Confirmed pre-installed factory app on an unbranded MTK device that did steal my DATA folder including encrypted wallets, the app was a flashlight that can read:
Contacts
SD card
Microphone
network
gps
and literally it had permission for everything including NFC which I don't even have on phone, so it's a universal app that factory install on all of their devices.
This is a warning to anyone with unbranded phone that even if you be-careful and not install apps or malware it can be already on your phone from the factory.
The origin of this phone is a small brand from India manufactured in china, and no I am not on any of those countries this was imported here by merchants.
I would recommend you to read permissions for any of the apps that you suspect, also install network monitor and check which applications are using the network.
in my case the pre loaded flashlight was very active, since I am rooted I was able to trace an IP, the data was not even encrypted so thx god my wallet backups are, all data was being passed through port 80, which is a common port not only for web browsing but also for most botnets, because who is gonna suspect or block it? so yeah it's an HTTP botnet.
I will analyze the internals of the app to figure out more, for now I have frozen the app.
Again, please don't trust unbranded phones, I wonder how many was ripped off their wallets or personal information from this method.
I'd like some more information. So the phone came with malicious access software and what you did was put wallet software on it, or did it used as a backdoor to your internal network to access your computer, that has your wallet on it?
The wallet is on the phone, but I noticed strange activity, high internet usage, battery dies fast so I decided to check what's going on and started monitoring each program and how much data it uses, than I started sniffing the app which was a "LED flash".
Another thing, it was using port 80 to communicate with the server, please note that the LED flash needs no internet, have no ads, and is a system app that is spouses to have only one permission "Control LED and maximum it would have take pictures permission for compatibility with some phones", this one had all permissions you could ever imagine on a phone, there was permissions I never seen such as "Start and stop wimax communications" WTF is that an LED flash? really?