Samsung embeds IronSource spyware app on phones across WANA

by the-anarchiston 6/21/2025, 3:06 AMwith 480 comments

by boramalperon 6/21/2025, 3:56 AM

I suspect a strong link between mass surveillance (by corporations for advertising or by states for intelligence purposes) and the very recent targeting of the senior Iranian nuclear scientist and military officers at their homes in Iran.

Wherever you are from or whatever side of the conflict you are on, I think we can all agree that it’s never been easier to infer so much about a person from “semi-public” sources such as companies selling customer data and built-in apps that spy on their users and call home. It allows intelligence agencies to outsource intelligence gathering to the market, which is probably cheaper and a lot more convenient than traditional methods.

“Privacy is a human right” landed on deaf ears but hopefully politicians will soon realise that it’s a matter of national security too.

by AlotOfReadingon 6/21/2025, 3:43 AM

Because the link is down:

https://web.archive.org/web/20250506145643/https://smex.org/...

The article leaves out quite a lot about what AppCloud is, but it's essentially how Samsung monetizes their non-flagship device users and can do things like insert installation advertisements into the notification tray, and silently install apps.

Personally, if I found this on my device it'd be the final straw to grit my teeth and finally get a personal apple device.

by grishkaon 6/21/2025, 3:52 AM

The "unremovable" part is inaccurate. While you can't completely remove it because it resides on the system partition, you most probably can still disable it with an adb command:

    adb shell pm uninstall --user 0 com.package.name
This command is very powerful as it works for any app, even those that have "disable" greyed out in the settings. I disabled the Galaxy Store on my S9 this way for example.

by the-anarchiston 6/21/2025, 4:05 AM

As this post is trending quicker and more than I would have expected it to, I would like to add to this story:

It appears to be a similar case across the MENA region. While the SMEX post primarily focuses on WANA, it is possible to find other reports (e.g. [1]) from the MENA region that describe similar practices by Samsung. There, however, the stories talk about "Aura", rather than "AppCloud".

[1] https://www.moroccoworldnews.com/2025/06/212144/samsung-embe...

by thenthenthenon 6/21/2025, 5:19 AM

AppCloud, developed by the controversial Israeli-founded company ironSource (now owned by the American company Unity)

Yes the Unity 3D engine company wow.

by 0rzechon 6/21/2025, 6:15 AM

Same thing in Europe and North America. AppCloud is present on Samsung devices. Sometimes from the get go, sometimes after system update, sometimes after security update (the irony of that!). Carrier-locked or not, it doesn't matter. Sometimes it's visible only after switching the "Show system applications" toggle on application list in device settings. There are many people reporting that their Galaxy S series phones have it too. This AppCloud stuff is absolutely outrageous!

by reccyon 6/21/2025, 10:48 AM

This article has basically no technical details and scant evidence for the claims made by the authors. It's rage bait that is intended for emotional reaction rather than a curious and intelligent analysis.

by userbinatoron 6/21/2025, 4:22 AM

making it nearly impossible for regular users to uninstall it without root access, which voids warranties and poses security risks

Stop parroting the corporate propaganda that put us into this stupid situation in the first place. Having root access on devices you own should be a fundamental right, as otherwise it's not ownership.

by v5v3on 6/21/2025, 8:31 AM

Samsung is a South Korean company.

South Korean needs USA to protect it.

Consider everything from South Korea to be under the blessings of the NSA.

by msgodelon 6/21/2025, 8:13 AM

I've given up on smartphones. They're all unacceptably bad and for the most part take value out of your life rather than adding it.

I own a $50 Android tablet just for the required certificates to run DUO for work and other than that just use a UMPC with a modem card and VOIP for everything.

by ArtTimeInvestoron 6/21/2025, 5:57 AM

I sometimes think that "track record" is the main value of Google and Apple. They have been around for decades, and except in their own interest to collect data for themselves, I am not aware of any blatant privacy violations of these companies. And one can hope that in their own interest, they keep it that way. That's not great, but it's better than the other companies.

