Adups Technology
| Basic information | |
|---|---|
| Founded | 2012 |
| Legal Structure | |
| Industry | Firmware over-the-air updates,Mobile software |
| Also known as | Shanghai Adups Technology Co., Ltd.,ADUPS |
| Official website | |
Shanghai Adups Technology Co., Ltd., a China-based firmware-over-the-air update vendor, wrote preinstalled software that transmitted budget Android phone users' text messages, contacts, call logs & real-time location to servers in Shanghai without the owners' consent.[1][2] The security firm Kryptowire reported the collection in November 2016, most visibly on the BLU R1 HD, a $50 phone sold on Amazon, and the two Adups system apps that performed the transfers could not be disabled by the owner.[1][3]
BLU Products said about 120,000 of its phones carried the software, while Adups claimed its firmware ran on more than 700 million active devices worldwide.[3][1] The Federal Trade Commission found that Adups obtained full administrative access to the phones it shipped software to, and brought a deceptive-practices action against BLU that ended in a September 2018 consent order requiring express consent before collecting communications or location.[2][4][5]
Company background
[edit | edit source]Adups was founded in 2012.[6] The FTC described it as a China-based company that offers advertising, data mining, and firmware over-the-air (FOTA) update services to mobile & Internet of Things connected devices.[2] FOTA software pushes operating-system and security updates to a phone over its network connection, which requires the vendor's code to run on the device with high privileges. Adups told SecurityWeek that its firmware was integrated in devices from over 400 mobile operators, semiconductor vendors, and device manufacturers, and that it had over 700 million active users worldwide.[1]
CyberScoop reported that Adups had a record of acting on users' phones without their knowledge before the 2016 disclosure, including a 2015 case in which the company was found installing apps on Micromax Android devices without permission.[6]
How the firmware worked
[edit | edit source]The Adups code shipped in the device's system partition as preinstalled software, the category commonly called bloatware when it cannot be removed. Because the two collecting apps were installed as system apps, the phone's owner could not disable them through the normal Android application controls, & standard antivirus tools running as ordinary apps could not remove them.[1][7] A buyer purchasing a BLU R1 HD from a retailer had no way to see the software, consent to its data collection, or uninstall it. The same preinstalled-firmware problem has appeared with other vendors' devices, including Lenovo's Android tablets.
The collection channel & the command channel were technically distinct. Kryptowire found that the personal-data transfer used multiple layers of encryption & was sent over secure web protocols (HTTPS) to a server in Shanghai.[1] Adups gave the same account, stating that it used multiple encryption layers and HTTPS in the transmitting process.[1] The separate command-fetch endpoint documented in the National Vulnerability Database used plain HTTP and was therefore open to a man-in-the-middle attack.[7]
Incidents
[edit | edit source]2016 Kryptowire discovery
[edit | edit source]In November 2016, Kryptowire reported that Adups firmware preinstalled on budget Android phones transmitted users' personal data to servers in China without consent.[1] The New York Times first reported the finding.[8] The data included the full contents of text messages, contact lists, call and text-message logs with full telephone numbers, real-time cellular tower location data, and lists of applications installed on each device.[2] Kryptowire found that the transmission occurred every 72 hours for text messages and call-log information, and every 24 hours for the other personal data.[1] The FTC's later complaint described both the 72-hour and 24-hour transmission intervals.[2]

The two apps responsible, com.adups.fota.sysoper and com.adups.fota, were system apps the user could not disable.[1] The most visible affected device was the BLU R1 HD, a phone the report singled out and one that sold for $50.[3] BLU Products confirmed that approximately 120,000 of its phones carried the Adups software and said it was being removed.[8] Amazon took the R1 HD off its website around the time of the disclosure.[3] ZTE stated that no ZTE devices sold in the United States had ever had the Adups software installed, & Huawei stated that the company named in the report was not on its list of approved suppliers and that it had never done business with it.[3]
Command execution backdoor and CVE-2016-10138
[edit | edit source]The National Vulnerability Database published CVE-2016-10138 on January 13, 2017, with a CVSS 3.0 base score of 7.8 (HIGH), covering the BLU Advance 5.0 and BLU R1 HD devices running Shanghai Adups software.[7] The com.adups.fota.sysoper app set the android:sharedUserId attribute to android.uid.system, which made it execute as the system user, & it exposed a broadcast receiver named com.adups.fota.sysoper.WriteCommandReceiver that any app on the device could interact with.[7] Through that receiver, a third-party app could tell the software to call a phone number, factory reset the device, take screenshots, record the screen as video, install applications, inject events, and read the Android log.[7]

