TL;DR: If it’s also integrated into firmware, it has full-device access. If it’s just this specific app, per Kaspersky, it still has “elevated privileges” and can install crap. It cannot be disabled without breaking the UI.

Doing a scan without copying the apk:

As you can see from main screenshot, the APK would have been accessible for scanning.
I copied it to Download directory as that one gets real-time monitoring, but it will pick it up elsewhere after a scan as well.

Anyway:
VirusTotal report

Found 4 months ago by Kaspersky

And I found my device in list on blog post from Sophos. Unfortunately, they only provide a partial list, as they mention this affects “nearly 50 models”.

From listed domains, with help of strings I found launcher(dot)szprize(dot)cn, although it doesn’t seem to resolve to anything at the moment.

Also something interesting from Kaspersky:

When integrated into the firmware, the malware behaves differently depending on several factors. It will not activate if the language set on the device is one of Chinese dialects, and the time is set to one of Chinese time zones. It will also not launch if the device doesn’t have Google Play Store and Google Play Services installed.

Now what?

I’ve been using it for nearly 2 years, so there’s that…

I am thinking of contacting the retailer I bought this device from, as it’s still in sale. But I am not sure if they will care about it. Also, the only way I seem to be able to contact them is via tech support, so there’s the chance of just getting a copy-pasted answer.

As for my particular unit, I’ll probably try to update the software to newest version to see if it’s still (visibly) present.
Unfortunately, updates on these devices are unstable as fuck, so I’ll have to deal with that. I also hope it won’t make me loose access to MediaTek EngineerMode band selection as that’s something I quite want to keep using.
Or perhaps try to return it under warranty.

Since QuickStep also controls navigation (both gestures and 3-button) it can’t even be disabled even if I used alternative launcher.

  • psychOdelic she/her@discuss.tchncs.de
    link
    fedilink
    English
    arrow-up
    25
    ·
    edit-2
    15 hours ago

    Help I just bought an armor 21…

    (You can contact ulefone, and ask for the firmware for your device, they will send it to you!) I did that, rooted my phoen and removed all google BS with an ADB tool. I hope I’m safe Edit:

    LITERALLY CRASHED AND STOPPED WORKING AFTER WRITING THIS COMMENT.

    Edit: Doesnt turn on

    Edit: Bootloops.

    • WhyJiffie@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      4
      ·
      8 hours ago

      you can’t just remove everything by google that way. the google mobile services package is intehrated to the system in such a way, that uninstalling or even just disabling some of the core google packages will make it bootloop. I don’t know the specifics, but if you want to tinker, have a look at the opengapps installer. see what it is exactly doing in the package for your android version, and try to undo them manually with root. be aware though that its an unofficial project, manufacturers don’t use it, but trying to remove opengapps results in the same situation, so its installer can help you make sense of how is it installed.