{"id":8941,"date":"2023-12-20T12:00:00","date_gmt":"2023-12-20T10:00:00","guid":{"rendered":"https:\/\/blog.eset.ee\/et\/?p=8941"},"modified":"2026-06-14T19:58:47","modified_gmt":"2026-06-14T16:58:47","slug":"these-arent-the-android-phones-you-should-be-looking-for-2","status":"publish","type":"post","link":"https:\/\/blog.eset.ee\/et\/en\/2023\/12\/20\/these-arent-the-android-phones-you-should-be-looking-for-2\/","title":{"rendered":"These aren\u2019t the Android phones you should be looking for"},"content":{"rendered":"<p>When shopping for a new smartphone, you\u2019re likely to look for the best bang for your buck. If you\u2019re on the hunt for a top-of-the-range device but aren\u2019t keen on paying top dollar for it, offerings from lesser-known manufacturers will probably make your shortlist. Indeed, in the fiercely competitive smartphone market you may be even spoiled for choice as some little-known but high-end contenders can, in many respects, rival the flagship products of established tech titans like Apple, Samsung and Google.<\/p>\n<p>On the other hand, while handsets targeting the price-conscious of us may not break the bank, they lose out when assessed against criteria such as brand recognition, competing telecommunications technologies and, in some cases, <a href=\"https:\/\/www.reuters.com\/technology\/european-countries-who-put-curbs-huawei-5g-equipment-2023-09-28\/\">global security and data privacy considerations<\/a>. Prestige (or lack thereof) and pricing policies associated with some manufacturers also have impacts on public perception \u2013 after all, the smartphone has evolved into one of the main status symbols of our time.<\/p>\n<p>In some respects, even some cutting-edge devices can then be relegated to the mid-range or possibly even budget-friendly category. Particularly in the latter, smartphones often come loaded with older Android versions and have lesser, if any, after-purchase support. They often receive neither feature nor security updates, receive them late or only for a short period of time, and their manufacturers may even be barred from the Google Play Store app ecosystem entirely. As shown by several cases where phones were <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/23\/e\/lemon-group-cybercriminal-businesses-built-on-preinfected-devices.html\">shipped with malware straight out of the box<\/a>, supply chain security is another reason for worry.<\/p>\n<h2>Android multiverse?<\/h2>\n<p>With a <a href=\"https:\/\/www.statista.com\/statistics\/272698\/global-market-share-held-by-mobile-operating-systems-since-2009\/\">market share of more than 70 percent<\/a>, or around 3.3 billion active users, Android maintains its position as the leading global mobile operating system (OS). However, all is not equal in the world of Androids. Among Android-powered smartphones with full features, Samsung leads the way with a market share of almost 35 percent while its share of the total smartphone market amounts to 20 percent, right behind Apple.<\/p>\n<p>Samsung is leading the pack not only thanks to its innovativeness and the high quality of its products that feature various options for every budget. Samsung\u2019s lead also has to do with the fact that its phones benefit from security safeguards baked into Google Play and many of its phones come with software updates for longer periods of time than most of its competitors in the fragmented Android ecosystem. This all ultimately ensures optimized hardware and software integration and, by extension, enhances user experience and security.<\/p>\n<p>Meanwhile, new handsets from, for example, Chinese tech giant Huawei, have been barred from the Google Play Store since 2019. In order to maintain its presence on the global market, the company, which boasts its own range of high-end smartphone models, has built its own operating system called HarmonyOS. This OS is largely based on the freely available Android Open-Source Project (AOSP). However, such exclusions from Google Play could have security implications for end users.<\/p>\n<h2>Collective security<\/h2>\n<p>In addition to <a href=\"https:\/\/source.android.com\/docs\/security\/features\">security features baked into Android<\/a>, users also benefit from security extended via the Google Play Store itself and its enabled-by-default Play Protect safeguards. This officially sanctioned Android app environment is built into the phones of smartphone manufacturers who are compliant with US and EU regulations. The store\u2019s security is backed by Google\u2019s App Defense Alliance, which was <a href=\"https:\/\/security.googleblog.com\/2019\/11\/the-app-defense-alliance-bringing.html\">launched in November 2019<\/a> and counts <a href=\"https:\/\/www.eset.com\/me\/about\/newsroom\/press-releases\/press-releases\/eset-becomes-founding-member-of-googles-app-defense-alliance-eset-to-proactively-protect-mobile-ap-7\/\">ESET as a member<\/a>.