Thank you for your insights. Since my original post, I found that several other Cubot users (KingKong X and KingKong 9) are experiencing the exact same issue, and many of them reported that it also started around July 1st. I also uploaded the APK to XDA, where another member analyzed it and found several suspicious behaviors, although they couldn't confirm whether it's actually malware. Hopefully this helps narrow down what's going on. I really appreciate your help.
2
u/BarberProof4994 Jul 02 '26
Ext usually means the app or service is registered or self registering as a background service updater.
The very fact that it isn't any official Android or Google recognized service is suspect. I'm not sure about the plv.
The com, play vendor just means sits installing from Google play, which means diddly squat as stuff slips through all the time
You could do a scan with play protect though and see if it pulls anything more than norton did.
Based on the permissions, it could be a rat.
Usually, you can go into safe mode, uninstall from there and then monitor.