How to keep yourself safe from Chinese spyware on budget Android phones

Mobile Malware
The last thing you want your smartphone doing is sending your text messages, contacts, and location history to a server in China. But according to mobile security firm Kryptowire, a particularly nasty brand of Android software did just that, transmitting text, data, call, location, and app data to a Chinese server every 72 hours.

Researchers began to raise red flags last fall, when it was discovered the the data mining tool in question — called Adups — had been living inside hundreds of millions of devices produced by more than 40 manufacturers. Florida-based Blu Products was one of the affected parties, and assured at the time that the problem had been identified and every trace of the spyware had been removed from its phones.

Now, nearly 10 months since the initial report, Amazon has suspended the sale of several Blu devices from its Prime Exclusive lineup over re-emerging security concerns. Kryptowire appeared at July’s Black Hat security conference in Las Vegas to say the spyware still existed on some of Blu’s current phones, which led to Amazon’s decision the following week.

The code, which comes preinstalled on certain Android devices, sends the data surreptitiously. “Even if you wanted to, you wouldn’t have known about it,” Kryptowire vice president of product Tom Karygiannis told The New York Times last year.

How to know if you’ve been affected, and what to do

An investigation conducted by mobile security researchers at Trustlook in December found that as many as 43 manufacturers, including brands like Lenovo and Gionee, contained similar spyware. According to the firm’s report, the software collects serial numbers, software version numbers, operator information, and texting and call data from infected phones; the company found traces in All Win Tech smartphones in Taiwan, Archos devices in France, DEXP phones in Russia, and Prestigio hardware in the Czech Republic.

Here’s a list of manufacturers with affected devices:

  • Aaron Electronics
  • Aeon Mobile
  • All Win Tech
  • Amoi Technology
  • Archos
  • AUX
  • Bird
  • BLU
  • Cellon
  • Coship Mobile
  • Cubot Mobile
  • DEWAV Communication
  • DEXP Digital Experience
  • Eastaeon Technology
  • Electronic Technology
  • Gionee
  • GOSO
  • Hisense
  • Hongyu
  • Huaqin
  • Huiye
  • Inventec Corporation
  • Konka Group
  • Lenovo
  • Logicom
  • Longcheer
  • Malata Mobile
  • Mediatek Helio
  • Prestigio
  • Ragentek
  • RDA Micro
  • Reallytek
  • RUIO
  • Sanmu
  • Sprocomm
  • Tinno
  • Uniscope
  • VSUN
  • Water World Technology
  • Wind Communication
  • WingTech
  • Yifang Digital
  • Zhuhai Quanzhi
  • ZTE

At this time, there’s no sure way to know if Adups is sending your personal information. However, some phone makers use Adups, rather than Google, to push over-the-air system updates, which is a clear indicator that the software is at least present on your device. The offending file, com.adups.fota, typically appears as “System Update” or “Wireless Update” within your phone’s list of apps in the settings menu. These are system apps, so they cannot be uninstalled — though they can be disabled. At the moment, disabling is the only known way to prevent Adups from running without rooting or installing custom firmware, which are riskier measures that will void your manufacturer’s warranty.

In November, Trustlook updated its Antivirus & Mobile Security app on the Google Play Store to check for Adups’ presence. The firm says it has updated the app continually to search for new Adups system programs linked to data collection as they’ve been discovered.

Specific phones known to include Adups more recently are the Blu Grand M and Cubot X16S. In addition to discovering the spyware in those two devices, Kryptowire’s Ryan Johnson told CNET he hasn’t found it in any handsets priced over $300. Additionally, only MediaTek chipsets have thus far been linked to the scheme. It would seem Adups is targeting low-cost hardware, predominantly from manufacturers that don’t sell phones in the U.S.

For those reasons, at this time we recommend staying away from budget smartphones powered by MediaTek processors built by any of the companies listed above.

Where it came from

The spyware is the product of Chinese firm Shanghai Adups Technology Company, and it targeted more than 700 million low-end Android devices. Adups said it worked with phone makers like Huawei and ZTE to develop the tool to monitor user behavior — ostensibly to identify junk text messages and calls.

But the software was never intended for American phones. An apparent bug caused more than 120,000 phones sold by Blu to become infected with the Adups tool. “Blu Products has identified and has quickly removed a recent security issue caused by a third-party application which has been collecting unauthorized personal data in the form of text messages, call logs, and contacts from customers using a limited number of Blu mobile devices,” a spokesperson for the company said in November.

In Blu’s case, the malware appears to have originated from a seemingly innocuous support app. Adups provides a utility that manufacturers use to perform remote firmware updates. “It was obviously something that we were not aware of,” Samuel Ohev-Zion, Blu’s chief executive, told The New York Times.

Blu claims Adups disregarded its request not to mine users’ data. “We have an email history with Adups saying we did not want that functionality on our devices, and they violated our request,” Ohev-Zion told PCMag. The company retained the services of Kryptowire to “keep tabs” on its software for a year, and partnered with chipmaker MediaTek to ensure its phones receive up-to-date, “clean” versions of Android.