<\/p>\n<p>The Google Play Store is home to <a href=\"https:\/\/www.businessofapps.com\/data\/metrics\/number-of-apps\/google-play\/\">more than 2.6 million apps<\/a>, and almost all of them could, in theory, have malicious \u201csleeping functionalities\u201d invisible at the time of upload or, as was the case with <a href=\"https:\/\/www.welivesecurity.com\/2023\/05\/23\/android-app-breaking-bad-legitimate-screen-recording-file-exfiltration\/\">Ahmyth malware<\/a> discovered by ESET recently, receive a malicious update later on in an incident also highlighted in Google\u2019s <a href=\"https:\/\/services.google.com\/fh\/files\/blogs\/gcat_threathorizons_full_jul2023.pdf#page=6\">August 2023 Threat Horizons report<\/a>. Where threats are spotted on <a href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/badbazaar-espionage-tool-targets-android-users-trojanized-signal-telegram-apps\/\">security-conscious stores<\/a> like the Samsung Galaxy Store and even the Google Play Store, their operators act quickly to remove the apps.<\/p>\n<p>As such, Android devices are at risk from <a href=\"https:\/\/www.welivesecurity.com\/2022\/05\/04\/3-most-dangerous-types-android-malware\/\">several main types of malware<\/a>. They are banking trojans, which steal login credentials and can even <a href=\"https:\/\/www.welivesecurity.com\/2018\/12\/11\/android-trojan-steals-money-paypal-accounts-2fa\/\">bypass two-factor (2FA) authentication<\/a>. Another threat is posed by Remote Access Trojans (RATs), which can spy on victims and receive direct commands from attackers to steal money, credentials or data, hijack social media accounts and record phone calls. Then there is also Android ransomware that often spreads via malicious links on insecure websites or in emails and messages. Keeping people safe from these kinds of risks is central to the Alliance\u2019s mission.<\/p>\n<h2>Security concerns us all<\/h2>\n<p>Most Android devices come fitted with manufacturer skins on top of the Android barebones version and offer access to Google Play. There are also vendors that have established a foothold in the market with other AOSP-based operating systems, but their app stores and apps available in them aren\u2019t vetted by the App Defense Alliance.<\/p>\n<p>Using third-party app stores or other unvetted places may be tempting, as they feature <a href=\"https:\/\/www.makeuseof.com\/what-are-the-dangers-of-third-party-app-stores\/\">apps that you might not find on mainstream stores<\/a> or offer fully open-source (FOSS) alternatives that bypass regional restrictions \u2013 or they were just not made by a tech giant you don\u2019t want to share your data with. And while some of these stores may be properly regulated and run by <a href=\"https:\/\/www.androidpolice.com\/best-google-play-store-alternatives\/\">legitimate companies<\/a>, there are also <a href=\"https:\/\/www.riskiq.com\/wp-content\/uploads\/2021\/01\/RiskIQ-2020-Mobile-App-Threat-Landscape-Report.pdf\">hundreds of app stores with less strict, if any, vetting processes<\/a>.<\/p>\n<p>A bottom line emerges, where risks from alternative apps and app stores are more likely to impact some phone brands than others, and is a worry especially for those without access to Google\u2019s authentic OS and app environments. [Note: Even people who decide to dispense with the safeguards built into Google Play-supported Android handsets and install apps from outside the official app store can, or will soon be able to, <a href=\"https:\/\/security.googleblog.com\/2023\/10\/enhanced-google-play-protect-real-time.html\">use the store\u2019s real-time scanner<\/a> to check apps from other sources.]<\/p>\n<h2>Cautionary tales abound<\/h2>\n<p>There\u2019s been no shortage of examples of risks involving third-party app stores and phone makers, including those you probably never heard of. Let\u2019s review at least a few that have emerged over the years:<\/p>\n<ul>\n<li>The British NE Regional Economic and Cyber Crime Units <a href=\"https:\/\/www.welivesecurity.com\/2022\/08\/30\/tikshock-dont-get-caught-out-5-tiktok-scams\/\">issued a warning<\/a> back in 2020 about scammers claiming that specific paid-for apps \u2013 <a href=\"https:\/\/twitter.com\/nereccu\/status\/1305855711180718086\">in this case a fake &#8216;TikTokPro&#8217; app<\/a> \u2013 could be downloaded \u201cfree\u201d from certain third-party app stores. Victims got spyware or adware instead.<\/li>\n<li>And, just as there are <a href=\"https:\/\/www.welivesecurity.com\/2020\/09\/30\/aptc23-group-evolves-its-android-spyware\/\">fake apps<\/a>, <a href=\"https:\/\/www.welivesecurity.com\/2021\/04\/20\/whatsapp-pink-watch-out-fake-update\/\">app updates<\/a> and app stores created to lure victims into downloading malware, similar dangers can stem from cheap devices made by B-grade or no-name mobile brands. In 2020, anti-fraud firm <a href=\"https:\/\/www.bbc.co.uk\/news\/technology-53903436\">Upstream found malware<\/a> submitting fraudulent requests for subscription services on 53,000 Tecno W2 smartphones sold in some African countries.<\/li>\n<li>Similar threats, embedded in firmware, could be found in devices bought cheaply on big e-commerce platforms like <a href=\"https:\/\/www.forbes.com\/sites\/thomasbrewster\/2019\/07\/10\/25-million-android-phones-infected-with-malware-that-hides-in-whatsapp\/\">Alibaba<\/a> and <a href=\"https:\/\/arstechnica.com\/information-technology\/2023\/05\/potentially-millions-of-android-tvs-and-phones-come-with-malware-preinstalled\/\">Amazon<\/a> and it\u2019s likely that many budget and ultra-cheap offerings come with \u201cadditional costs\u201d, such as adware and other nastiness.