Some Android devices ship with applications or update mechanisms that introduce security risks before a user installs anything. This April 2020 article examines several pre-installed threats through Bitsight’s sinkhole observations.

The analysis combines a 24-hour window of events to compare the observed geographic and industry distribution. It discusses threats with different capabilities, including remote access, silent application installation, and insecure over-the-air updates.

The counts refer to observed IP addresses and specific monitored infrastructure. They are not a direct count of distinct devices, and mobile-network addressing limits what can be inferred about individual organizations. The article provides historical context and mitigation guidance.

Read the original article at Bitsight