Chinese Firm Installed Back Door on Thousands of Smartphones; Says It Was a Mistake

Advertisement
By Gadgets 360 Staff | Updated: 16 November 2016 14:38 IST
Highlights
  • The personal data was collected via a back door software made by AdUps
  • The software was installed on all Blu R1 HD phones
  • AdUps also manages software updates for Huawei and ZTE

A security firm claims it has found mobile phone firmware on smartphones being sold in the US that transmitted personally identifiable information (PII) to servers in China via a back door. Several such reports have emerged over the years, and conspiracy theories usually point to the Chinese government being the ultimate beneficiary of the data. The software company in question - Shanghai Adups Technology - however claims that this is not the case, and that the software meant for a Chinese manufacturer was mistakenly included in US devices.

Security firm Kryptowire says it has found several models of Android smartphones being sold through US retailers like Amazon and Best Buy that contained the contentious firmware. These models included the Blu R1 HD, which gained popularity due to its very low price of $50 (subsidised by ads) and was sold exclusively through Amazon. The common denominator between the smartphones was the presence of commercial Firmware Over The Air (FOTA) made by Adups, a back door found to be collecting and transmitting sensitive data to its servers in China, apart from having the ability to executive remote commands with escalated privileges and the ability to reprogram devices.

Information that was collected and transmitted included the full-body of text messages, contact lists, call history with full telephone numbers, unique device identifiers including the International Mobile Subscriber Identity (IMSI) and the International Mobile Equipment Identity (IMEI) from a user's phone. In some versions of the software, it even included fine-grained location. This transfer was happening without any initiation to the customer. Notably, even anti-virus and other security software on phones were not able to discover the threat, as they normally disregard software already bundled on the phone by the smartphone manufacturer.

Advertisement

As mentioned, the software was spotted in the Blu R1 HD smartphone, and Kryptowire informed Google, Amazon, Blu, and Adups of the issue. Both Blu and Amazon were fast to react to the issue. Blu has issued a software update that will apparently fix the 'potential security issue', which is said to affect 120,000 of its devices. Furthermore, the Blu R1 HD, which was being sold on Amazon exclusively, is no longer listed on the website as well. Amazon is also informing users that their smartphones will receive an update.

Advertisement

AdUps itself has defended itself and its intentions, saying the data is not linked to the Chinese government. According to a document provided by Adups to Blu to explain the issue, and obtained by the New York Times, the company said the version of the software that collected and transmitted information was meant for certain Chinese manufacturer that wanted to monitor user behaviour. It was not meant for smartphones in the US. "This is a private company that made a mistake," the company's lawyer told NYT.

Adups claims that its software is present in over than 700 million devices in 200 countries, including smartphones made by Huawei and ZTE. Its service portfolio includes smartphones, tablets, and automobile entertainment systems.

Advertisement

While both Adups and Blu have acknowledged the issue, there is the possibility such a back door continues to exist in other smartphones using versions of the FOTA software. If you'd like to check if your smartphone is affected, look for these apk files on your smartphone - com.adups.fota and com.adups.fota.sysoper.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Apple's M5-Powered MacBook Pro 14-inch, iPad Pro Now Available in India
  2. OnePlus 15 Price Leaked; Could Be Cheaper Than its Predecessor at Launch
  3. JioSaavn Announces 'Limited-Time' Annual Plan: Price, Benefits
  4. Amazon Could Bring Robots to Replace Half a Million Human Jobs
  5. Oppo Reno 15 Pro Max Could Launch Soon With These Camera, Display Features
  6. Nubia Z80 Ultra Launched With 7,200mAh Battery, Snapdragon 8 Elite Gen 5
  7. Redmi K90, Redmi K90 Pro Max Launch Today: All You Need to Know
  1. Redmi K90, Redmi K90 Pro Max Launching Today: Know Price, Features and Specifications
  2. Astrophotographer Captures Stunning “Raging Baboon Nebula” in Deep Space
  3. Cambridge Team Uncovers Unexpected Quantum Behaviour in Non-Metal Organic Molecule
  4. New Fossil Teeth Evidence Suggests Herbivorous Dinosaurs Preferred Nutrient-Rich, Textured Plants
  5. Ek Deewane Ki Deewaniyat OTT Release Reportedly Revealed Online: When and Where to Watch?
  6. Final Destination: Bloodlines Now Available for Streaming on JioHotstar
  7. Vash Level 2 Now Streaming Online: Know Where to Watch This Janki Bodiwala Starrer Horror Movie
  8. Apple Working On iOS Framework That Simplifies One-Time App Data Transfers From iPhone to Android
  9. Tether User Base Crosses 500 Million Mark as Stablecoin Supply Nears $182 Billion
  10. Google's Gemini AI Assistant Could Soon Add a Mic Lock Option for Longer Voice Commands: Report
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.