<\/li>\n<li>Cheapo phones aren\u2019t necessarily only distributed in the developing world. In 2020, the U.S. government issued UMX U686CL Android smartphones for low-income users. It turned out later that they had come <a href=\"https:\/\/www.wired.com\/story\/government-funded-phones-preinstalled-malware\/\">preinstalled with unremovable malware<\/a> displaying unwanted advertisements and downloading unauthorized apps.<\/li>\n<\/ul>\n<h2>Here there be monsters<\/h2>\n<p>ESET Research continues to hunt down mobile threats, including those that target users of software from third-party stores or malware distributed in messages or on websites. Recent threats like <a href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/unlucky-kamran-android-malware-spying-urdu-speaking-residents-gilgit-baltistan\/\">Kamran spyware, hidden in a news app in Pakistan<\/a> and downloaded directly from a legitimate news site, show just one of many problems with unvetted apps. After downloading the app and accepting its terms, the app started to gather data like contacts, calendar events, call logs, location information, device files, SMS messages, images and more.<\/p>\n<p>Chances are high that you\u2019re not from the Gilgit-Baltistan region of Pakistan. Regardless of where you live, however, you probably use a diversity of apps that aid you with banking, supply critical news updates, or just serve as entertainment. Whatever the price, brand or operating system powering your chosen handset, you need to explore the online world with caution.<\/p>\n<\/p>\n<p><a href=\"https:\/\/www.eset.com\/int\/home\/mobile-security-android\/?utm_source=welivesecurity.com&amp;utm_medium=referral&amp;utm_campaign=wls-ems&amp;utm_content=these-arent-the-android-phones-you-should-be-looking-for\"><img loading=\"lazy\" decoding=\"async\" alt=\"\" height=\"296\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/ems.png\" width=\"915\"><\/a><\/p>\n<h2>Going for the multi-layered security option<\/h2>\n<p>Among other things, the Kamran campaign laid bare the importance of where users source their apps as well as the need for multiple layers of security on mobile devices. Simply, the arsenal of threats and the diverse attack methods available to criminals \u2013 regardless of location \u2013 demands protection. For this reason, solutions like <a href=\"https:\/\/www.eset.com\/int\/home\/mobile-security-android\/\">ESET Mobile Security (EMS)<\/a> not only block malware as presented in the Kamran case, but also offer comprehensive protection that scans for and blocks potentially harmful websites and comes fitted with payment protection, anti-phishing, and proactive anti-theft capabilities.<\/p>\n<p>From spyware such as <a href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/unlucky-kamran-android-malware-spying-urdu-speaking-residents-gilgit-baltistan\/\">Kamran<\/a> and others threats mentioned in this blog, EMS goes a long way towards protecting you from these threats. In fact, EMS would have caught Kamran twice \u2013 first, via the Anti-Phishing feature that would have prevented accessing the page and second, thanks to its Anti-Virus module that would have scanned the malicious app both before and during the installation process, blocking it as shown in the picture below.<\/p>\n<figure><img decoding=\"async\" alt=\"ems kamran\" height=\"\" src=\"https:\/\/web-assets.esetstatic.com\/wls\/ems-kamran.jpeg\" title=\"\" width=\"\"><\/figure>\n<p>Whether by need or a sense of adventure, if you are diving into the unknown waters of budget-friendly phones from obscure manufacturers, third-party app stores and non-mainstream apps, you may face a perilous journey. In such as journey prioritizing security is a must. The easiest thing you can do is to download a <a href=\"https:\/\/www.eset.com\/int\/home\/mobile-security-android\/\">time-tested security solution<\/a> such as ESET Mobile Security, repeatedly awarded <a href=\"https:\/\/www.av-comparatives.org\/wp-content\/uploads\/2022\/06\/avc_mob_2022.pdf\">by third party testers like AV Comparatives<\/a> and others.<\/p>\n<p class=\"wls-source\"><a href=\"https:\/\/www.welivesecurity.com\/en\/mobile-security\/these-arent-android-phones-you-should-be-looking-for\/\" rel=\"nofollow noopener\" target=\"_blank\">Read the full analysis on WeLiveSecurity \u2192<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>You may get more than you bargained for when you buy a budget-friendly smartphone and forgo safeguards baked into Google Play<\/p>\n","protected":false},"author":5,"featured_media":8942,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[2905],"tags":[],"class_list":["post-8941","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-devices"],"acf":[],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts\/8941","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/comments?post=8941"}],"version-history":[{"count":1,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts\/8941\/revisions"}],"predecessor-version":[{"id":9676,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts\/8941\/revisions\/9676"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/media\/8942"}],"wp:attachment":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/media?parent=8941"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/categories?post=8941"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/tags?post=8941"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}