Motorola smartphones in the United States were found to intercept launches of the native Amazon Shopping app and briefly route users through a browser-based affiliate tracking link before opening Amazon. Researchers and users traced the behavior to Smart Feed, a preinstalled system component tied to an app recommendation or search feature, with network analysis linking requests to devicenative[.]com. The redirect reportedly hijacked launcher intents and injected an Amazon Associate referral token without user awareness, creating privacy, integrity, and undisclosed monetization concerns on affected devices, including the Motorola Razr 60 Ultra.
Technical scrutiny found the redirect was often invisible unless Android link-handling settings exposed the browser hop, but researchers warned the same server-side mechanism could theoretically be repurposed for phishing or credential-harvesting without a firmware update. Additional concern focused on the redirect infrastructure, including a domain said to have been registered only days earlier and tied in registration records to an independent fashion marketing blogger, raising insider-threat questions. Motorola later said the behavior was unintended, called it a configuration error, and stated it had corrected the routing so apps now launch directly, while backlash continued over the adware-like design and supply-chain trust implications.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Motorola stated that the redirect behavior was unintended and caused by a configuration error in an application recommendation or search feature developed with a third-party advertising affiliate. The company said it quickly corrected the routing so affected apps now launch directly, ending the affiliate redirect behavior.
Subsequent analysis linked the behavior to the preinstalled Smart Feed app, which intercepted Amazon app launches and sent requests through affiliate-tracking infrastructure including devicenative[.]com. Researchers also noted suspicious characteristics around the redirect setup, including a domain reportedly registered three days earlier and tied in registration records to an independent fashion marketing blogger.
A Motorola Razr 60 Ultra user reported that launching the native Amazon Shopping app triggered a brief browser-based redirect through an affiliate tracking link before opening Amazon. This observation led to further scrutiny of Motorola's preinstalled Smart Feed component.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.