Security News > 2019 > June > Tracing the Supply Chain Attack on Android

Tracing the Supply Chain Attack on Android
2019-06-25 14:28

Earlier this month, Google disclosed that a supply chain attack by one of its vendors resulted in malicious software being pre-installed on millions of new budget Android devices. Google didn't exactly name those responsible, but said it believes the offending vendor uses the nicknames "Yehuo" or "Blazefire." What follows is a deep dive into the identity of that Chinese vendor, which appears to have a long and storied history of pushing the envelope on mobile malware.


News URL

https://krebsonsecurity.com/2019/06/tracing-the-supply-chain-attack-on-android/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Android 4 0 17 2 0 19