• After 15+ years, we've made a big change: Android Forums is now Early Bird Club. Learn more here.

Phone is hacked

i am aware you can flash stock software to any samsung device using samsung smartswitch, however most standard users will likely ruin the software of the device trying to do so. By sending in the device to the repair center, the factory software can be reinstalled safely with no issues. Any android users with knowledge of rooting their devices will likely NOT reinstall stock software in favor of their preferred software.

Yes, i am very familiar with the samsung stock software, and i can assure you this particular app in NOT installed by default. Yes, i do have an s7, and yes, it has infected it. If you were to review a full list of all permissions this app has been given in reference to any other apps that come pre-installed from the factory, it is clearly malicious. All samsung framework programs/apps that run on any samsung phone are all handled exclusively by odin and knox. Any com.samsung* based apps are generally followed by *.android* since most samsung phones run the android os. To my working knowledge, there are no samsung core apps that are simply com.samsung.*

The custom roms I have installed on all my Samsung's were developed for a specific bootloader and modem. For the most part, it is recommended, especially when coming from a different rooted rom, to install official stock firmware. Here is just one example of many.


https://forum.xda-developers.com/note-4-sprint/development/rom-updated-1-14-2017-t3538051

Screenshot_2020-03-05-16-24-42.png
 
I can say that you have been hacked and it is through the internet or network. My phones, both of my brothers phones(plus several other ones they have), my daughters phone-and she is 800 miles away from us, plus 3 android tablets, 3 laptops, and 2 desktops have all been hacked! Not to mention my BMW through Bluetooth. I told my parents our conversations were being listened to and it was proven October 11 when they cut in on my parents phone and asked if we were done yet. It sounds sci-fi, spy movie stuff, but it is real. All android devices have been rooted and a factory reset does nothing, cache partition really does nothing and they made it where you can do nothing in boot mode. I have made it into the rooted system but they have it locked down as well. I could view certain files, like the git log. That one file showed where they started hacking my device on 3-22-17. But ramped up and made themselves really known on 9-5-19. They changed some of the security certificates and changed the operating system. Starting with an app that shows up in all androids, system ui. They even got a phone I haven't used in 5 years and did not go on the internet or my email on it. Was in settings only and somehow Wi-Fi was turned on but I never connected it. It does not even have a sim card. I have gotten 2 new phones since 9-14-19. The first one I didn't even get home with when they had gotten into it. 2 weeks later I got another one and it took a day and a half. I have been to 3 public libraries that their computers are also hacked, 2 of them I know came from a guy that had been hacked and used them. My parents were hacked over their magic jack talking to me. It does however seem to attach to Google, Facebook, and Microsoft products or apps. Everything on my devices are overlays. Whatever this malware is, its vicious. My directory tree is very different from my brothers. It seems they are being done by different people. I have found a few apps to look for are System UI, a 2nd Android Setup, Emergency information, Facebook App installer, Facebook App manager, Facebook Services, FM Radio service(did not come on my new phone), AASAservice, Page Buddy, com.codeaurora.FM recording(this is on ALL of our devices, old and new), DirectConnectManager,Email Storage, Email sync, Enterprise Sim Pin Service, epdg test app, filter installer, IMS service, interaction control, lwlan settings(on an android) KLMS Agent, MDMApp, MmsService, Nearby Service, OMACP, Passpoint Settings, added Phone apps, photo screensavers, popupui receiver, ringtone backup, root browser, root pa, RoseEUKor, Safety information, Screen mirroring, secure ui service, security storage, security log agent, settings storage(does settings need storage?), silent logging, smartcard service, software update(I have 2 now), SoundAlive, SysScope, TouchWiz Home(this was added about a year ago) wlan test, Wluc test. I know these to be because around 6 months ago I wrote down all the apps in my phone and in the last month I now have these as well. I just want to let people know there is some bad stuff going around and what to look for and I suggest checking your apps on a regular since they do it quietly at first. I had to disconnect my drivers seat on my car because they were moving it up and down and forward as I drove. Stay alert is all I can say!
Sadly, I have to agree with you. Both my SM-J7Prime, and Tab-A 2017 have been hacked. I have most of the same overlays that you have posted installed on my phone which is now a rooted device. I haven't been able to remove them even in safe mode. My Google account has been cloned. Now my SamsungTab-A 2017 is configured with the same identifier name so that my cell phone carrier can't tell the difference between the two. Of course most say this is not possible but I will back you 100%. It's happened to me too!
 