I don't see how any company can compete with this unless they somehow figure out how to make a vastly superior product.

by OutOfHereon 6/21/2025, 4:44 AM

Samsung currently has an unremovable spyware app on North American phones that pastes (records) everything copied to the clipboard by any app. It is the Samsung Keyboard app. It cannot be removed. It doesn't matter if you're using any other keyboard app. Samsung Keyboard pastes (records) everything that gets copied to the clipboard by any app. The Samsung Keyboard app cannot even be disabled from Android.

As an aside, I recall getting a lot more ads when I used Samsung Keyboard.

by Grandeculioon 6/21/2025, 3:18 PM

I found the app on my Samsung phone but I also found something interesting.

Go to Settings->Apps and find the app in the list. Click "Configure in AppCloud" and then click "Personal Data". A form shows up where you can request access to the data or request a deletion of the data.

I just requested access to my data, received an email confirmation where I had to click a link. I am curious to see what they will send me (if they will send me anything).

by ehntoon 6/21/2025, 6:11 AM

Samsung Phone on Australia, it was present on my device also. So not just West Asia and Africa.

I was able to disable it but not remove it, unclear if it will re-enable itself. It had sent about 35mb of data since March 1st, and was enabled as a background service.

by yahoozooon 6/21/2025, 10:07 AM

That feel when you’re going to make an Israeli spy joke then read the article headline and it’s ACTUALLY about an Israeli spy operation.

by mousethatroaredon 6/21/2025, 2:33 PM

Not in this field but, if you're willing to sacrifice performance for security (by avoiding closed, western, hardware) how hard would it be to for a group of top hardware and software engineers to make a secure smartphone?

Id gather you could go very far with the following list:

- Proved correct micro kernel

- Encrypted messaging by default

- Encrypted memory

- Encrypted messaging between processes.

- hardware switches for modems, peripherals and battery

by sneakon 6/21/2025, 3:36 AM

Buying a device that only runs OEN Android is ridiculous for this exact reason.

We need to decouple phone hardware from phone software, as we did with computers.

by anshumankmron 6/21/2025, 7:15 AM

I observed this when I purchased a Samsung phone in 2022. My phone cost 35K INR. Even I found it alarming, apart from having bs apps pre-loaded. Switched to an iPhone a year or so later. Never looked back.

by mellosoulson 6/21/2025, 10:25 AM

Editorialized title. Even the original calls it bloatware not spyware.

by TZubirion 6/21/2025, 6:23 AM

"AppCloud is developed by ironSource, an Israel-founded company (now acquired by American company Unity)"

I did not expect the thing I made games with as a teen to be involved in a global war.

by midtakeon 6/21/2025, 8:48 PM

Supply chain compromise is maybe one of the most cyberpunk aspects of modern security. It's not mathematical but it depends on allegiances, power, and money. Is it too late to introduce cryptographic verification into the supply chain in a way that the customer can be secure, or is it too late and a cyberpunk dystopia is the only future? Can mathematics change the meta?

by autoexecon 6/21/2025, 8:43 PM

Samsung embeds spyware on every device they sell in the US too, we just don't have any privacy laws to stop them.

by Abishek_Muthianon 6/21/2025, 6:04 AM

Even in India the entry level Samsung phones are subsidised by bloatwares, Unfortunately there’s not many options for an entry level phone with regular updates.

So the question is who would we like to be exploited by?

by aszantuon 6/21/2025, 5:29 PM

Couldn't get rid of some assistant that I would have to have registered with Samsung last phone. When it broke I switched over to a used Nokia. Little bit less convenient but I wish they wouldn't keep pushing that annoying spyware stuff on us... I'm perfectly fine to just use my phone for browsing and staying in touch with ppl... Why the f. Do I need Google Assistant which I also can't cancel...I swear, next phone will be one of those bricks for the elderly...

by 31337Logicon 6/21/2025, 8:36 PM

Soooo... What do y'all recommend if I want to run a rooted Android phone? Seems like our options are becoming more and more limited each year. :-(

by xchipon 6/21/2025, 9:42 AM

> AppCloud, developed by the controversial Israeli-founded company ironSource (now owned by the American company Unity), is embedded into devices

