Indian Military did a full, deep analysis of a wide range of Android products and found all of the following were backdoored and functioning as malware. 360 is on that list as backdoored/malware.
Weibo, WeChat, SHAREit, Truecaller, UC News, UC Browser, BeautyPlus, NewsDog, VivaVideo- QU Video Inc, Parallel Space, APUS Browser, Perfect Corp, Virus Cleaner (Hi Security Lab), CM Browser, Mi Community, DU recorder, Vault-Hide, YouCam Makeup, Mi Store, CacheClear DU apps studio, DU Battery Saver, DU Cleaner, DU Privacy, 360 Security, DU Browser, Clean Master – Cheetah Mobile, Baidu Translate, Baidu Map, Wonder Camera, ES File Explorer, Photo Wonder, QQ International, QQ Music, QQ Mail, QQ Player, QQ NewsFeed, WeSync, QQ Security Centre, SelfieCity, Mail Master, Mi Video call-Xiaomi, and QQ Launcher.
Defence Ministry to Indian armed forces: Uninstall these Chinese apps immediately
My own experience. I needed to use WeChat a few months ago because I had some dealings with some Chinese Multi-National Corps. They ALL use WeChat over there, it's like the only chat they are willing to use. Anyway, so I signed up to communicate with them. At the same time I pointed my SIEM to the device with WeChat, and sure enough, it was scooping up ALL of the data on the phone.. I mean it was literally downloading the full contents of the device directly to Beijing.
I had planned for this, and used a dummy Android Device on it's own VLAN - they're cheap enough to buy outright these days anyway and I don't want that Chinese garbage on my personal devices.. Anyway, I spilled the beans to every contact I had on WeChat which by then was about 60-70 people and uninstalled the app and tossed the device into a donation pile. At least Chinese Intelligence are predictable, to a fault, and essentially the easiest to subvert.
By the way, I'd stop worrying TOO MUCH about Russia, and start worrying about China. China has a massive effort to implant hundreds of thousands of their citizens as spies and agents of subversion in the USA. They've installed 'fake' families of intelligence agents all across the USA. They've married Chinese women to US Citizens for the sole purpose of spying. They've got an impressive and vast network in this country to steal IP and offer direct HUMINT to the Chinese Govt. Trust nothing from them. NOTHING!
I've never run into a single cheap IoT device from China (and dutifully sold on Amazon) that wasn't backdoored. This runs deep, don't think it stops at HIKVision, it's been embedded in all of it.