The cheap tablet came out of the box already working for someone else
Nobody downloaded this one. Bitdefender spent roughly two years following a campaign it calls Midnight Mimosa, and the researchers' own summary is about as blunt as security writing gets: it is on the phone before the owner switches it on for the first time, and it cannot be uninstalled.
The hardware is cheap Android gear built on MediaTek platforms, including counterfeits dressed up to look like Samsung and Apple models. Thousands of individual devices across more than 150 countries, with Mexico and France at the top of the list. Because the malicious component sits in the system partition rather than anywhere a user can reach, it runs with system privileges: installing and removing apps on its own, granting itself permissions, pulling down and running fresh code whenever the operators decide to. Bitdefender watched it switch the Google Play Store off while it installed payloads and switch it back on afterwards, which leaves the owner with nothing to notice. Thirteen apps on Google Play were talking to the same infrastructure, without the firmware version's privileges.
Part of what it does is ad fraud, which costs you nothing but battery. The other part should bother anyone with a home router. The device is rented out as a residential proxy, so strangers' traffic leaves your broadband line wearing your IP address. When that traffic is used for scraping or fraud, the trail arrives at your house.
The advice is unglamorous and holds anyway. A no-name tablet priced below what it would cost to build honestly is a gamble, and a gift of one is the same gamble with extra steps. Tendvane's network scan lists every device currently sitting on your Wi-Fi, which is frequently a longer list than people expect.