Chinese Firm Installed Back Door on Thousands of Smartphones; Says It Was a Mistake

Advertisement
By Gadgets 360 Staff | Updated: 16 November 2016 14:38 IST
Highlights
  • The personal data was collected via a back door software made by AdUps
  • The software was installed on all Blu R1 HD phones
  • AdUps also manages software updates for Huawei and ZTE

A security firm claims it has found mobile phone firmware on smartphones being sold in the US that transmitted personally identifiable information (PII) to servers in China via a back door. Several such reports have emerged over the years, and conspiracy theories usually point to the Chinese government being the ultimate beneficiary of the data. The software company in question - Shanghai Adups Technology - however claims that this is not the case, and that the software meant for a Chinese manufacturer was mistakenly included in US devices.

Security firm Kryptowire says it has found several models of Android smartphones being sold through US retailers like Amazon and Best Buy that contained the contentious firmware. These models included the Blu R1 HD, which gained popularity due to its very low price of $50 (subsidised by ads) and was sold exclusively through Amazon. The common denominator between the smartphones was the presence of commercial Firmware Over The Air (FOTA) made by Adups, a back door found to be collecting and transmitting sensitive data to its servers in China, apart from having the ability to executive remote commands with escalated privileges and the ability to reprogram devices.

Advertisement

Information that was collected and transmitted included the full-body of text messages, contact lists, call history with full telephone numbers, unique device identifiers including the International Mobile Subscriber Identity (IMSI) and the International Mobile Equipment Identity (IMEI) from a user's phone. In some versions of the software, it even included fine-grained location. This transfer was happening without any initiation to the customer. Notably, even anti-virus and other security software on phones were not able to discover the threat, as they normally disregard software already bundled on the phone by the smartphone manufacturer.

As mentioned, the software was spotted in the Blu R1 HD smartphone, and Kryptowire informed Google, Amazon, Blu, and Adups of the issue. Both Blu and Amazon were fast to react to the issue. Blu has issued a software update that will apparently fix the 'potential security issue', which is said to affect 120,000 of its devices. Furthermore, the Blu R1 HD, which was being sold on Amazon exclusively, is no longer listed on the website as well. Amazon is also informing users that their smartphones will receive an update.

Advertisement

AdUps itself has defended itself and its intentions, saying the data is not linked to the Chinese government. According to a document provided by Adups to Blu to explain the issue, and obtained by the New York Times, the company said the version of the software that collected and transmitted information was meant for certain Chinese manufacturer that wanted to monitor user behaviour. It was not meant for smartphones in the US. "This is a private company that made a mistake," the company's lawyer told NYT.

Adups claims that its software is present in over than 700 million devices in 200 countries, including smartphones made by Huawei and ZTE. Its service portfolio includes smartphones, tablets, and automobile entertainment systems.

Advertisement

While both Adups and Blu have acknowledged the issue, there is the possibility such a back door continues to exist in other smartphones using versions of the FOTA software. If you'd like to check if your smartphone is affected, look for these apk files on your smartphone - com.adups.fota and com.adups.fota.sysoper.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Jailer 2 OTT Release Date Reportedly Revealed Online: When and Where to Watch it Online?
  2. NASA Shuts Down Voyager 1 Instrument to Extend Mission Life in Deep Space
  3. These Vivo Smartphones Will Cost More in India Due to the Latest Price Hike
  1. NASA Shuts Down Voyager 1 Instrument to Extend Mission Life in Deep Space
  2. Oppo Enco Clip 2 With Open-Ear Design, Up to 40 Hours Total Battery Life Launched Alongside Oppo Watch X3 Mini
  3. Vivo Y6t Launched With 6,500mAh Battery, Snapdragon 4 Gen 2 SoC: Price, Specifications
  4. OCBC Partners Lion Global Investors and DigiFT to Launch Tokenised Gold Fund With GOLDX Token
  5. Oppo Pad 5 Pro Launched With 13,380mAh Battery, Snapdragon 8 Elite Gen 5 SoC Alongside Oppo Pad Mini: Price, Features
  6. Redmi K90 Max Launched With Dimensity 9500 SoC, 8,550mAh Battery and Active Cooling Fan: Price, Specifications
  7. Oppo Find X9 Ultra Launched With Snapdragon 8 Elite Gen 5 SoC, 200-Megapixel Periscope Camera: Price, Specifications
  8. Oppo Find X9s Pro Launched With 200-Megapixel Cameras, 7,025mAh Battery: Price, Specifications
  9. OnePlus Ace 6 Ultra Geekbench Listing Reveals MediaTek Dimensity 9500 Chip, 16GB RAM
  10. Motorola Edge 70 Pro+ Leaked Renders Hint at Design, Five Colour Options
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.