If your device has had a root malware installed then the only way to get rid if it is to reflash the device. You can find the official firmware at sammobile.com.

Be aware that malware only gets on a device because you, or someone else with access to it, installs it. So don't just reinstall all of your apps because one of them will be the source of the problem.
 
Someone put a hack on my phone using a package it use the calender and I can get it stop iv done a factory reset and change my password several times and lost my Google account can someone help plz






Try not cheating and downloading cheat apps for games frankly in my opinion you deserve what you get maybe you'll learn a lesson from it hopefully that lesson isn't how to fix your phone
 
Given they way TikTok were caught spying on the iOS clipboard, said they'd stop, never stopped and now try to wriggle by claiming that their current constant clipboard access is different from previous, it's very hard to have much trust in them (including their claim that they aren't doing the same on Android, where the OS won't alert the user if they are).
 
You folks have lost your minds. Especially this guy that posted before me. 99% of what you posted to 'watch out for' are stock, OEM apps and services that come installed on the phone from the factory. TouchWiz Home is what operates your freaking phone. A few minutes on Google will prove that. Then again, you'll probably still only believe the things that support your conspiracy theory.

Most conspiracy theorists are like that, in my experience. Even with irrefutable proof, they still stick with their conspiracy, usually going deeper into the conspiracy by now using another crazy theory to explain away the irrefutable proof.

Put the computer duster down and quit vaping brake fluid. That crap kills brain cells and then you come up with conspiracies like what's posted in this thread.


Wow. Just wow. You shouldn't be allowed to spread disinformation like this.

AHAHAHAHAHA!! This made me laugh as I was LITERALLY thinking the same thing while reading these posts.

I mean, like, I really doubt that something this severe would happen to a normal user using a normal unrooted phone (referring to @Been hacked). It would've make more sense if the person in question has had a bad reputation with some people, otherwise it seems kinda irrational to be harassed by some random hacker for no apparent reason.

If this was a Reddit thread, people there would be pretty skeptical towards most of the hacking stories being told.
 
Last edited:
Sadly, I have to agree with you. Both my SM-J7Prime, and Tab-A 2017 have been hacked. I have most of the same overlays that you have posted installed on my phone which is now a rooted device. I haven't been able to remove them even in safe mode. My Google account has been cloned. Now my SamsungTab-A 2017 is configured with the same identifier name so that my cell phone carrier can't tell the difference between the two. Of course most say this is not possible but I will back you 100%. It's happened to me too!

This is why I would much rather buy a Google Pixel or any other Android phone running vanilla Android than a Samsung phone. With Pixel devices you can choose to encrypt all your data on your phone.

From my eyes, Samsung phones always seem like they have a bad reputation when it comes to security (probably due to the insane amount of bloatware they have). Also, those two devices you own are 1) outdated 2) low-end devices and 3) probably running outdated security patches. Best solution is to upgrade to a current flagship device.
 
Last edited:
Actually all Android devices have had their storage encrypted by default for several years, irrespective of manufacturer. And in some respects Samsung's knox system is more secure than a Pixel.

Incidentally I am typing this on a Pixel.
 
Actually all Android devices have had their storage encrypted by default for several years, irrespective of manufacturer. And in some respects Samsung's knox system is more secure than a Pixel.

Incidentally I am typing this on a Pixel.

I thought it was just Nexus devices that were encrypted. Secure or not, in actuality I don't hear much cases of being hacked on a Pixel. Not surprising since Pixels always get the latest Android updates.
 
I thought it was just Nexus devices that were encrypted. Secure or not, in actuality I don't hear much cases of being hacked on a Pixel. Not surprising since Pixels always get the latest Android updates.

I believe since Android 6, all Android devices have encrypted internal storage. Although micro-SDs, and other removable storage are not encrypted by default. Google devices like Pixel not having micro-SD storage of course.
 
I believe since Android 6, all Android devices have encrypted internal storage. Although micro-SDs, and other removable storage are not encrypted by default. Google devices like Pixel not having micro-SD storage of course.

That's partially what I was saying. I meant the Nexus 5X/6P specifically were the first phones I've witnessed to have file-based encryption, which also were Google's marshmallow phones.
 
