To save everyone’s time:
The first app named “File Recovery and Data Recovery” (com.spot.music.filedate) has over 1 million installs, and the second one named “File Manager” (com.file.box.master.gkd) has over 500,000 installs.
Why is it always file manager apps?
Because a file manager app asking for Full Disk Access is not suspicious, and Full Disk Access is one hell of a good way to get access to data to exfiltrate. There likely wouldn’t even be suspicion if it also asked for Internet access: if it supports connecting to network shares, you wouldn’t think twice about it having that permission.
Simple File Manager Pro is FOSS. Just use this if you have to get a third party file manager.
https://f-droid.org/packages/com.simplemobiletools.filemanager.pro/
I assume that one factor is that they necessarily have to have access to your files.
It’s always apps that you definitely don’t need in the first place. File managers, battery savers, RAM managers, etc. The users who would think to install those kinds of apps, when their phone already likely already has built-in (and probably better) support for that functionality, are the same users malware developers look to target. They’re usually not tech savvy, and less likely to realize that their data’s been compromised, and even less likely to determine who compromised it.
I have paid for Xplore because built in file managers ALWAYS absolutely lacking in usability, features and are generally much worse products, or are filled with garbage (or even worse, in the case of MIUI its a privacy nightmare). Xplore is the only file manager that has made me not use a ES File Explorer apk made for Android 4 from 2014 that I still used into the start of this year 2023 (from before the Cheetah Mobile acquisition, that turned the app updates into malware). This ancient version of ES File Explorer STILL works almost perfectly in Android 12.
If I have “File Manager +” does that mean I’m extra spied on??
File Manager + Spyware
No no no it’s just China doing you a solid and backing up your sensitive information just in case you lose your phone. It uses Blockchain technology where if you ever need it back they just block you.
My experience with Aliexpress
use MiXplorer or ZArchiver, they are good.
MiXplorer (and it’s addons): Google Drive / Beta (mixplorer.com/beta) (or, if you want to support the developer; Google Play Store (includes addons))
ZArchiver: Google Play Storeedit: corrected the layout.