0 24323240 24323355 24324267, hotness: undefined, score: 6, children: 5
testaccount789 0 points 4 days ago

Not from Temu. I see such brands commonly in Slovakian stores.
If I check Alza, a pretty large electronics store, these are the numbers per brand:

Just the options when you shop on a budget. Although Motorola (or Samsung) probably wins it there for the most part.
Anyway, I love such unique hardware, and unfortunately usual brands don't do any unique designs. I guess those died with Blackberry and LG.
For example, at least Unihertz and Ulefone even have phones with a built-in projector. Although... they are actively cooled. And... there's no way to clean out the dust, so I feel like it will just overheat to death after 2 months of collecting pocket lint.

But I also like idea/design of PinePhone and Fairphone. If there was a more powerful version of PinePhone, I'd probably rock that.
I just like when brands actually do something different rather than just sticking to most common 95% and focusing on highest profit.

path: 0 24323240 24323355 24324267 24325567, hotness: undefined, score: 0, children: 4
tomcatt360 5 points 4 days ago

When people here say "Temu" they mean any place where you can buy from companies that have forgettable names, don't care about their reputation, and have zero incentive not to spy on their users and sell their data.

We mean "don't buy things that you won't have full control over just to save money or get a feature that you want".

Best of luck regardless, may your next phone be rootable and repairable!

path: 0 24323240 24323355 24324267 24325567 24327045, hotness: undefined, score: 5, children: 3
mildlyinfuriating
mildlyinfuriating

@lemmy.world

login for more options
46407
1797
4959

Home to all things "Mildly Infuriating" Not infuriating, not enraging. Mildly Infuriating. All posts should reflect that. Please post actually infuriating posts to !actually_infuriating@lemmy.world

I want my day mildly ruined, not completely ruined. Please remember to refrain from reposting old content. If you post a post from reddit it is good practice to include a link and credit the OP. I'm not about stealing content!

It's just good to get something in this website for casual viewing whilst refreshing original content is added overtime.


Rules:

1. Be Respectful

Refrain from using harmful language pertaining to a protected characteristic: e.g. race, gender, sexuality, disability or religion.

Refrain from being argumentative when responding or commenting to posts/replies. Personal attacks are not welcome here.

...


2. No Illegal Content

Content that violates the law. Any post/comment found to be in breach of common law will be removed and given to the authorities if required.

That means: -No promoting violence/threats against any individuals

-No CSA content or Revenge Porn

-No sharing private/personal information (Doxxing)

...


3. No Spam

Posting the same post, no matter the intent is against the rules.

-If you have posted content, please refrain from re-posting said content within this community.

-Do not spam posts with intent to harass, annoy, bully, advertise, scam or harm this community.

-No posting Scams/Advertisements/Phishing Links/IP Grabbers

-No Bots, Bots will be banned from the community.

...


4. No Porn/Explicit

Content


-Do not post explicit content. Lemmy.World is not the instance for NSFW content.

-Do not post Gore or Shock Content.

...


5. No Enciting Harassment,

Brigading, Doxxing or Witch Hunts


-Do not Brigade other Communities

-No calls to action against other communities/users within Lemmy or outside of Lemmy.

-No Witch Hunts against users/communities.

-No content that harasses members within or outside of the community.

...


6. NSFW should be behind NSFW tags.

-Content that is NSFW should be behind NSFW tags.

-Content that might be distressing should be kept behind NSFW tags.

...


7. Content should match the theme of this community.

-Content should be Mildly infuriating. If your post better fits !Actually_Infuriating put it there.

-The Community !actuallyinfuriating has been born so that's where you should post the big stuff.

...


8. Reposting of Reddit content is permitted, but attribution is not required in any way. No links to Reddit in post body

-If you would like to provide a source link, do so in the comments but not in the post body.

...

...


Also check out:

Partnered Communities:

1.Lemmy Review

2.Lemmy Be Wholesome

3.Lemmy Shitpost

4.No Stupid Questions

5.You Should Know

6.Credible Defense


Reach out to LillianVS for inclusion on the sidebar.

All communities included on the sidebar are to be made in compliance with the instance rules.

go to feed...