I thought it was just Nexus devices that were encrypted. Secure or not, in actuality I don't hear much cases of being hacked on a Pixel. Not surprising since Pixels always get the latest Android updates.
Actually Samsung flagships these days often get the monthly security patch a few days before the Pixels (e.g. some Samsung Galaxy S models already have the July security patch, which the Pixels will get next week). OS updates of course lag badly behind the Pixels, but we are talking security here so that's a separate issue. The Pixels probably do get them for longer though, and lower-end Samsungs will get less support.

The truth is that there are very few cases of actual Android hacking to start with, and as there are hundreds of times more Samsungs out there than Pixels it's not clear that you can draw much of a conclusion from the numbers of reports you see. And to stress again, I'm saying this as a Pixel owner and someone who has frequently been critical of Samsung's corporate behaviour. So I'm not speaking as a Samsung fan, just trying to be fair about this.
 
Last edited:
I believe since Android 6, all Android devices have encrypted internal storage.

Default encryption was introduced with Android 6 so if your phone CAME with 6.0 or higher, your data was encrypted and you had to jump through hoops to decrypt it, if you were so inclined. However, if you're phone came with <6.0 and you upgraded to 6.+ and your phone was not previously encrypted (encryption was an option in 5.x) it would not be encrypted as part of the upgrade.
 
Sadly, I have to agree with you. Both my SM-J7Prime, and Tab-A 2017 have been hacked. I have most of the same overlays that you have posted installed on my phone which is now a rooted device. I haven't been able to remove them even in safe mode. My Google account has been cloned. Now my SamsungTab-A 2017 is configured with the same identifier name so that my cell phone carrier can't tell the difference between the two. Of course most say this is not possible but I will back you 100%. It's happened to me too!
 
