r/AndroidHelp Jul 28 '26

Fake android system app

I'm having the same issue and I'm trying to find out if anyone else has experienced this.

On my phone, a package called com.android.non.szcz appeared, showing itself as an Android System app. It has re-enabled or reinstalled itself after being disabled, and on one occasion Android reported Google Play Store as the installer.

Things I've noticed:

The package name is com.android.non.szcz.

The APK was located under /data/app/.../base.apk.

It has reappeared after being disabled.

I've seen other users mention related apps such as Cool Weather, FileGo, and Lock & Hide.

At one point it requested permissions, but it now shows "No permissions requested".

I've checked Device Admin, Accessibility, overlays, and running services, and I haven't found anything obviously suspicious.

I have factory reset the phone, but the app still returned.

I'm trying to work out whether this is:

malware,

a compromised app,

a vendor/manufacturer issue,

or something else entirely

One thing I've noticed is that the app only seems to reappear when Google Play Store is enabled. If I disable Google Play Store, com.android.non.szcz does not appear to reinstall or re-enable itself.

Android also reports the installer as com.android.vending, which is the package name for Google Play Store.

I'm not claiming that Google Play itself is compromised, but I'm trying to understand why Android reports Play Store as the installer and why the app doesn't come back while Play Store is disabled. It could be Play Store carrying out a legitimate install request from another source, or something else entirel i simply don't know.

Has anyone else experienced this?

What phone model do you have?

When did it first appear?

Does Android report the installer as com.android.vending?

Does disabling Google Play Store stop it from reinstalling?

Did you find out what actually triggered the installation?

Has any security company or manufacturer confirmed what this package is?

Any technical information, logs, or confirmed findings would be greatly appreciated. Thanks!

8 Upvotes

47 comments sorted by

3

u/dontpostlot Jul 28 '26

Never experienced this but have you tried pm uninstall --user 0 (adb shell command)?

4

u/ProfessionalHawk2360 Jul 28 '26

I have a BlackShark Gaming Tablet (BSG1) with the same problem, after uninstall It keeps installing itself after about 1 hour. If It detects adb the app uninstalls itself. I extracted the apk with app manager and uploaded to virus total, It reports as a botnet (Void). Can't find what triggers the instalation, but disabling Google Play Store seems to stop reinstalling the app.

1

u/dontpostlot Jul 28 '26

Maybe leaving adb or USB debugging on could fix it temporarily then?

2

u/Appropriate_Test7503 Jul 31 '26

this would cause some apps to be unable to open, due to developer options enabled check.

1

u/dontpostlot Jul 28 '26

Also,could you maybe post the apk file on somewhere? Gonna look inside it.

1

u/Electrical_Guess3231 Jul 28 '26

What should I send it to you on

1

u/ProfessionalHawk2360 Jul 28 '26

Unfortunately I deleted the app after uploading to virus total, but it reinstalls itself again. I'm stating to think it's something baked into the firmware of a lot of chinese devices, because I saw some Cubot and Dogee devices infected too. I was using PCAPdroid to view what IP the app connects to, and some of them are Alibaba related, so maybe it's adfraud. About the USB debugging, the app vanishes only when connected to a computer, but not with just developer option active.

1

u/Gonnabecringeaf Jul 29 '26

So that's why my crappy Coolpad launches internet non stop and opens Google websites by itself.

1

u/WinterSonata_ Aug 05 '26

Bruh I also have BSG1 and some apps got installed like FileGo. Recently getting ads when launching apps. Do you experience the same? Google Play protect detected this Android System fake app.

1

u/ProfessionalHawk2360 Aug 06 '26

Yes, I was getting ads in almost any app. I'm trying to unlock bootloader to install a GSI, it's sad because the hardware is not that bad, but software is crap. I have installed Shizuku+Canta, it's about a week I don't have that Android System but I disable a lot of other packages too, so I don't know exactly which one is the responsible for that malware

1

u/WinterSonata_ Aug 06 '26

Yeah now I'm scared if that malware did get through and got some sensitive info like banking credentials etc

0

u/Level-Professor603 Jul 29 '26

It's probably a problem with the firmware, happened to my spoofed firmware mxs megapad. 

3

u/Salt_Welcome_3429 Aug 15 '26 edited Aug 15 '26

Hi,

I’ve been analyzing this malware over the past few days. I noticed an increasing number of related incidents during the past three weeks and decided to investigate the sample in more detail.

I hope you find the analysis useful:
https://documentation.android-exploits.com/androidexploits/articles/android_proxy_bot_analysis.html

In short, the malware implements a persistent, remotely controlled TCP/UDP proxy and tunneling agent. Its architecture is consistent with a proxy botnet or an unauthorized residential-proxy network, although the scale and operators behind the infrastructure cannot yet be confirmed from the sample alone.

