Loading recent posts...

Mar 5, 2015

Xiaomi Mi4 LTE Sold with Dodgy Apps Pre-Installed, Rooted

The highly popular Mi4 LTE Android smartphone produced by Xiaomi has been found to be shipped from the factory with serious security risks that range from pre-loaded risky apps to root and a shady flavor of the underlying Android operating system.

The demand for Xiaomi devices has grown lately and the Mi4 LTE smartphone seems to attract a large number of customers. In mid-February, 25,000 units sold out in 15 seconds on India’s online retailer Flipkart.

Apps detected as malware found in default configuration
However, it appears that at least the versions sold in China are filled with enough security problems to make a customer think twice about purchasing it. Following an initial analysis, security researchers at mobile data security company Bluebox discovered that a unit they bought in China came pre-installed with a set of risky apps, some labeled as malware by antivirus solutions. One potentially dangerous app was Yt Service, whose purpose is to integrate an adware service called DarthPusher. An app pushing advertisements would not generally ring the alarm, but Bluebox says that Yt Service created the false impression that it was developed by Google, its developer package being named “com.google.hfapservice.”

“In other words, it tricks users into believing it's a ‘safe’ app vetted by Google,” Bluebox said in a blog post on Thursday. Other shady apps present on the device were PhoneGuardService (com.egame.tonyCore.feicheng), which is detected by some antivirus solutions as a Trojan, and SMSreg, marked as malware in some cases. In total, the researchers say they’ve found six suspicious apps whose behavior is similar to malware, spyware or adware.

Murky version of OS installed
Using Trustable, their mobile security assessment tool, it was discovered that the analyzed Mi4 unit was vulnerable to Masterkey, FakeID, and Towelroot (Linux futex), basically all glitches the utility scans for, except Heartbleed. Apart from this, the device was rooted and USB debugging mode was turned on. Bluebox reported that the “su” application needed a security provider in order to work on the device; but even so, the risk is still present as cybercriminals could leverage one of the vulnerabilities and take advantage of the root to take complete control over the device. During the analysis, the researchers observed that although the reported version of the operating system was Android 4.4.4 (Kitkat), it appeared to include elements from earlier releases.

One example was the USB debugging icon, which was taken from Jelly Bean (Android 4.1-4.3.1). Furthermore, some of the vulnerabilities uncovered were specific to earlier versions of Android and have been fixed in Kitkat. The results of the investigation do not make clear if the OS version used was designed just for testing purposes or it was intended as a consumer release.

Smartphone passes the legitimacy test
Forked Android versions are far from being rare, as a study from ABI Research revealed that in Q4 2014 alone, 40% of all Android shipments were custom variants, which oftentimes come with security risks due to insufficient assessment. Considering these findings, the researchers thought that the phone they got could have actually been a fake, so they put the theory to the test through various methods, including a utility from Xiaomi specifically created for this purpose. The device passed the legitimacy test. Bluebox disclosed its results to Xiaomi but the smartphone manufacturer did not reply, so the report was made public.

Xiaomi Mi4 LTE
Image credits to Xiaomi

Trustable score for the analyzed Mi4 LTE from Xiaomi
Image credits to Bluebox


Post a Comment

Twitter Delicious Facebook Digg Stumbleupon Favorites More

Design by Free WordPress Themes | Bloggerized by Lasantha - Premium Blogger Themes | coupon codes