Report Alleges Unisoc/Longcheer Supply Chain Compromise via System Apps
A forensic report claims signed system apps on Unisoc/Longcheer devices enable covert C2 tunnels and anti-forensic kernel panic attacks.
A forensic report claims that devices built on Unisoc T606/T616 chipsets and Longcheer ODM designs (e.g., Motorola Moto G04s) contain manufacturer-signed system apps—fmradio, IMS, and sgps—that are abused to establish covert WireGuard-based C2 tunnels. According to the report, legitimate VoLTE and FM radio functions are used as cover for audio exfiltration, while headset and Bluetooth events are said to trigger deliberate kernel panics that wipe volatile memory to hinder forensic analysis.
The author also alleges that an embedded Longcheer root certificate in the system trust store enables MITM decryption of HTTPS traffic. Because traditional patching is described as infeasible due to BootROM and system-partition constraints, the report proposes operational mitigations—DNS-over-TLS blocking, disabling VoLTE, using power-only USB cables, and SIM replacement—claimed to have held for over 36 days in a live device.
For engineers working on mobile security and supply chain risk, this case illustrates how implicit trust in signed system apps can be exploited through living-off-the-land techniques at the OEM/ODM level. The shared YARA rules offer hash-independent, behavior- and certificate-based detection, but the findings originate from a community submission and have not yet been independently confirmed by CISA or Talos.