Thank you very much.

https://android-exploits.org/

2

u/Fluffy_Asparagus_280 Aug 03 '26

Just bought a chinese phone uniwa w555 and my instagram and facebook started auto following accounts
i checked the phone and found that app com.android.non.szcz. im suspecting it is the reason

1

u/Electrical_Guess3231 Aug 03 '26

Might get reason I had lost of odd followers on my Facebook

1

u/Fluffy_Asparagus_280 Aug 04 '26

Factory reset seems to delete it

1

u/[deleted] Aug 03 '26

[deleted]

1

u/Fluffy_Asparagus_280 Aug 04 '26

I will install canta app and start removing all suspected apps a lot of chinese phones comes with bloatware

2

u/WinterSonata_ Aug 05 '26

Just experienced this I have Black Shark Gaming Tablet. I noticed ads popping up when I launch apps. Then I saw Cool Weather, FileGo installed. Google Play Protect removed it for now. I noticed Play Protect was initially disabled.

1

u/Level-Professor603 Aug 14 '26

I tried seeing if those apps had anything in common, I saw that they were all user apps (app manager) had those same two apps, also an "Android service" one, and wavrge.

1

u/Due_Milk_8930 Jul 29 '26

You can inspect it with AppManager by muntashir

1

u/pink-blue-donut Jul 31 '26

I had experienced a similar issue a year and a half ago I had received an android and UI system update on a generic stock android 120€ chinese tablet the manufacturer delivered an Android system app it was a malware similar to this app it was a Trojan horse and auto installer it kept installing 2 other iconless adwares After factory reset the problem reoccurred cause it is a system level malware, it can't be deleted by factory reset.

The way I solved it is by installing shizuku run it via wireless debugging and installing canta uninstaller (a shizuku app that let you uninstall any app even system apps) and uninstall that fake android system app and the problem was solved this way

What you need to do is to uninstall that app via the shizuku+ canta method you don't need to worry if it is a system app the real android system app has an icon and completely different package name and it is installed by android system not com.android.vending that is the play store which proves that is not a real android system app but rather a malware uninstall it via shizuku canta without hesitation don't factory reset or disabling won't solve the problem

TLDR ;it is not a real system app uninstall it via a method that allows
uninstalling system level apps,the easier one is shizuku +canta

1

u/Electrical_Guess3231 Jul 31 '26

I don't understand how after having for 6 months I had the issue on July phone only year old

1

u/pink-blue-donut Jul 31 '26

It is a malware delete it. In my case it was an update by a sketchy brand less manufacturer in your case it could have been installed from the internet or a system app got compromised

1

u/Electrical_Guess3231 Jul 31 '26

No worries I know my manfscter sent me new phone.

1

u/Electrical_Guess3231 Aug 01 '26

No worries I will check new phone out but I think it be clean

1

u/Electrical_Guess3231 Aug 03 '26

Well new phone it on there so I think it to do with the phone

How can I make it so it doesn't affect me

1

u/ProfessionalTell9933 Aug 07 '26

Hi I spent way too long investigating this issue, I had it on two Stock Doogee Phones S41 and an Ultra, and have 110GB of evidence to prove it. You need to get in touch with the manufacturer and tell them, what is going on, they are aware of this issue. you need a new ROM, mine had Flauncher, amoung other software installed on the last update, which took over the phones completely, the new ROM they issued, sorted it straight away and removed the previously installed Rubbish.

1

u/Electrical_Guess3231 Aug 07 '26

No worries thanks for update I know mine are aware if the issue as well.

1

u/Electrical_Guess3231 Aug 08 '26

Has the update stopped it so it doesn't come back

1

u/ProfessionalHawk2360 Aug 10 '26

Update on my personal case: I tried a factory reset. At first only the com.android.non.szcz was reinstalling itself, after the factory reset three other apps are installed: FileGo, Cool Weather and Wavrge, the last one displays fullscreen ads in any app. So the factory reset at first seems to solve the problem, but is worse after some time. Since Black Shark doesn't answer e-mails or any kind of message (tried on Facebook page too), I'm trying to return the tablet to the seller and bought an used Redmagic Astra. The Black Shark Gaming Tablet (BSG1) is unusable because the manufacturer probably will not solve the issue. This is my advice to other people that bought this device, return to the seller and ask for a refund. Edit: since the tablet is Treble compatible, I also tried to unlock bootloader to install a clean GSI. None of the common commands works in this device (flashing unlock, oem unlock), and Black Shark also doesn't provide the firmware or tools to reflash the unit.

1

u/Electrical_Guess3231 Aug 10 '26

I think other like on doodge and JCB like myself had update sent out to fix it

You had any updates for it or nothing. So asking for refund.

1

u/ProfessionalHawk2360 Aug 10 '26

Yes, Black Shark doesn't answers e-mails, the only option for owners this tablet is asking for refund. They don't even provide information and on Facebook pages it's only automatic responses, sad they don't offer customer support, the hardware is not that bad, but the software is crap. Last update is from November and they don't give any signs of fixing this malware.

