Security researchers reported that a significant share of Android infections stemmed from malware and adware embedded in the system partition or shipped in device firmware, particularly on low-cost smartphones and tablets. Because these components reside in protected system areas, they are difficult to remove without reflashing the device and can survive normal cleanup efforts. The report said 14.8% of users hit by malware or adware over the prior year had infections in the system partition, with prevalence reaching 27% for some budget vendors.
Researchers identified two main infection paths: malware that gains root access and installs itself into system directories, and ad-related code inserted into firmware before devices are sold. Threats observed included Triada, Lezok, Agent.pe, Sivu.c, Plague.f, Agent.pac, Penguin.e, Necro.d, Facmod.a, Guerrilla.i, Virtualinst.c, and Secretad.c, which were linked to silent app installation, intrusive advertising, code downloading, and remote control capabilities. The report also highlighted adware-like behavior in some Meizu apps and the widespread presence of the /bin/fotabinder binary, which could download and execute code from remote servers, underscoring supply-chain security risks in budget Android devices.

Trace attribution and downstream blast radius.
1 event from the most recent confirmed update back to the earliest known activity.
Securelist published an analysis of Android adware and malware embedded in device system partitions or preinstalled firmware, describing how such threats are difficult or risky for users to remove. The report identified common families including Triada, Lezok, Agent.pe, Sivu.c, Plague.f, Agent.pac, Penguin.e, Necro.d, Facmod.a, Guerrilla.i, Virtualinst.c, and Secretad.c, and said some low-cost vendors preinstall adware as part of their business model.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 32 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.