Pre-Installed Malware in Smart Devices Poses Serious Cybersecurity Risks

Pre-Installed Malware in Smart Devices Poses Serious Cybersecurity Risks

First seen 20 Jun 2026, 20:49 UTC TechtimesTechliciouswww.ic3.govsupport.apple.com 71.0

Article Content

Browse articles
ThreatCluster

A Wall Street Journal investigation revealed that low-cost smart devices from Amazon and Walmart, including digital photo frames and streaming boxes, are being shipped with pre-installed malware that routes internet traffic through users' connections. This malware, identified as residential proxy software, allows cybercriminals to conduct illicit activities while masking their identity. The FBI has issued warnings about these compromised devices, estimating that around 20 million households in the U.S. are affected. The malware is embedded at the factory level, making traditional security measures ineffective. Users remain unaware as their internet connections are exploited for activities like bank fraud and phishing. The investigation found that all tested devices connected to criminal networks immediately upon being powered on. Consumers are urged to check for specific warning signs to identify potentially compromised devices.

Key Points: • Low-cost smart devices from Amazon and Walmart are arriving with pre-installed malware. • The FBI estimates 20 million U.S. homes have at least one infected device. • Consumers can identify risks by checking for specific signs in product listings.

Timeline

2026-01-01
FBI issues advisory on compromised smart devices
The FBI warned that low-cost IoT devices are being used in cybercrime, highlighting the risks of residential proxy software.
Techlicious
2026-06-15
Wall Street Journal investigation published
An investigation revealed that all tested devices from Amazon and Walmart connected to criminal networks immediately after being powered on.
Techtimes
2026-06-20
Techlicious article published
A follow-up article confirmed the findings of the WSJ investigation and provided guidance for consumers on identifying compromised devices.
Techlicious