Cyber Security News

Unremovable Spyware on Samsung Devices Comes Pre-installed on Galaxy Series Devices

Samsung has been accused of shipping budget Galaxy A and M series smartphones with pre-installed spyware that users can’t easily remove.

The software in question, AppCloud, developed by the mobile analytics firm IronSource, has been embedded in devices sold primarily in the Middle East and North Africa (MENA) region.

Security researchers and privacy advocates warn that it quietly collects sensitive user data, fueling fears of surveillance in politically volatile areas.

AppCloud tracks users’ locations, app usage patterns, and device information without seeking ongoing consent after initial setup. Even more concerning, attempts to uninstall it often fail due to its deep integration into Samsung’s One UI operating system.

Reports indicate the app reactivates automatically following software updates or factory resets, making it virtually unremovable for average users. This has sparked outrage among consumers in countries such as Egypt, Saudi Arabia, and the UAE, where affordable Galaxy models are popular entry points into Android.

The issue came to light through investigations by SMEX, a Lebanon-based digital rights group focused on MENA privacy. In a recent report, SMEX highlighted how AppCloud’s persistence could enable third-party unauthorized data harvesting, posing significant risks in regions with histories of government overreach.

“This isn’t just bloatware, it’s a surveillance enabler baked into the hardware,” said a SMEX spokesperson. The group called on Samsung to issue a global patch and disclose the full scope of data shared with ironSource.

Social media platforms have amplified the controversy, with viral posts claiming international bans on affected devices. However, official statements from Samsung and regulatory bodies like the FCC deny any such prohibitions, labeling the rumors as misinformation.

Samsung has yet to respond directly to SMEX’s allegations, but a company spokesperson reiterated their commitment to user privacy standards.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Guru Baran

Gurubaran is the Co-Founder and Editor-in-Chief of CyberSecurityNews.com, specializing in vulnerability analysis, malware research, ransomware, and computer forensics.

Recent Posts

Critical RCE Vulnerabilities in AI Inference Engines Exposes Meta, Nvidia and Microsoft Frameworks

Critical RCE Vulnerabilities in AI Inference Engines Exposes Meta, Nvidia and Microsoft Frameworks

As artificial intelligence infrastructure rapidly expands, critical security flaws threaten the backbone of enterprise AI…

12 seconds ago
Iranian SpearSpecter Attacking High-Value Officials Using Personalized Social Engineering Tactics

Iranian SpearSpecter Attacking High-Value Officials Using Personalized Social Engineering Tactics

A dangerous espionage campaign is targeting senior government and defense officials worldwide. Iranian hackers are…

24 minutes ago
New MobileGestalt Exploit for iOS 26.0.1 Enables Unauthorized Writes to Protected Data

New MobileGestalt Exploit for iOS 26.0.1 Enables Unauthorized Writes to Protected Data

A sandbox escape vulnerability affecting iPhones and iPads running iOS 16.2 beta 1 or earlier…

1 hour ago
Researchers Detailed Techniques to Detect Outlook NotDoor Backdoor Malware

Researchers Detailed Techniques to Detect Outlook NotDoor Backdoor Malware

Outlook NotDoor backdoor malware first appeared in threat campaigns identified by Lab52, the intelligence arm…

1 hour ago
North Korean Hackers Infiltrated 136 U.S. Companies to Generate $2.2 Million in Revenue

North Korean Hackers Infiltrated 136 U.S. Companies to Generate $2.2 Million in Revenue

The U.S. Justice Department announced major actions against North Korean cybercrime, including five people admitting…

2 hours ago
Hackers Exploiting XWiki Vulnerability in the Wild to Hire the Servers for Botnet

Hackers Exploiting XWiki Vulnerability in the Wild to Hire the Servers for Botnet

A sharp increase in attacks targeting a critical vulnerability in XWiki servers. Multiple threat actors…

3 hours ago