Manufacturer’s Backdoor Found on Popular Chinese Android Smartphone
Summary
A popular Android smartphone sold primarily in China and Taiwan but also available worldwide, contains a backdoor from the manufacturer that is being used to push pop-up advertisements and install apps without users’ consent. The Coolpad devices, however, are ripe for much more malicious abuse, researchers at Palo Alto Networks said today, especially after the discovery of a vulnerability in the backend management interface that exposed the backdoor’s control system. Ryan Olson, intelligence director at Palo Alto, said the CoolReaper backdoor not only connects to a number of command and control servers, but is also capable of downloading, installing and activating any Android application without the user’s permission. “We’ve never seen something with this much capability [from a manufacturer],” Olson said, pointing out that CoolReaper even exceeds Carrier IQ’s software that was found to be recording keystrokes in addition to gathering device and usage information. “The fact that the CoolReaper management interface could be hijacked by malicious attackers through a vulnerability helps highlight the danger of pre-installing this type of backdoor program,” Palo Alto said in its report.