
The Unwanted Prize: Launcher Turned Backdoor
Our researchers found a modified Android launcher app, pre-installed on several budget phone models, that can silently install/remove/replace apps over connections that don’t properly validate SSL/TLS certificates and checks every four hours for arbitrary code to execute with system privileges.