I can say that you have been hacked and it is through the internet or network. My phones, both of my brothers phones(plus several other ones they have), my daughters phone-and she is 800 miles away from us, plus 3 android tablets, 3 laptops, and 2 desktops have all been hacked! Not to mention my BMW through Bluetooth. I told my parents our conversations were being listened to and it was proven October 11 when they cut in on my parents phone and asked if we were done yet. It sounds sci-fi, spy movie stuff, but it is real. All android devices have been rooted and a factory reset does nothing, cache partition really does nothing and they made it where you can do nothing in boot mode. I have made it into the rooted system but they have it locked down as well. I could view certain files, like the git log. That one file showed where they started hacking my device on 3-22-17. But ramped up and made themselves really known on 9-5-19. They changed some of the security certificates and changed the operating system. Starting with an app that shows up in all androids, system ui. They even got a phone I haven't used in 5 years and did not go on the internet or my email on it. Was in settings only and somehow Wi-Fi was turned on but I never connected it. It does not even have a sim card. I have gotten 2 new phones since 9-14-19. The first one I didn't even get home with when they had gotten into it. 2 weeks later I got another one and it took a day and a half. I have been to 3 public libraries that their computers are also hacked, 2 of them I know came from a guy that had been hacked and used them. My parents were hacked over their magic jack talking to me. It does however seem to attach to Google, Facebook, and Microsoft products or apps. Everything on my devices are overlays. Whatever this malware is, its vicious. My directory tree is very different from my brothers. It seems they are being done by different people. I have found a few apps to look for are System UI, a 2nd Android Setup, Emergency information, Facebook App installer, Facebook App manager, Facebook Services, FM Radio service(did not come on my new phone), AASAservice, Page Buddy, com.codeaurora.FM recording(this is on ALL of our devices, old and new), DirectConnectManager,Email Storage, Email sync, Enterprise Sim Pin Service, epdg test app, filter installer, IMS service, interaction control, lwlan settings(on an android) KLMS Agent, MDMApp, MmsService, Nearby Service, OMACP, Passpoint Settings, added Phone apps, photo screensavers, popupui receiver, ringtone backup, root browser, root pa, RoseEUKor, Safety information, Screen mirroring, secure ui service, security storage, security log agent, settings storage(does settings need storage?), silent logging, smartcard service, software update(I have 2 now), SoundAlive, SysScope, TouchWiz Home(this was added about a year ago) wlan test, Wluc test. I know these to be because around 6 months ago I wrote down all the apps in my phone and in the last month I now have these as well. I just want to let people know there is some bad stuff going around and what to look for and I suggest checking your apps on a regular since they do it quietly at first. I had to disconnect my drivers seat on my car because they were moving it up and down and forward as I drove. Stay alert is all I can say!
I have had the same thing happen. Only a few stories I've found online similar. It started with my Google accounts and possibly a shady ex bf, but has gotten into everything. I believe it started through accessing my home wifi then router. Y device access code was changed when connecting through ethernet. Ive had AT&T here to show them how the default code won't work after resting hard wired through my ethernet. They said to get a different service cause "that's weird" lol. I've had all of my devices shut down at the same time (not even devices on the same service) programs installed as system apps that you can not delete on at least 6 devices. My phone bill with att shows that I'm texting every minute and that some one is using huge loads of data every hour or so. They just show the last number I texted over and over. So. For instance. I'll be sitting next to my boyfriend and it will say I texted him every minute that day. AT&T treated me the same way. Like "what are you? The president?" Meaning who the hell would want to hack me? I don't know that answer , but it's a thing and it's real. I had my last phone completely taken over so I got new service and a new phone. When I got home and used it they had gotten into it already. The start of it was through my Bluetooth I believe, samsung wearable and Bixby. I had several Google accounts and each were taken over where I would change the password and they were right behind changing it again. They use Google voice and set up voip lines to use for a click to call service it seems, where a company pays per call or text for advertising. I've intercepted some voicemails on my Google voice when I've been able to get in. They even have several of my 2factor set up to their own devices. They use knox and have set up an enterprise with workgroups and all of my emails. They use samsung and Microsoft accounts with whatever they're doing also Xbox apps. . I've given up. I just accept that nothing I do is private anymore. The only thing I've been able to use that Kind of helps is a no root firewall from playstore and I block every app and unblock when I need to use it. Here's the big one they constantly try to get through. All disguised as system apps... my next step is a new device under fake name. I've even contacted FCC over this, they say ATT Wwill contact me but never do and since these people have all access to my emails I'll never know what actual correspondence has taken place bthey throw stiff in spam or forward my emails etc. I do believe it's a network/ internet issue that then gives them access to everything in your home wifi. I am not technicologicaloy savvy in the least. I've learned so much from this I'm debating going into some cyber security profession because this shit is a disgusting invasion of privacy and no one has helped me at all. I would pay anything to stop it but all these top notch securoty companies are set up for businesses. I've tried every mallard and anti-virus and paid for so called security but it doesn't help because they can access and change passwords through my email so I inevitably lose access to the account. Also, many developer options set up on my phone. I had no clue what most of this stuff was before this. Please don't discount people's stories or situations simply because it hasn't happened to you or because you don't understand the situation. There's crazy people smarter than you out there...
 

Attachments

  • Screenshot_20220113-092546_NoRoot Firewall.jpg
    Screenshot_20220113-092546_NoRoot Firewall.jpg
    246.1 KB · Views: 209
QUOTE="Hadron, post: 7963274, member: 219218"]If your device has had a root malware installed then the only way to get rid if it is to reflash the device. You can find the official firmware at sammobile.com. Be aware that malware only gets on a device because you, or someone else with access to it, installs it. So don't just reinstall all of your apps because one of them will be the source of the problem.[/QUOTE] I Wanted to offer some more accurate info here - there are several examples of in-the-wild malware and RATs that require ZERO user input. Zero day exploits like what the Israeli masterminds behind Pegasus malware utilize. The
 
You folks have lost your minds. Especially this guy that posted before me. 99% of what you posted to 'watch out for' are stock, OEM apps and services that come installed on the phone from the factory. TouchWiz Home is what operates your freaking phone. A few minutes on Google will prove that. Then again, you'll probably still only believe the things that support your conspiracy theory.

Most conspiracy theorists are like that, in my experience. Even with irrefutable proof, they still stick with their conspiracy, usually going deeper into the conspiracy by now using another crazy theory to explain away the irrefutable proof.

Put the computer duster down and quit vaping brake fluid. That crap kills brain cells and then you come up with conspiracies like what's posted in this thread.


Wow. Just wow. You shouldn't be allowed to spread disinformation like this.


<br>
Germans gave this exact reaction to family members and friends who claimed these same targeted gaslighting tactics were neing used on them during the rise of hitler's fourth reicht and the notorious secret police.

do your own research and see how petty the the things they would do to people were. flatten bike tires daily. move items.around in their homes. open windows to the same height throughout. they named it Zersutsung (sic) and it means "to decay". we hired their brightest minds and now we shall suffer for it.
 
