Security firm: China’s Coolpad is intentionally giving its phones a severe security flaw

Researchers at Palo Alto Networks have released a new report which says that many of the phones manufactured by Chinese handset maker Coolpad are being shipped with a serious security flaw. According to the report, most of the Coolpad phones researchers tested contained a backdoor (they call it “CoolReaper”) that allowed the phone’s software to autonomously do things like:
- Download and install/uninstall apps
- Delete user data
- Send, receive, or spoof phone calls and text messages
- Upload user data to Coolpad servers
In a blog post about the report, Palo Alto Networks (which sells security products aimed at protecting users from these sorts of issues and thus is not necessarily impartial) writes:
We expect device manufacturers to install software on top of Android that provides additional functionality and customization, but CoolReaper does not fall into that category. Some mobile carriers install applications that gather usage statistics and other data on how their devices are performing. CoolReaper goes well beyond this type of data collection and acts as a true backdoor into Coolpad devices.
Coolpad customers in China have reported installation of unwanted applications and push-notification advertisements coming from the backdoor. Complaints about this behavior have been ignored by Coolpad or deleted.
The news comes at an interesting time, having been released on the same day that Chinese security firm Qihoo 360’s US$400 million investment in a joint venture with Coolpad was confirmed. Qihoo has previously been accused of misleading users in its own ways, and to some this news may suggest that the new Qihoo-Coolpad joint venture is not to be trusted.
More importantly, though, Qihoo is a web security company: its mobile and PC-based security suites are the centerpiece of its product line. One has to assume that as part of the due diligence for the Coolpad investment, Qihoo’s security experts took a look at Coolpad’s products, so what happened? Did they simply miss this apparently-gaping backdoor? That would be pretty embarrassing for a security company. Did they find it and decide to go through with the deal anyway? That doesn’t look good either.
As of this writing, the news of the CoolPad backdoor vulnerability doesn’t seem to have made a big splash in China. If it continues to fly under the radar – or if the Palo Alto Networks report can be convincingly discredited – it could have no effect at all. But if it does start to get attention, it could be a serious blow to Coolpad and Qihoo 360’s new venture before they’ve even gotten the new company off the ground.
We have contacted both Coolpad and Qihoo 360 for comment on this story, and will update this post if we hear back.
(Source: Palo Alto Networks blog)
Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.




