Security16.11.2016

Android phones leaking private data to China

BLU R1 HD

Kryptowire has released a report describing how certain Android devices collected personal data and transmitted it to third-party servers without consent.

The backdoors were found in a firmware that ships with devices such as the BLU R1 HD, which was available through major US retailers.

“These devices transmitted user and device information, including the full body of text messages, contact lists, call history with full telephone numbers, and unique device identifiers,” said Kryptowire.

“The firmware could target specific users and text messages matching remotely-defined keywords. The firmware also collected and transmitted information about the use of applications [and] bypassed the Android permission model.”

Data transmission occurred every 72 hours for text messages and call log information, and every 24 hours for other information. The data was transmitted to:

  • bigdata.adups.com (primary)
  • bigdata.adsunflower.com
  • bigdata.adfuture.cn
  • bigdata.advmob.cn

All of these domains resolved to the IP address 221.228.214.101, which belongs to the Adups company, said Kryptowire.

Remote code execution

Kryptowire also found that the firmware executed remote commands with escalated privileges and was able to remotely reprogram the devices.

“Bigdata.adups.com was the domain that received the majority of the information, whereas rebootv5.adsunflower.com, with IP address 61.160.47.15, was the domain that can issue remote commands.”

Kryptowire said it has sent its findings about affected devices to Google, Amazon, Adups, and BLU Products.

Now read: Android security in South Africa is a disaster waiting to happen

Show comments

Latest news

More news

Trending news

Poll

Which operating system do you have installed on your personal computer?

View Results

Loading ... Loading ...
Sign up to the MyBroadband newsletter