My Samsung Work Phone Came Preinstalled With Spyware
Last modified on July 24, 2026 • 9 min read • 1,894 words
Working at the University of Helsinki, you might get the impression that the IT department is serious about protecting your digital safety. For example, the IT department forces all UH employees to take a yearly “exam” to prove that we still remember the basics of computer security and privacy. They also continue – against all experts’ advice – to force users to update their passwords annually. Studies have shown that both above practices are lowering and not increasing the security posture [1,2]. Privacy is more of a theater than reality in today’s digital world [3]. Should I have been surprised that the Android phone model officially recommended by my own IT department came preinstalled with spyware?
Forced to upgrade Earlier this year, I needed to upgrade my work phone since my old one (a OnePlus Nord) had not received security updates since November 2023. The phone was still working perfectly, and the battery lasted easily through the working day. To avoid having to replace my phone again after only four years, I inquired from IT which model they recommended, having a long security update window in mind. The default recommendation was a Samsung Galaxy A35 5G. “Long” meant in this case 4 years [4], which is significantly less than the upper-end models from Google or Apple, which do receive 7 years of security updates nowadays [5].
Curiosity killed the cat Last month, I read an article about AppCloud: a spyware that comes preinstalled on budget Samsung phones targeted for the Middle East and Africa region [6]. Curiosity killed the cat and my piece of mind for a whole month, because I found this software on my new work phone, which had been bought from the Finnish mobile network provider Telia [7].
AppCloud AppCloud is a pre-installed, unremovable application developed by the Israeli/US company ironSource (now part of Unity), and is described in multiple cybersecurity news outlets as spyware [8, 9, 10]. According to reports, the application can collect sensitive user data, including biometric information and device fingerprints, and is typically found on low-budget Samsung devices [11]. I clearly do sensitive work on the device, including using it for multi-factor authentication (MFA), accessing emails containing confidential student information, and essentially most of the work that I do not do in my office at my desktop computer. The presence of what appeared to be manufacturer-installed spyware on an IT-recommended device was a significant security red flag. I contacted UH, Telia’s, and Samsung’s IT helpdesks, setting in motion a weeks-long exchange that was both illuminating and disheartening.
“Nothing to worry about” The initial response from IT was close to “who cares?”. My concerns were characterized as being part of a “noisy” discussion, with the implication that the reports were from a politically motivated activist group and lacked verifiable evidence. Downplaying user concerns is a critical issue in institutional security. I encountered a similar dismissal when using all three helpdesks. Upon first contacting Telia, I was even told that, even if it was spyware, it was from our friends (the US and Israel), and that, being in Finland, there was no reason for concern. Not everybody who got involved in the discussion was equally dismissive, and I continued to provide screenshots and detailed information in the following investigation. I became uneasy when IT’s own checks revealed that my device was an anomaly. Among the other university-procured Samsung devices (Galaxy A35s?) that were sampled, none had AppCloud installed. My phone also appears to be an EU-specific model, not a “grey market” device from the MENA region, as a colleague had speculated. This led to a new theory from IT: that I had inadvertently installed the spyware myself by opting into Samsung’s ecosystem (Samsung Account or Samsung Cloud) during the phone’s initial setup.
The “solution” The proposed solution was to perform a full factory reset of the device and, crucially, to opt out of all Samsung-related features and avoid restoring anything from cloud backups, as either action might reinstall the unwanted application. While IT suggested that disabling the app should be sufficient, they also conceded that a future software update could potentially re-enable it. The responsibility for cleaning the device and ensuring its future security was placed squarely on my shoulders. I doubted that a factory reset would get rid of spyware. If anything, then Israeli companies know mobile phone security (or insecurity) better than anyone [12]. I had to wait for the factory reset until my Christmas vacation, because I need the phone dozens of times every day to authenticate to the university’s digital properties. As I expected, the factory reset did not work, and I contacted Samsung Finland again, who suggested that I should visit a Samsung service center and flash the original Samsung firmware to the device because the AppCloud might have been installed by the carrier/vendor (i.e., Telia). They clearly said that the app is not preinstalled by Samsung. So I used one of my vacation days to cycle to Pitäjänmäki to the nearest authorized Samsung service center. After flashing the original Samsung image to the phone, AppCloud was still there. Did they lie to me?
More testing Technically, both Telia and Samsung were telling the truth. I found out what is going on by doing experiments that involved about a dozen factory resets. The results: When WiFi is not enabled during setup, there is never any AppCloud. But once WiFi or any other means of communication is enabled (either during or after installation), the AppCloud appears after some time by itself. Samsung is technically correct when they say it is not preinstalled by Samsung, because it is just pushed to the device after the user has started to use it.
AppCloud not preinstalled, but downloaded after device activation Samsung is dishonest because once AppCloud has installed itself magically in the background, its info claims “App downloaded from Galaxy Store”. However, I never gave Samsung permission to download anything from the Galaxy Store. When I click “App details in store”, I get to the same page that I see during the initial phone setup, where I had refused to agree to any downloads from the Galaxy Store. Still, none of the items is ticked, but according to the phone, this app was nevertheless downloaded from the Galaxy Store. I am sure this is somehow legally correct. After all, I must give Google permission to push updates and apps to the phone. It’s impossible to start using the phone without doing so, and perhaps Google is also somehow involve".