A separate component, com.adups.fota.sysoper.TaskService, fetched commands from http://rebootv5.adsunflower.com/ps/fetch.do & executed them as the system user. Because that request was made over plain HTTP, the NVD recorded it as open to a man-in-the-middle attack.[7] The FTC's complaint described the same class of problem in its own terms, stating that the software carried vulnerabilities that made the devices susceptible to command-injection attacks by which an unknown third party could gain full access and, among other things, factory reset a device, take screenshots and video recordings of the screen, and install malicious applications.[2]
2017 finding of continued collection
[edit | edit source]On July 25, 2017, CyberScoop reported that Kryptowire researcher Ryan Johnson had found the Adups software still taking in sensitive data nearly a year after the original disclosure. The collection had been scaled back since 2016, Kryptowire said, but it continued and could be scaled back up with a single update.[6] BLU was still using Adups, & the firm still received data without permission, including the user's phone number, cell tower, device identifiers, and list of installed applications.[6] CyberScoop also reported that Adups had a command-and-control channel that could execute code on a user's phone as a system user.[6] Johnson described the reach of that capability in an interview:
The capability is there and that's certainly a capability I wouldn't be comfortable with... Having a foreign country have the power to execute arbitrary commands as the most privileged user other than root on the phone.
2018 FTC action against BLU
[edit | edit source]On April 30, 2018, the FTC announced a settlement with BLU Products & its co-owner and President Samuel Ohev-Zion over the Adups collection.[9] The Commission's two-count complaint alleged that BLU violated Section 5(a) of the Federal Trade Commission Act.[5] Count I alleged a deceptive representation about the disclosure of personal information: BLU had represented that it limited third-party disclosure of user data to what was necessary to perform services, when Adups in fact received data that was not needed for those services.[2] Count II alleged a deceptive representation about data security: BLU had claimed it used appropriate procedures to protect personal information.[2] The complaint stated that Adups obtained full administrative access and control of BLU's devices.[2] The Federal Trade Commission said the vote to issue the complaint and accept the proposed agreement was 2-0.[9]
The final consent order took effect after the public-comment period. On September 10, 2018, the FTC gave final approval on a 5-0 vote.[4] The order prohibits BLU & Ohev-Zion from misrepresenting how they protect the privacy & security of personal information, requires them to implement & maintain a comprehensive security program, and subjects BLU to third-party assessments of that program every two years for 20 years.[4] The analysis of the order added that before collecting or disclosing covered information, BLU must clearly and conspicuously disclose the categories of information collected, the third parties that receive it, and the purposes of the collection, and must obtain the consumer's affirmative express consent.[5]

2020 Lifeline phone finding
[edit | edit source]In January 2020, Malwarebytes Labs reported that the UMX U683CL, sold by Assurance Wireless by Virgin Mobile for $35 under the government-funded Lifeline program, shipped with an app that auto-installed other apps without user consent.[10] The app, named Wireless Update and the phone's only means of updating the operating system, was a variant of Adups; Malwarebytes detected it as Android/PUP.Riskware.Autoins.Fota.[10] Nathan Collier of Malwarebytes described the behavior:
From the moment you log into the mobile device, Wireless Update starts auto-installing apps. To repeat: There is no user consent collected to do so, no buttons to click to accept the installs, it just installs apps on its own.

See also
[edit | edit source]References
[edit | edit source]- ↑ 1.00 1.01 1.02 1.03 1.04 1.05 1.06 1.07 1.08 1.09 Kovacs, Eduard (2016-11-16). "Backdoor in Some Android Phones Sends Data to Server in China". SecurityWeek. Retrieved 2026-09-13.
- ↑ 2.00 2.01 2.02 2.03 2.04 2.05 2.06 2.07 2.08 2.09 Federal Trade Commission (2018-04-30). "Complaint, In the Matter of BLU Products, Inc., and Samuel Ohev-Zion" (PDF). Retrieved 2026-09-13.
- ↑ 3.0 3.1 3.2 3.3 3.4 Schoon, Ben (2016-11-15). "Some budget Android phones in the US reportedly affected by 'backdoor' which sent personal data to China". 9to5Google. Retrieved 2026-09-13.
- ↑ 4.0 4.1 4.2 4.3 Federal Trade Commission (2018-09-10). "FTC Gives Final Approval to Settlement with Phone Maker BLU". Retrieved 2026-09-13.
- ↑ 5.0 5.1 5.2 Federal Trade Commission (2018-04-30). "Analysis of Proposed Consent Order to Aid Public Comment, In the Matter of BLU Products, Inc" (PDF). Retrieved 2026-09-13.
- ↑ 6.0 6.1 6.2 6.3 6.4 6.5 O'Neill, Patrick Howell (2017-07-25). "Chinese tech firm continues to secretly siphon data from Android phones". CyberScoop. Retrieved 2026-09-13.
- ↑ 7.0 7.1 7.2 7.3 7.4 7.5 7.6 NIST National Vulnerability Database (2017-01-13). "CVE-2016-10138". Retrieved 2026-09-13.
- ↑ 8.0 8.1 Khandelwal, Swati (2016-11-16). "Pre-installed Backdoor On 700 Million Android Phones Sending Users' Data To China". The Hacker News. Retrieved 2026-09-13.
- ↑ 9.0 9.1 Federal Trade Commission (2018-04-30). "Mobile Phone Maker BLU Reaches Settlement with FTC over Deceptive Privacy and Data Security Claims". Retrieved 2026-09-13.
- ↑ 10.0 10.1 10.2 10.3 Collier, Nathan (2020-01-09). "United States government-funded phones come pre-installed with unremovable malware". Malwarebytes Labs. Retrieved 2026-09-13.