Android phones leaking private data to China
Kryptowire has released a report describing how certain Android devices collected personal data and transmitted it to third-party servers without consent.
The backdoors were found in a firmware that ships with devices such as the BLU R1 HD, which was available through major US retailers.
“These devices transmitted user and device information, including the full body of text messages, contact lists, call history with full telephone numbers, and unique device identifiers,” said Kryptowire.
“The firmware could target specific users and text messages matching remotely-defined keywords. The firmware also collected and transmitted information about the use of applications [and] bypassed the Android permission model.”
Data transmission occurred every 72 hours for text messages and call log information, and every 24 hours for other information. The data was transmitted to:
- bigdata.adups.com (primary)
- bigdata.adsunflower.com
- bigdata.adfuture.cn
- bigdata.advmob.cn
All of these domains resolved to the IP address 221.228.214.101, which belongs to the Adups company, said Kryptowire.
Remote code execution
Kryptowire also found that the firmware executed remote commands with escalated privileges and was able to remotely reprogram the devices.
“Bigdata.adups.com was the domain that received the majority of the information, whereas rebootv5.adsunflower.com, with IP address 61.160.47.15, was the domain that can issue remote commands.”
Kryptowire said it has sent its findings about affected devices to Google, Amazon, Adups, and BLU Products.