In many regions, the only way manufacturers and sellers reach consumers is through very economical devices that sacrifice critical aspects like the ability to receive frequent updates, but that's not all. They also preinstall a significant number of unwanted apps and add mechanisms that make their removal difficult. The latest two examples are Android.DownLoader.473.origin and Android.Sprovider.7, trojans that install digital junk in the background and add advertising.

Low-Cost Android Smartphones Infected with Trojans That Reinstall Apps
Trojan

Competing on price is very complicated for some companies, especially when they face markets like China, Russia, India, and Latin America. It has been well proven that in certain regions the so-called "high-end" doesn't gain traction, so their markets fill with alternative options that don't always live up to expectations. One of the first things to fall by the wayside is the ability to update Android, deepening fragmentation. Manufacturers have no interest in developing updates and do everything possible to make consumers move from one device to another. As if that weren't enough, unscrupulous minds decide to extract even more money from these products with the help of preinstalled apps and malicious downloaders.

Low-Cost Android Smartphones Infected with Trojans That Reinstall Apps
The MegaFon Login 4 LTE device was one of those affected by the Android.DownLoader.473.origin trojan.

The Report from Dr. Web

The Russian antimalware company Dr. Web recently published a report on two trojans disguised as downloaders whose objective is to add and reinstall apps without the user's consent. The first is known as Android.DownLoader.473.origin, while the second was identified as Android.Sprovider.7. In the case of Android.DownLoader.473.origin, the module activates as soon as the device completes initialization and waits for a WiFi connection to download a configuration file with specific instructions. Inside that file is the list of apps that are installed in the background. As for Android.Sprovider.7, the trojan can download APKs, run apps, open links in the browser, make calls, add shortcuts to the "desktop", show ads in the status bar and at the top of apps.

Low-Cost Android Smartphones Infected with Trojans That Reinstall Apps
Lenovo hardware was also affected by the trojans.

The complete list of affected devices could be much longer. Most of the names are unknown to us: for example, MegaFon and Digma are Russian brands (a telephone provider and a distributor, respectively). However, Android.Sprovider.7 was detected on two Lenovo devices, the A319 and A6000 smartphones. Dr. Web puts all its suspicions on local resellers, who would be infecting the devices before putting them on sale, but we can't help but remember Superfish...