logo

Threat Research: Pre-Installed Android Malware

ID: 0c694cae-416c-5410-84b9-7808e4ccf2b8

STIX ID: report--0c694cae-416c-5410-84b9-7808e4ccf2b8

Feed Name: Zimperium Blog

Threat Score
50/100

Date Published: 2017-03-16

Date Updated: 2026-05-01

...
...

**Executive Summary:** Twenty-one malicious apps from the Loki and SLocker families were found pre-installed on at least 36 high-end smartphone models sold via unofficial channels (e.g., eBay), with Loki enabling root access and data theft and SLocker performing device-locking ransomware operations; zIPS can detect these apps but fully removing pre-installed infections requires re-flashing the device.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.