Proprietary · · 684 days

Adups FOTA collected phone data

BLU devices shipped with ADUPS FOTA software that collected text messages, call logs, contacts, location, and app data. The update provider became a built-in surveillance channel.

ADUPS was hired to do firmware-over-the-air updates. BLU directed manufacturers to preinstall ADUPS software on phones sold through major retailers. The update channel was trusted by design: it lived in the system image and did work normal users could not inspect or remove.

Kryptowire found the behavior on a BLU R1 HD in 2016. The ADUPS packages com.adups.fota and com.adups.fota.sysoper collected the contents of text messages, call logs, contacts, location, device identifiers, and installed-application data. The collection ran silently and sent data to ADUPS infrastructure in China.

The FTC later alleged that this was not needed for updates. Its complaint said ADUPS transmitted text messages every 72 hours and real-time location data every 24 hours, and that BLU failed to vet and oversee the service provider. BLU publicly said ADUPS had updated its software after the report, but the FTC alleged ADUPS continued to operate on older devices without adequate oversight.

The case sits at the boundary of supply chain and surveillance. The software was not a rogue typo package or malware added after shipment. It was an official third-party firmware component distributed through device manufacturing and update paths. That made the blast radius large, quiet, and hard for users to correct.