Motorola Phones’ Preinstalled App Hijacks Amazon App for Affiliate Fraud
Key Takeaways A preinstalled system application on Motorola smartphones has been found to covertly hijack Amazon app launches. The “Smart Feed” app redirects users through affiliate...
Key Takeaways
- A preinstalled system application on Motorola smartphones has been found to covertly hijack Amazon app launches.
- The “Smart Feed” app redirects users through affiliate tracking URLs, potentially generating undisclosed revenue for an unknown third party.
- This behavior, confirmed on the Motorola Razr 60 Ultra, raises significant concerns about supply chain security and user trust.
- The issue leverages techniques similar to adware and banking Trojans, including intent hijacking and external server communication.
Motorola Phones’ Preinstalled App Hijacks Amazon for Affiliate Fraud
A covert system application, preloaded on Motorola smartphones, has been discovered intercepting attempts to launch the Amazon shopping application. This hidden software then surreptitiously reroutes users through affiliate tracking links before they reach Amazon.com. The revelation sparks serious questions regarding supply chain integrity, user consent, and undisclosed monetization practices on high-end Android devices.
Table Of Content
The unusual activity first came to light through a report by a Motorola Razr 60 Ultra owner on Reddit. The user observed that tapping the Amazon app icon no longer initiated a direct launch. Instead, the device briefly opened a web browser, navigated to an unfamiliar URL, and then redirected to Amazon.com with an integrated affiliate identifier.
How the Affiliate Hijack Works
Subsequent network traffic analysis pinpointed a hidden, preinstalled system application named “Smart Feed” as the orchestrator of this redirection. This application initiates outbound connections to devicenative[.]com, an external server implicated in providing configuration data and affiliate codes for target applications.
When a user selects a shopping application icon from their device’s launcher, Smart Feed intercedes the launch intent. It then replaces the original intent with a browser redirect, embedding the monetization payload. The process is outlined as follows:
- A user taps the Amazon app icon (or potentially other shopping apps) in the launcher.
- The Smart Feed application intercepts this launch intent before it reaches the intended Amazon app.
- Smart Feed queries
devicenative[.]comto retrieve specific affiliate parameters. - A browser window opens, navigating through a redirect URL that ultimately resolves to Amazon.com, now tagged with an injected affiliate ID.
- The user arrives at Amazon.com, generally unaware that revenue credit has been claimed via an intermediary.
This redirection often goes unnoticed by users, primarily because most devices have “Open links in app by default” enabled – a default setting that few users ever alter.
Adware-Like Tactics and Security Implications
Beyond the immediate concern of potential financial misconduct, the observed behavior exhibits characteristics frequently associated with adware and even banking Trojans. These include intent hijacking, the use of hidden system-level persistence, and external command-and-control (C2)-style communication with a remote server (devicenative[.]com) for dynamic configuration. The fact that Smart Feed is a hidden, preinstalled system app makes it difficult for users to detect or uninstall.
From a cybersecurity threat modeling perspective, the architecture currently used to inject affiliate codes could theoretically be updated via the remote server. Such an update could redirect users to malicious phishing sites or credential-harvesting pages without requiring a device firmware update. The reliance on an external domain for behavioral instructions is particularly troubling, as it allows the app’s functionality to be altered dynamically.
The issue has been confirmed on the Motorola Razr 60 Ultra, a premium device with a retail price of approximately $1,300. It remains unclear whether this behavior extends to other Motorola models or regional variants of their smartphones. The domain devicenative[.]com suggests the involvement of a third-party monetization SDK or an affiliate partner, rather than Motorola directly engineering this functionality. Regardless, Motorola bears accountability for bundling such software on its devices. As of this publication, Motorola has not released an official statement. The findings gained broader attention following a report from 9to5Google on May 25, 2026.
What You Should Do
- Monitor App Behavior: Pay close attention if your Amazon app (or other shopping apps) unexpectedly open in a browser first, or if you notice unusual redirects.
- Check Default Link Settings: Navigate to your phone’s settings to review which apps are set to open links by default. If you suspect an issue, disable “Open links in app by default” for your Amazon app to make redirects more visible.
- Report Suspicious Activity: If you own a Motorola device and observe similar behavior, report it to Motorola customer support and consider sharing your findings on relevant tech forums.
- Exercise Caution: Be wary of any preinstalled apps that lack clear functionality or cannot be easily uninstalled.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.