Samsung ignores end users’ whishes That means that it is irrelevant whether I agree to download apps/updates from the Galaxy Store or not during setup, because Samsung has arranged to push some apps without the need for anybody to agree to anything. Hiding this fact and the inability to uninstall are red flags for me. Officially, the software is used to tailor advertising and app discovery, but in order to tailor advertising, it needs to have some insight into what I am doing on the device. While the only visible permission is “Notifications”, this seems unlikely to be the whole truth. Apparently, the software discloses device identifiers, IP addresses, and behavioral patterns with its customers [11] — although the exact data practices are not transparently reported. Even if it is not spyware, it is likely still violating my privacy.
Samsung is not friendly to aftermarket operating systems Sadly, I cannot install easily LineageOS , crDroidOS , or GrapheneOS on this device, because Samsung does not want you to do that. Otherwise, that would be the solution. Had I bought a OnePlus or Google Pixel phone, installing a freedom and privacy-respecting version of Android would be easy.
Any take-home messages?
- The End-User as the Last Line of Defense: In a chronically underfunded modern digital workplace, security is not a given. It is a struggle that requires constant vigilance and – absent a proactive IT department – a significant investment from the end user. Institutional IT does not always seem to be aware of the latest threats, including those embedded in the devices they recommend. Neither do they seem to be up to date with modern ways of handling IT security. In the outdated IT security model that seems to dominate many of the IT department’s actions, we - the users – are paradoxically the enemies. Instead, IT should make us allies, but this would require meaningful engagement beyond mandatory lecturing and forced password changes. Do I blame IT? Imho, it is the leadership’s role to provide the vision, means, and culture that allow for meaningful security and privacy. For the time being, we users must be our own security advocates.
- The Illusion of Choice: When Samsung asks the user to opt in or opt out of the Samsung surveillance eco-system, the choice is an illusion, at least in the case of AppCloud and for certain user groups.
- The Need for Institutional Accountability: The fact that my university’s IT department still relies on outdated security practices, such as mandatory password changes [1], and mandatory employee “security training” that are known to cause security fatigue [2], points to a larger cultural issue that needs to be addressed. The security fatigue has apparently also reached the very people who are supposed to keep us safe. To my yearly inquiry about why UH is still requiring regular password changes despite all expert advice, I do not even get any real explanation anymore. Last year I was told “that such changes take time”, but this year I was only told “The yearly password renewal requirement is based on the University’s security policy and it remains in effect for now.” I am speechless in the face of such a decline in the intellectual ability to reflect upon one’s own actions and/or laziness to engage in any meaningful way with the very people that are the reason why the IT department exists at all!
Remaining questions Why was my device the only one affected among those sampled? While the vast majority of AppCloud installations are happening outside Europe, individual cases have been reported from a few European countries. Because individual cases do not make sense for user profiling for marketing, are these cases accidents or intentional targeting? I have been aware of a method to remove the AppCloud that has been published on YouTube (probably voiding the phone’s warranty) [13]. I finally tried it out on Christmas Eve. The software at least disappeared from the list of installed apps, but whether it is really gone and gone for good remains to be seen. That would be a nice Christmas present.
References
[1] NIST advises against regular password changes: https://pages.nist.gov/800-63-4/sp800-63b.html
[2] Why mandatory security training makes us less secure: https://medium.com/deeptempo/why-most-security-awareness-training-is-actually-making-you-less-secure-5f4770d8f4e0
[3] The famous Verge “Privacy is Dead” article: https://www.theverge.com/internet-culture/775740/anonymity-privacy-filming-viral-tiktok
[4] Life of lifetimes of Samsung devices: https://endoflife.date/samsung-mobile
[5] The ecological costs of prematurely updating your smartphone: https://en.reset.org/ecological-problem-mobile-phone/?utm_source=chatgpt.com
[6] Malwarebites.com reporting about AppCloud: https://www.malwarebytes.com/blog/news/2025/11/budget-samsung-phones-shipped-with-unremovable-spyware-say-researchers
[7] Finnish mobile phone network provider Telia: https://telia.fi
[8] More online reporting: https://www.androidheadlines.com/2025/11/unremovable-appcloud-app-samsung-phones-privacy-fears-controversy.html
[9] The thread about AppCloud on X: https://x.com/IntCyberDigest/status/1989374273878630761
[10] Discussion thread on Samsung’s own EU user community website https://eu.community.samsung.com/t5/galaxy-a-series/how-do-i-get-rid-of-appcloud/td-p/7918282
[11] The SMEX Open Letter to Samsung: End Forced Israeli App Installations in the WANA Region: https://smex.org/open-letter-to-samsung-end-forced-israeli-app-installations-in-the-wana-region/
[12] The Israeli company Cellebrite which helps the FBI to get into iPhones; https://en.wikipedia.org/wiki/Apple%E2%80%93FBI_encryption_dispute
[13] The YouTube video that explains how to uninstall AppCloud: https://www.youtube.com/watch?v=qBU6kqS1vuY