We have new spyware coming from Israel, let's update the list:

- Pegasus

- Candiru

- QuaDream

- Cellebrite

- Paragon Solutions

- Nemesis

- AppCloud

by like_any_otheron 6/21/2025, 5:13 PM

It's time to start treating such actions, including/especially when done by corporations, as criminal hacking or an act of war, because as many commenters noted, that is what it amounts to. It's frustrating seeing the consequence be an open letter, where if an individual did this, there would international warrants issued against them.

by ggmon 6/21/2025, 3:51 AM

Would sufficient people change purchase decisions in ways which they could recognise this as a root cause?

by akerstenon 6/21/2025, 3:52 AM

In my experience, Samsung is a label that means "stay far, far away." From the Galaxy Note fiasco to my microwave to my dishwasher to ... Probably at least three other products before I learned my lesson.

I even refuse to buy QD-OLED monitors out of indignation that Samsung makes the panels. Maybe I'm alone but maybe one day we'll boycott lousy companies out of business.

by mightyrabbit99on 6/21/2025, 6:21 AM

The only phone brands that I am aware of which sells phones that are able to be rooted are Samsung and Xiaomi. I'm also in need of a phone that has an SD card slot so I don't see myself switching to any other brand.

by noisy_boyon 6/21/2025, 2:32 PM

The only thing that is stopping me from switching to an iPhone is file level access and Syncthing - is that a solved issue? Anyone care to share?

by nottorpon 6/21/2025, 8:34 AM

> AppCloud, developed by the controversial Israeli-founded company ironSource (now owned by the American company Unity)

Unity the ones doing a game engine?

by AbuAssaron 6/21/2025, 6:52 PM

IronSource spyware is made by an Israeli company

by CriticalRegionon 6/22/2025, 12:49 PM

The article and the post title make it sound like Samsung phones come with NSO software preinstalled and a drone strike is making its way to your living room. It's adware bloat. It's a privacy nightmare. It's predatory on the part of the OEM, be it Samsung or Lenovo or Microsoft or all the other OEMs that preinstall bloatware. It happens to be Israeli (though even that's not true - Unity is an American company).

There's no need to present it as anything less than what it is, it is enough of a scandal already. Fear mongering using the words "Israeli Spyware" just undermines the very just point being made.

by codedokodeon 6/21/2025, 11:07 PM

Good to learn this. Was considering buying Samsung because it seems to be the only non-Chinese [non-spyware ridden] smartphone under $150. But what choices I have left now. Maybe buy a phone that can be reflashed with something open source.

And of course I don't keep anything valuable on the phone, do not login anywhere, do not install apps etc. It is an untrusted device because it does not run Linux.

by viktorcodeon 6/21/2025, 11:43 AM

Fact of life: cheap Android phones are funded by ads. Same holds true for TV sets.

by Iolaumon 6/21/2025, 9:18 AM

A user may not be able to uninstall it, but can they disable it?

by theyinwhyon 6/21/2025, 5:50 AM

Should we expect to have trojans in every unity game now?

by gmercon 6/21/2025, 3:55 AM

If anyone needed another reason to stay the fuck away from Unity

by ingohelpingeron 6/21/2025, 4:31 AM

we need a satslink now!

by bdavbdavon 6/21/2025, 7:41 AM

Is this where we discover we’ve got another Pegasus preloaded.

by hd4on 6/21/2025, 7:46 AM

it's now a case of choosing between who you least care about spying on you - think I'll choose a Chinese phone next time, at least they're not currently engaged in genociding children

by TiredOfLifeon 6/21/2025, 5:49 AM

"Otherwise please use the original title, unless it is misleading or linkbait; don't editorialize."

by Atlas667on 6/21/2025, 4:59 AM

THEY WILL TARGET YOU too if you ever find yourself against western and/or Israeli interests.

Capitalist technologies are the surveillance state incarnate. They must study people in order to manufacture consent.

Remember democracy is majority rule, when have you ever had true control over your political destiny? You KNOW the answer is never.

Democracy =/= trust.

Democracy = control.