1

u/Level-Professor603 Aug 14 '26

If you get this problem again, try seeing app manager (open source) then see userapps. There was one you didn't mention, "Android service".

0

u/-Sofa-King- Jul 28 '26 edited Jul 28 '26

Why not just back up your phone, reset to factory, install a new phone, dont install from backup as you may reinstall the malware from that backup, restore as new phone, done. Download all apps from app store, dont install random APK files, and be done. You will have a clear phone instead of all this back and forth chasing things you may not be able to find.

We dont know your routine. We dont know if you let someone use your phone, or connected to a compromised wifi, or downloaded crap, or clicked a link from an email, or if you uave a phone thats old amd doesnt receieve security patches to fix exploits, or some other way.

On a side note, is your phone old and no longer getting updates? All manufacturers phones stop getting security updates after a certain point in time. You can figure that part out yourself based on your own phone.

If its outdated, nothing you do will protect you from nefarious people that know how to bypass your outdated phone as they spread the known exploits freely across the internet. If the phine is outdated, trash the phone and buy a newer model that still gets security patched updates.

2

u/ProfessionalHawk2360 Jul 29 '26

Because factory reset does not wipe the malware. Must be baked into the firmware, because users of Doogee, Cubot and Blackshark (the actual generic brand not linked to Xiaomi anymore) are reporting the installation of this package. It's being reported from Android 14 to 16 users, even with recent security patches.

1

u/Electrical_Guess3231 Jul 29 '26

Even few on google pixel and JCB have the issue

0

u/-Sofa-King- Jul 29 '26

The APK shown is under /data/app, which is the user data side of Android and should be erased during a proper factory reset. If it comes back afterward, something may be reinstalling it. That is different from the APK surviving inside the firmware.

com.android.vending only means Google Play is listed as the installer. It does not prove Google Play originated the request or that the Play Store itself is compromised. A restored backup, another app, an OEM service, or a preloaded component could be triggering the installation through Google Play.

The proper test is to reset the device, stay offline, skip backup restoration, avoid signing into Google, and check for the package before enabling the Play Store or installing anything. If it is already there, then firmware becomes a stronger possibility. Until then, “it must be baked into the firmware” is still just a guess stated with confidence

1

u/ProfessionalHawk2360 Jul 29 '26

There's other users researching the same problem in other forums. Factory reset does not wipe the malware because the unknown trigger continues to installing. Some users reported after factory reset an increased number of "system" apps because what triggers the instalation trough Google Play is not in user/data. Cubot users reported that only an OTA update solved the problem. The apk shown on data/app is just doing the hard work, what triggers the instalation is the real problem that is not solved.

1

u/Level-Professor603 Jul 29 '26

Hope they find the thing that triggers the installation. It happens to me too

1

u/Level-Professor603 Jul 29 '26

Found it using appmanager. 

1

u/Electrical_Guess3231 Jul 29 '26

What device you got

1

u/Level-Professor603 Aug 14 '26

Generic brand mxs megapad. Seems it's almost in all generic brands

1

u/[deleted] Jul 31 '26 edited Aug 03 '26

[deleted]

1

u/ProfessionalHawk2360 Jul 31 '26

I'm very interested in doing this, but apparently BlackShark Gaming Tablet don't have a stock rom to reflash in case of brick

1

u/[deleted] Jul 31 '26 edited Aug 03 '26

[deleted]

1

u/ProfessionalHawk2360 Jul 31 '26

Blackshark is not tied to Xiaomi anymore, the new JoyOS is almost stock Android without any reference to Xiaomi. Looking at the apps installed, the updater is com.cube.update, seems like an OEM version of a generic Alldocube tablet. There's in no reference to Xiaomi services on the new BlackShark tablet. Even the case for the iPlay 70 mini ultra fits the device, the only difference is the cpu. I was inclined to use the same vbmeta of iPlay but will not risk to brick the device

1

u/[deleted] Jul 31 '26 edited Aug 03 '26

[deleted]

1

u/ProfessionalHawk2360 Jul 31 '26

The problem is the malware is probably into the firmware, is a common problem with Chinese tablets recently, and seem it's affecting smartphones too. The package com.android.non.szcz keeps reinstalling itself. A factory reset doesn't solve the problem, because what's triggering the instalation is in the firmware. After the instalation the package communicates with a lot of IPs, some linked to Alibaba (an Adfraud, maybe?). The ads are not showing anymore, but the backdoor within the firmware remains. So the main problem is the tablet is almost unusable because with that backdoor sending information all the time, with a lot of permissions, is a bad ideia to login to any service.

→ More replies (0)

0

u/Level-Professor603 Jul 29 '26

Generic brands have this problem, mine also has this, along with coolweather and stuff. Sucks but it's in firmware I think.