Adups said that it had destroyed all information collected from Blu phones. “Today there is no Blu device that is collecting that information,” Ohev-Zion said last year. Now, Kryptowire is claiming that statement is false, while Blu maintains the situation has been dealt with. Meanwhile, an Adups spokeswoman told CNET all issues were resolved in 2016 and no longer exist.

It is not the first time Adups has raised the ire of an American tech company. Google, Android’s primary developer, instructed the Chinese firm to remove its surveillance tools from phones that shipped with the Google Play Store.

It is unclear precisely which devices are vulnerable. So far, the company has declined to publish a list of affected phones and said that there was not an easy way for customers to determine whether or not their devices contained Adups’ monitoring software. A representative for the company told The New York Times that it was incumbent on phone manufacturers, not Adups, to inform users that their personal information was being collected.

ZTE USA released a statement to press in November. “We confirm that no ZTE devices in the U.S. have ever had the Adups software cited in recent news reports installed on them, and will not,” it said. “ZTE always makes security and privacy a top priority for our customers. We will continue to ensure customer privacy and information remain protected.”

Update: Added newest information regarding Blu’s Amazon Prime Exclusive phones, in addition to an updated list of affected manufacturers and recommendations on how to spot the spyware and avoid buying a device that may contain it.

Computing

Smishing sounds funny, but it’s a serious threat to your phone’s security

We all know phishing is a huge security problem, but most people still believe it’s a problem limited to email. According to new reports, however, phishing scams are attempting to exploit your trust in text messages.
Mobile

Samsung Galaxy S9, S9 Plus, Note 9 set to receive Android 9.0 Pie in January

Android 9.0 Pie has been released. But is your phone getting Android 9.0 Pie, and if so, when? We've done the hard work and asked every device manufacturer to see when their devices would be getting the update.
Computing

Sending SMS messages from your PC is easier than you might think

Texting is a fact of life, but what to do when you're in the middle of something on your laptop or just don't have your phone handy? Here's how to send a text message from a computer, whether you prefer to use an email client or Windows 10.
Mobile

Common Huawei Mate 20 Pro problems, and how to fix them

The beautiful Huawei Mate 20 Pro is in your hand, and there is a problem that's bothering you with it. We've gathered together frequently reported problems with the phone here, and provide potential solutions too.
Deals

Bigger than Black Friday: Don’t miss the best Single’s Day deals

Thanks to AliExpress, Single's Day – the world's largest retail day – is no longer a foreign affair. If you're ready to do some early holiday shopping or want to score some discounts ahead of Black Friday, we've rounded up some of the…
Emerging Tech

Awesome Tech You Can’t Buy Yet: 1-handed drone control, a pot that stirs itself

Check out our roundup of the best new crowdfunding projects and product announcements that hit the web this week. You may not be able to buy this stuff yet, but it sure is fun to gawk!
Product Review

It's so fast it has a clip-on fan. But the Asus ROG phone isn't just for gamers

Is a gaming smartphone only something a mobile gamer should consider buying? In the case of the Asus ROG Phone, the good news is the device is so capable, and a genuinely impressive all-rounder, that everyone should take a closer look…
Mobile

Our favorite ebook reader is not a Kindle. Here are all the best options

If you're a bookworm, an ebook reader can be an important part of your life, one that allows you to read your books whenever and wherever you like. But which should you get? Here are five of the best ebook readers available.
Mobile

Samsung made a $2,700 flip phone with the brains of a smartphone

The Samsung W2019 is a high-end flip phone that comes with flagship specifications such as 6GB of RAM and Qualcomm's Snapdragon 845. The device features a pair of S-AMOLED displays, a dual rear camera setup, and an eye-popping price tag.
Mobile

Google, Samsung, OnePlus, and Huawei face off in an Android battle royale

The good news is that there are some great options in the Android smartphone market right now. The bad news is that too much choice makes it tough to decide. We compare the Pixel 3 XL, the Galaxy Note 9, the OnePlus 6T, and the Mate 20 Pro.
Mobile

Apple to boost its Amazon presence with listings for iPhones, iPads, and more

Apple is about to start offering more of its kit on Amazon. The tech giant currently only has very limited listings on the shopping site, but the deal will see the arrival of the latest iPhones, iPads, MacBooks, and more.
Mobile

Get your gaming on the go with this list of the 25 best Android games

The Google Play Store is loaded with both terrific and terrible gaming titles. We vetted the store to bring you some of the best Android games available, whether you're into puzzles, shooters, racing games, or something else.
Mobile

Google’s Gboard now uses A.I. to recommend GIFs based on your conversation

Google is bringing a new feature to Gboard that should make it better for those that regularly use GIFs and stickers. The feature essentially uses A.I. to recommend GIFs and stickers based on your conversation.
Computing

Cloudflare’s privacy-enhancing 1.1.1.1 DNS service comes to iOS and Android

Cloudflare's 1.1.1.1 DNS resolver service has been ported to mobile devices, and now anyone with an Android or iOS device can download it for free to take advantage of its speed and privacy-boosting features.