Some Budget Phones in the US Still Sending Personal Data Back to China, Says Kryptowire

Advertisement
By Sanket Vijayasarathy | Updated: 27 July 2017 18:21 IST
Highlights
  • Kryptowire last year found cheap phones in the US sending data to China
  • Security firm says Adups’ spyware still active
  • It also found vulnerabilities in a MediaTek chipset

Despite last year's revelation where some smartphones being sold in the US were found laced with a software that could send private data to servers in China, it seems as though nothing was learnt from the mistake. According to a recent study, it seems the group behind last year's privacy-invading software is still active and continues to send personal data to China, only more discreetly than before.

Shanghai Adups Technology, a firm based in China, was caught last year in November for having added a backdoor to the firmware of cheap smartphones like the Blu R1 HD sold in the US. The firmware was found to be sending personally identifiable information (PII) to servers in China via a back door. At the time, the Shanghai-based firm said it had mistakenly used code for China-based software in these firmware.

Advertisement

Researchers at Kryptowire discovered this back then and at the Black Hat security conference in Las Vegas on Wednesday, the security firm once again revealed that Adups' software is still sending data from the Blu Grand M smartphone to the company's server in china, CNET reports. This was discovered by Ryan Johnson, a research engineer and co-founder at Kryptowire in May, almost six months after Shanghai Adups Technology confessed it was a mistake.

"They replaced them with nicer versions," Johnson said. "I have captured the network traffic of them using the command and control channel when they did it." Following this reveal, a Adups spokeswoman said the company had resolved the issues last year and that the firmware "are not existing anymore."

Advertisement

Apart from the Blu smartphone, Johnson also found the firmware on the Cubot X16S. These cheap Chinese phones sent data that included a list of apps installed, the apps used, IMEI numbers, call logs, browser history, and more to China. In fact, Adups claimed last year that its software is present in over than 700 million devices in 200 countries, mostly targeting low cost phones.

Cases of spyware, malware, and ransomware have been growing in recent times. The Black Hat security conference comes following recent cyber-attacks like WannaCry and Petya ransomware. There have also been reports recently of Android-based malware like SpyDealer and LeakerLocker. All of these cases have raised an alarming concern over the safety of personal information over the digital space.

Advertisement

These cases also point out some serious vulnerabilities with the Android platform. Kryptowire said last year that it examined 20 pieces of firmware from low-end Android devices, all of which seemed to have vulnerabilities that could allow spyware apps. Notably, all of these devices also had a particular MediaTek chipset. The chipset comes with a pre-installed app called MTKLogger, which allowed for data surveillance of browser history and GPS, to name a few. While MediaTek claims to have resolved the issue, the security firm found the vulnerability still present till last week on the Blu Advance 5.0.

As of now, it's unclear what happens to the data when it reaches China. Adups has said that it would delete the data but that doesn't answer as to how has been used and to what capacity.

Advertisement

Update: Blu has provided a statement regarding the reports:

BLU Products responds to inaccuracies reported by several news outlets making clear that there is absolutely no spyware or malware or secret software on BLU devices, these are inaccurate and false reports. BLU is reaching out to several reporters to correct their articles and issue apologies, which BLU has started receiving.

The original report by Kryptowire issued on November 2016 regarding the Adups OTA application, stated a small fraction of BLU phones had a version of the application which was collecting phonebook contacts and text messages. Since BLU was unaware of this collection, they hadn't notified customers, thus it was deemed as a potential privacy issue. BLU moved quickly and resolved the problem by having Adups turn off this functionality.

Furthermore, BLU decided to switch the Adups OTA application on future devices with Google's GOTA. Even though it is BLU's policy to only use GOTA moving forward, some older devices still use ADUPS OTA.

Using ADUPS OTA is not an issue here. ADUPS is a well-known application used by several device manufacturers around the world. The issue is exactly what kind of data is actually being collected by this ADUPS application, and whether it presents a security or privacy risk.

BLU hired Kryptowire in November of 2016 since their first report to regularly monitor the ADUPS application in their devices, and they have since been doing that. The data that is currently being collected is standard for OTA functionally and basic informational reporting. This is in line with every other smartphone device manufacturer in the world. There is nothing out of the ordinary that is being collected, and certainly does not affect any user's privacy or security. In addition, as per Tom Karygiannis, VP of Kryptowire, the data collection is in line with BLU's Privacy Policy, and does not constitute any wrong doing by BLU.

Regarding that some information may be stored in China servers, their privacy policy clearly states that some of the data collected can be stored in servers outside the US, there is absolutely nothing wrong with having a server in China. BLU management takes issue with the statement that any server in China is prone to risk while several other multibillion dollar companies and other mobile manufactures such as Huawei and ZTE use them.

BLU has several policies in place which takes customer privacy and security very seriously, and confirms that there has been no breach or issue of any kind with any of its devices.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement
Popular Mobile Brands
  1. OTT Releases of the Week (Mar 30th - Apr 5th): From Aamir Khan's Sitaare Zameen Par
  2. Honor X80i With MediaTek Dimensity 6500 Elite Chip Launched: See Price
  3. Google AI Pro Subscribers Now Get 5TB of Storage Across Drive, Photos
  4. Oppo F33, Oppo F31 Pro Launch Timeline, Price Range Leaked
  5. Vivo V70 FE Launched in India With 7,000mAh Battery, 200-Megapixel Main Camera
  6. OnePlus Nord 6 First Impressions
  7. Infinix Note 60 Pro With Active Matrix Panel to Arrive in India on This Date
  1. Apple's iPhone 18 Pro Models May Not Arrive in Classic Black Finish Just Like iPhone 17 Pro, Tipster Claims
  2. Oppo F33, Oppo F31 Pro Launch Timeline, Price Range Revealed in New Leak
  3. Capcom Adds Original Versions of Resident Evil 1, 2 and Resident Evil 3 Nemesis to Steam
  4. Google's Next Fitbit Wearable Could Launch Without a Display; Said to Require Paid Subscription
  5. CFTC-FTX Settlement: Former FTX Executive Nishad Singh to Pay $3.7 Million, Faces Trading Ban
  6. Slack Upgrades Slackbot With New AI Features to Turn It Into an Enterprise Agent
  7. Australia Mandates Financial Services Licences for Crypto Exchanges Under New Bill
  8. DoT Reportedly Extends SIM Binding Mandate Till the End of 2026
  9. Government Migrates 16.68 Lakh Official Email Accounts to Zoho Cloud, Spends Rs. 180 Crore
  10. Infinix Note 60 Pro India Launch Date Revealed; Company Teases Active Matrix Feature on Rear Panel
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.