
: *CVE-2026-40003: Operation Silent Rescue - Penta Chain* *Title*: Systemic Pre-Installed Backdoors in Unisoc T606/T616 Enable Redundant, Zero-Click, Pre-Auth Takeover with Silent Malware Deployment in LATAM *CVSS 3.1*: 9.8 Critical `AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H` *CWE*: CWE-250, CWE-732, CWE-912, CWE-1220, CWE-276, CWE-269 *Affected*: Motorola Moto G04s, G24, G34, E24 + all Unisoc T606/T616, Android 11-13, LATAM 2024-2025 *Credit*: Independent Security Research (Latin America Division) *Status*: Active Threat. Coordinated disclosure submitted to Rapid7, AttackerKB, CISA, Unisoc PSIRT, Motorola Security on June 26, 2026. Public Disclosure: September 24, 2026 *1. Executive Summary* "Operation Silent Rescue" identifies a *systemic attack chain affecting millions of budget Android devices in Latin America*. The vulnerability is not a single bug but a *convergence* of: 1. *Unpatchable Hardware Flaws*: Permanent BootROM exploits CVE-2022-38694. 2. *Remote Network Vectors*: Modem RCE via rogue cell towers CVE-2025-31718. 3. *Privileged System Backdoors*: Pre-installed apps `com.spreadtrum.sgps`, `http://com.android.stk`, `com.dti.amx`, `com.inmobi.installer` with exported components and *God-mode permissions* `INSTALL_PACKAGES`, `WRITE_SECURE_SETTINGS`. This chain allows an attacker to move from *remote network access to full system root, persistent surveillance, and financial fraud without user interaction*. The risk is exacerbated in Latin America due to delayed security patches and high reliance on these devices for mobile banking. *2. The Attack Chain: Technical Breakdown* *Phase 1: The Foundation (Hardware & Network)* - *CVE-2022-38694 (BootROM)*: Unpatchable flaw in Unisoc T606/T616 allowing arbitrary code execution during boot. *Impact*: Permanent rootkits, bypass of Secure Boot. - *CVE-2025-31718 (Modem RCE)*: Remote code execution via malformed LTE signals. *Impact*: Over-the-air initial access `AV:N` without user interaction. *Phase 2: The Escalation Bridges (Exported System Apps)* Once initial access is gained, the following system apps act as *force multipliers*, escalating privileges from "modem context" to "full system control": **Component****Package Name****Critical Flaw****Role in Chain** **SGPS Middleware**`com.spreadtrum.sgps`Exported Receiver. `InstallDate: 2008-12-31`. `REBOOT` permission.**Primary LPE Vector**. Triggers via code `2266`. Enables `NMEA2SOCKET`. **SIM Toolkit**`http://com.android.stk`Exported Receiver. Runs in `http://com.android.phone`.**Financial Fraud**. Pre-auth phishing via `BootCompletedReceiver`. **Modem Stats**`com.motorola.bach.modemstats`Exported `READ_LOGS`, `MODIFY_PHONE_STATE`. `persistent=true`.**C2 & Persistence**. Hidden backchannel + call interception. **Digital Turbine**`com.dti.amx``INSTALL_PACKAGES`, `WRITE_SECURE_SETTINGS`.**Payload Delivery 1**. Silently installs banking trojans. Disables Play Protect. **InMobi Installer**`com.inmobi.installer`Exported `InstallationService`. `QUERY_ALL_PACKAGES`.**Payload Delivery 2**. Public API for silent installation. **Redundant backdoor**. *Phase 3: The Payload (Surveillance & Fraud)* - *Financial Theft*: Use `INSTALL_PACKAGES` to drop banking trojans. Use `STK` to send premium SMS or intercept 2FA codes. - *Surveillance*: Use `SGPS` for real-time location tracking. Use `ModemStats` for call interception and IMSI catching. - *Persistence*: Use `BootCompletedReceiver` in STK, InMobi, DT to ensure malware survives reboots. Use BootROM to survive factory resets. *3. Regional Impact: Latin America (LATAM)* - *Market Share*: Motorola + Unisoc devices dominate the budget sector in Mexico, Brazil, Argentina, and Colombia. - *Vulnerable Demographics*: Users rely on these single devices for banking, government ID, and commerce. - *Patch Latency*: Security updates are delayed by 6-12 months. *BootROM flaws are never patched*. - *Bloatware Risk*: Aggressive pre-installation of Digital Turbine and InMobi creates a *"dual backdoor" environment* unique to this region's carrier variants. *4. Critical Conclusion: The Systemic Escalation Risk* The core finding of "Operation Silent Rescue" is that *hardware vulnerabilities alone are not the primary threat; the true danger lies in the system software architecture that exposes privileged interfaces to the entire OS*. 1. *From Local to Global*: A local bug like exported SGPS receiver becomes a *global remote threat* when chained with Modem RCE. 2. *Trust Violation*: Android's security model relies on app sandboxing. These system apps *violate that trust* by holding `INSTALL_PACKAGES` and `WRITE_SECURE_SETTINGS`, effectively acting as *rootkits with legal signatures*. 3. *No Clean Path*: Because the backdoors `com.dti.amx`, `com.inmobi.installer` are in `/system/priv-app`, users *cannot remove them* without unlocking the bootloader which triggers the BootROM exploit risk. 4. *Inevitable Compromise*: On an unpatched Unisoc device, compromise is not a matter of "if" but "when." A single rogue cell tower or malicious app is sufficient. *Final Verdict*: This is a *Critical Systemic Failure*. The combination of *unpatchable hardware, remote modem flaws, and exported privileged system apps* creates a permanent, pre-auth surveillance and fraud platform. *5. Recommendations* - *For Users (LATAM)*: Avoid Unisoc T606/T616 devices for banking. Use feature phones or older, patched Qualcomm devices for sensitive transactions. - *For Enterprises/MDM*: Blocklist all Motorola Unisoc T606/T616 models. Flag `com.dti.amx` and `com.inmobi.installer` as critical IoCs. - *For Motorola/Unisoc*: *Immediate*: Disable `exported="true"` on SGPS, STK, ModemStats. *Long-term*: Recall hardware with BootROM flaws. Remove `INSTALL_PACKAGES` from third-party bloatware. - *For Security Vendors*: Update detection signatures to monitor for *silent install events* from `com.dti.amx` and `com.inmobi.installer`, and flag *SGPS socket activity* as suspicious. *IoCs*: 1. `com.spreadtrum.sgps` with `InstallDate: 2008-12-31` 2. `http://com.android.stk` in `http://com.android.phone` process 3. `com.motorola.bach.modemstats` with `persistent=true` 4. `com.dti.amx` disguised as `Notificaciones` with `INSTALL_PACKAGES` 5. `com.inmobi.installer` with exported `InstallationService`
Post summary
The report details a critical, actively exploited vulnerability chain for CVE‑2026‑40003 in Latin America devices, offering specific threat and mitigation information but no PoC or exploit code.