I've had much of the same issues. Even the Hitler 4th Reich rang partly familiar. But nonetheless let me be first to say after the woman a couple posts back: Google workspace. Has anyone ever looked into becoming a Google administrator. Pay like $11 a month and get a "domain" (whatever the he'll that is) and administrative access along with all the things they can do to any Google account. And the best part is they can hide the users like us from even being notified of anyone accessing our stuff. I mean I've tried to contact Google with no replies. I can't even get a login audit log of any admin activity associated with my Google account. And there should be no admin activity as I'm not paying for workspace g suite admin access. And the only way to examine this stuff is to be an admin. It's like wtf! My phone has told me I don't have admin permission or admin access when I've tried to shut off permissions in apps settings. One day I pulled up a credential or security policy or something that told me the admins name. It was "something Web" or Webster or Webber I think. It was a female and I regret not noting how I found it. My phone had voice-mail and forwarding with some 916 phone number as the destination but I still got my calls and text which doesn't make any sense. I'm considering the agent I talked with on the help texting line wasn't even a real AT&T agent when they shut off my forwarding. Why is access to engineer mode now shut off too? Google web pages telling me that my "search was malformed and not to try it again and that's all they know" Wtf did chrome just tell me? Lol. I'm not the freaking president either but I feel important. Now my galaxy s10 doesn't even factory reset normally anymore. I mean through settings or hard factory reset. I've even got a weird recovery page coming up now sometimes. Only found one page concerning that. I'll throw some pics here if I can. But everyone reading this and believing us as crazy as it sounds should maybe share the forum thread or do their own research because I swear narcissists are targeting people to gaslight for whatever reason. Maybe I have a super power I'm unaware of and they want to destroy me first. Idk whatever. I'll break their face if I could ever catch up. Since when. Does a phone; when you factory reset it; go to a white screen with a loading symbol for 20 seconds and them say "welcome" at the setup screen? All done. Reset. Yeah right. Bill gates personal computer traveling In an Einstein relativity capsule through space on the wave of an atomic bomb initiated super nova in a worm hole factory resets in 20 seconds. Sorry bud.
As far as I can tell it is linked to Google administrative access possibly initiated by clicking something in Google drive or Google one and Google calendar. It moves in deeper altering the security policies and credentials. And possibly even originating through the Sims card vulnerability that's common as the cell phones they go in. Look it up. Sim cards haven't had their security patched In a long time and we all are busy running in our circles all day and never even know that something much bigger and very quiet it lurking right above us like a spider that's already got its prey tangled up in the web. So email me any real info. Don't send any links or attachments attachment or pics because I won't open them even though I Hella want too. ***emails redacted*** Thank you. Sorry I didn't have more pics. I factory reset before finding this thread. Even though I don't think the phone is really reset.
 

Attachments

  • Screenshot_20220812-064309_Chrome.jpg
    Screenshot_20220812-064309_Chrome.jpg
    119.7 KB · Views: 118
  • Screenshot_20220812-060343_Chrome.jpg
    Screenshot_20220812-060343_Chrome.jpg
    89 KB · Views: 87
  • Screenshot_20221218-070445_Samsung Internet.jpg
    Screenshot_20221218-070445_Samsung Internet.jpg
    106.1 KB · Views: 93
  • Screenshot_20220812-065133_Settings.jpg
    Screenshot_20220812-065133_Settings.jpg
    245.8 KB · Views: 88
Last edited by a moderator:
I removed your email addressed from the post. The only good thing that can come from that is a ton of spam. If you have notifictions turned on you should get emails if someone replies to this thread.
 
@daniel bill why do you guys that think that your phone is hacked, make these ginormous run-on sentenced single paragraph statements? its so hard to read and understand your points.

all of the stuff you stated does not mean your phone is hacked. hackers for the most part hack phones to steal your identity, get other personal data and even phone numbers from your contact list. hackers do not like to make their presence known.

a factory reset can take up to 20s or so. it is only wiping your data partition and nothing else.

and lastly google admin is not as easy to get into someone else's as you are thinking it to be. if you have doubts about your google account, then change your password and setup two step verification.
 
Back
Top Bottom