Sony Xperia Smartphones with Android 4.4.2 or 4.4.4, sending Data to China-based servers

Status
Not open for further replies.

Rus Anca

Level 25
Thread author
Verified
Jun 18, 2014
1,403
Sony Xperia Smartphones with Android 4.4.2 or 4.4.4 KitKat versions have been allegedly found to send user data back to China-based servers of Baidu.

Are you running a Sony Xperia handset with KitKat firmware? Then you may want to check your internal storage for a folder called “Baidu”. It appears that certain Android 4.4.2 or 4.4.4 firmware contains this folder, which is part of the stock build. The folder cannot be deleted, even if you try it will reappear once again shortly after.
Strangely, the folder appears to be created by Sony’s “my Xperia” service each time a network connection is switched on. Unfortunately, unticking the app from Device Administrators does not solve the issue. Neither does starting the phone in Safe Mode. The only temporary workaround is to block the MyXperia app from starting by using an “adb shell” command.

What is quite concerning regarding this development, is that through this process, the phone is making several pings to Chinese servers. Yet, we don’t know what information is being communicated. Sony recently escalated this to its internal teams and recently outlined the following message on its support forum:

This folder will be removed in future software updates for the phone. Until then I can only advise that you delete it manually after a reboot if you want to remove it. It’s safe to just delete it.

This is obviously a very serious issue, we noticed the “Baidu” folder on both new Xperia Z3 and Xperia Z3 Compact handsets. Sony needs to communicate how this app appeared in the first place and to reveal what information is being gathered. At least, Sony has a fix on the way. As soon as we hear any more we’ll let you know.


A “baidu” folder appears in a number of stock Sony Xperia KitKat firmware builds

2014-10-28-20.20.18-315x560.png


This folder is connected to Sony’s “my Xperia” location service and is regularly pinging with Chinese servers


Xpeira-Baidu_1-315x559.png
Xpeira-Baidu_2-315x559.png



Source(Xperia Blog):http://www.xperiablog.net/2014/10/28/select-sony-xperia-firmware-appears-to-contain-baidu-spyware/
 
Last edited:

souhrid

Level 5
Jun 29, 2012
226
Well I'm doomed now, seriously sony??:mad::mad:, i have noticed before the bauidu folder in my storage although i had no bauidu apps installed. I searched xda forums and realised that some other people have also( different manufacturer but I'm not so sure about it) reported the same problem there. Let me dig deeper into it.But I'm really pissed about sony right now :mad::mad:
Update: Nexus phone users have also reported about bauidu folder in their storage. This appears to be created by ES file explorer
Link: http://forum.xda-developers.com/google-nexus-5/help/baidu-folder-t2545185
 
Last edited:

Petrovic

Level 64
Verified
Honorary Member
Top Poster
Well-known
Apr 25, 2013
5,355
Sony Xperia Smartphones with Android 4.4.2 or 4.4.4 KitKat versions have been allegedly found to send user data back to China-based servers of Baidu, according to a post from XPERIA Blog.

The alleged spyware was found after users reported a strange folder named “Baidu.” The folder appeared automatically with no user permission and it automatically reappears even if it is deleted with admin rights or from Safe Mode.



“Just unpacked my Sony Z3 compact, haven’t installed a single app and its connecting to China,” a Reddit usersaid. “I am not so concerned about the folder itself but my phone now has a constant connection to an IP address in Beijing which I am not too happy about.”

At first sight, the “my Xperia” service seems to create the Baidu folder every time it connects to its servers.

Also, the folder’s contents have been reported to send pings to a server in China.

Other users alleged that the Baidu folder helps the Chinese government spy on users.

Among alleged permissions, the spyware can read status and device identity, make videos and take pictures, get location data, read memory contents and change system settings — all without user consent.



“This folder will be removed in future software updates for the phone [...] i can only advise that you delete it manually after a reboot if you want to remove it,” said one Sony support representative on their mobile support forum.

“The MyXperia app supports both Google Cloud Messaging service and the Baidu Push Notification framework, as do many third party apps, to make sure we can support our China customers as well as those in the rest of the world,” the support representative replied later on.

“The IP activity you are seeing is just linked to Baidu’s push notification system, which is an expected behaviour for this application.”
 

Cch123

Level 7
Verified
May 6, 2014
335
I don't think its a Baidu spyware. Sony is a Japanese company, and I don't think they will ever spy for the Chinese.
 
  • Like
Reactions: souhrid
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top