Android Phones Preinstalled With Malware That Collects Data, Injects Ads and Drains Battery: Report

Around 8.9 million devices from over 50 smartphone makers have reportedly been infected by the Guerrilla malware over a period of five years.

Advertisement
Written by David Delima, Edited by Siddharth Suvarna | Updated: 22 May 2023 11:27 IST
Highlights
  • The Guerilla malware was first detected five years ago
  • The malware is now preinstalled on several Android smartphones
  • An infected phone can also be directed to download more malware modules

The Guerrilla malware was first detected in 2018, spreading via the Google Play store

Photo Credit: Pixabay

Android smartphones from various manufacturers have reportedly been found to be infected with malware out-of-the-box, affecting users from multiple countries including India, Indonesia, Mexico, Thailand, Russia, and the US. The software can compromise the affected user's privacy and lead to a poor user experience due to excessive battery usage. The Guerrilla malware can also update itself and implant additional software on the victim's phone to collect personal data and inject ads into regular apps, according to security researchers.

Security firm Trend Micro recently reported that around 8.9 million Android phones were infected with the Guerrilla malware, adding that handsets from over 50 manufacturers were affected. The research was presented at the recently concluded Black Hat Asia 2023 security conference. The malware operator behind the Guerrilla malware reportedly has similarities with the Triada malware that was detected on phones in 2016.

The malware, which is preinstalled on these phones, can negatively impact a user's experience including battery drain and use of resources like the phone's processing power. as per the report. It is worth noting that the security firm has not mentioned any of the manufacturers or models affected by the malware. The Guerrilla malware was first detected on smartphones in 2018, and the malware was detected on apps downloaded via the Google Play store.

Advertisement

According to details shared by Trend Micro, the Guerrilla malware can install additional malicious software via a command and control (C&C) server controlled by the attacker known as the Lemon Group. These "modules" can collect user data to be sold to advertisers, inject ads to gain revenue, and use up the resources on the victim's phone. The malware is also capable of controlling popular messaging app WhatsApp, allowing it to send texts for "overseas marketing", according to the report.

Advertisement

The report states that smartphones from Asia and North America were impacted the most with 55.26 percent and 16.93 percent of all devices affected, respectively. Countries that were most affected by malware are the Angola, Argentina, India, Indonesia, Mexico, Russia, South Africa, Thailand, the Philippines, and the US.

While Trend Micro says that its investigation was aimed at smartphones, other IoT devices like Android TV and smart TV boxes, entertainment systems, and Android-based watches for children have also been infected by the Lemon Group. The security firm estimates that the malicious software has been spread to smartphones in several countries over a period of five years, likely translating to a significant profit for the Lemon Group behind the malware.

Advertisement


Google I/O 2023 saw the search giant repeatedly tell us that it cares about AI, alongside the launch of its first foldable phone and Pixel-branded tablet. This year, the company is going to supercharge its apps, services, and Android operating system with AI technology. We discuss this and more on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. OnePlus Pad Go 2 Launched in India With 10,050mAh Battery, 5G Connectivity
  2. OnePlus 15R Review
  3. OnePlus 15R With 7,400mAh Battery, Snapdragon 8 Gen 5 Debuts at This Price
  4. Apple's iPhone 18 Pro, iPhone Fold May Feature a Relocated Selfie Camera
  5. Realme 16 Pro+ 5G Listed on Certification Website With These Specifications
  6. OnePlus 15, Nord CE 5 Prices Slashed During Community Sale: See Offers
  7. Dhurandhar OTT Release Date: What We Know So Far
  8. Xiaomi 17 Ultra Surfaces on Regulatory Websites, Might Launch Soon
  9. JWST observations may unlock new clues about dark matter
  10. You Can Now Make Amazon Pay Transactions With Biometric Authentication
  1. Google Releases Gemini 3 Flash, Outperforms 3 Pro Model in Speed and Coding Performance
  2. James Webb Space Telescope Could Help Reveal Dark Matter in a Way Scientists Did Not Anticipate
  3. Interstellar Comet 3I/ATLAS Nears Earth on Dec. 19, Offering Rare Insights Into Cosmic Visitors
  4. Europe’s Ariane 6 Rocket Lifts Off With First Galileo Satellites, Boosting Europe’s Navigation Network
  5. NASA’s Parker Solar Probe Observes Solar Wind Making ‘U-Turn’, Shedding Light on Space Weather
  6. ESA Reveals City-Size ‘Cosmic Butterfly’ Crater on Mars Containing Signs of Ancient Water
  7. The Holy Grail of Eris OTT Release: Know When and Where to Watch it Online
  8. OnePlus Pad Go 2 Launched in India With 10,050mAh Battery, 12.1-Inch Display and 5G Connectivity: Price, Features
  9. OnePlus 15R Launched in India With 7,400mAh Battery, Snapdragon 8 Gen 5 SoC: Price, Specifications
  10. Flex By Google Pay: Google Partners With Axis Bank to Introduce UPI-Powered, Digital Credit Card
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.