Some Budget Phones in the US Still Sending Personal Data Back to China, Says Kryptowire

Advertisement
By Sanket Vijayasarathy | Updated: 27 July 2017 18:21 IST
Highlights
  • Kryptowire last year found cheap phones in the US sending data to China
  • Security firm says Adups’ spyware still active
  • It also found vulnerabilities in a MediaTek chipset

Despite last year's revelation where some smartphones being sold in the US were found laced with a software that could send private data to servers in China, it seems as though nothing was learnt from the mistake. According to a recent study, it seems the group behind last year's privacy-invading software is still active and continues to send personal data to China, only more discreetly than before.

Shanghai Adups Technology, a firm based in China, was caught last year in November for having added a backdoor to the firmware of cheap smartphones like the Blu R1 HD sold in the US. The firmware was found to be sending personally identifiable information (PII) to servers in China via a back door. At the time, the Shanghai-based firm said it had mistakenly used code for China-based software in these firmware.

Researchers at Kryptowire discovered this back then and at the Black Hat security conference in Las Vegas on Wednesday, the security firm once again revealed that Adups' software is still sending data from the Blu Grand M smartphone to the company's server in china, CNET reports. This was discovered by Ryan Johnson, a research engineer and co-founder at Kryptowire in May, almost six months after Shanghai Adups Technology confessed it was a mistake.

Advertisement

"They replaced them with nicer versions," Johnson said. "I have captured the network traffic of them using the command and control channel when they did it." Following this reveal, a Adups spokeswoman said the company had resolved the issues last year and that the firmware "are not existing anymore."

Advertisement

Apart from the Blu smartphone, Johnson also found the firmware on the Cubot X16S. These cheap Chinese phones sent data that included a list of apps installed, the apps used, IMEI numbers, call logs, browser history, and more to China. In fact, Adups claimed last year that its software is present in over than 700 million devices in 200 countries, mostly targeting low cost phones.

Cases of spyware, malware, and ransomware have been growing in recent times. The Black Hat security conference comes following recent cyber-attacks like WannaCry and Petya ransomware. There have also been reports recently of Android-based malware like SpyDealer and LeakerLocker. All of these cases have raised an alarming concern over the safety of personal information over the digital space.

Advertisement

These cases also point out some serious vulnerabilities with the Android platform. Kryptowire said last year that it examined 20 pieces of firmware from low-end Android devices, all of which seemed to have vulnerabilities that could allow spyware apps. Notably, all of these devices also had a particular MediaTek chipset. The chipset comes with a pre-installed app called MTKLogger, which allowed for data surveillance of browser history and GPS, to name a few. While MediaTek claims to have resolved the issue, the security firm found the vulnerability still present till last week on the Blu Advance 5.0.

As of now, it's unclear what happens to the data when it reaches China. Adups has said that it would delete the data but that doesn't answer as to how has been used and to what capacity.

Advertisement

Update: Blu has provided a statement regarding the reports:

BLU Products responds to inaccuracies reported by several news outlets making clear that there is absolutely no spyware or malware or secret software on BLU devices, these are inaccurate and false reports. BLU is reaching out to several reporters to correct their articles and issue apologies, which BLU has started receiving.

The original report by Kryptowire issued on November 2016 regarding the Adups OTA application, stated a small fraction of BLU phones had a version of the application which was collecting phonebook contacts and text messages. Since BLU was unaware of this collection, they hadn't notified customers, thus it was deemed as a potential privacy issue. BLU moved quickly and resolved the problem by having Adups turn off this functionality.

Furthermore, BLU decided to switch the Adups OTA application on future devices with Google's GOTA. Even though it is BLU's policy to only use GOTA moving forward, some older devices still use ADUPS OTA.

Using ADUPS OTA is not an issue here. ADUPS is a well-known application used by several device manufacturers around the world. The issue is exactly what kind of data is actually being collected by this ADUPS application, and whether it presents a security or privacy risk.

BLU hired Kryptowire in November of 2016 since their first report to regularly monitor the ADUPS application in their devices, and they have since been doing that. The data that is currently being collected is standard for OTA functionally and basic informational reporting. This is in line with every other smartphone device manufacturer in the world. There is nothing out of the ordinary that is being collected, and certainly does not affect any user's privacy or security. In addition, as per Tom Karygiannis, VP of Kryptowire, the data collection is in line with BLU's Privacy Policy, and does not constitute any wrong doing by BLU.

Regarding that some information may be stored in China servers, their privacy policy clearly states that some of the data collected can be stored in servers outside the US, there is absolutely nothing wrong with having a server in China. BLU management takes issue with the statement that any server in China is prone to risk while several other multibillion dollar companies and other mobile manufactures such as Huawei and ZTE use them.

BLU has several policies in place which takes customer privacy and security very seriously, and confirms that there has been no breach or issue of any kind with any of its devices.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement
Popular Mobile Brands
  1. Valve Unveils Steam Machine PC/ Console Hybrid: Everything You Need to Know
  2. ChatGPT With GPT-5.1 AI Model Is Warmer and Friendlier
  3. Oppo Reno 15 Pro Features Leaked; Could Include a Reno 15C Model
  4. iPhone 18 Pro Max Could Be the Heaviest iPhone to Date, Tipster Suggests
  5. Aadhaar vs mAadhaar Key Differences Explained
  6. A Future OnePlus Smartphone Could Debut With a 240Hz Display
  7. Vivo X300 Series Teased on Amazon Ahead of Launch in India
  8. Honor 500 Series Will be Launched in These Shades, Storage Variants
  9. Vivo X300 Series Teased to Launch Soon in India
  10. iQOO Confirms November Service Day With Complimentary Device Maintenance
  1. Google Reintroduces Cameyo to Let Enterprises Run Windows Apps on Chrome Browser
  2. Google Maps’ New Power Saving Mode is Exclusive to the Pixel 10 Series
  3. Samsung Galaxy Z Fold 8 Could be Thinner, Lighter Than its Predecessor to Increase Sales: Report
  4. Vivo X300 Series With Zeiss-Backed Cameras Teased on Amazon Ahead of India Launch: Expected Specifications
  5. Valve Enters Console Market Again With Steam Machine, a New PC/ Console Hybrid That Launches 2026
  6. Samsung Movingstyle Touchscreen Display Launched With Up to Three Hours Battery Life; Movingstyle M7 Tags Along
  7. Honor 500 Pro, Honor 500 Listings Reveal Storage Variants, Colour Options
  8. Valve Steam Frame VR Gaming Headset Announced With Eye-Tracking Cameras: Availability, Specifications
  9. OpenAI Upgrades ChatGPT With GPT-5.1 AI Models, Brings Friendlier Conversations and Less Jargon
  10. iQOO Announces Service Day Benefits Including Free Back Case and Protective Film
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.