According to a new investigation by Malwarebytes, hundreds of Android users may have the Adups backdoor active on their device.
Their discovery is related to the Adups case that concerned security experts in 2016. At that time, computer security firm Kryptowire detected a firmware code created by the Chinese company Adups that has the ability to collect a large amount of sensitive information from Android devices and send it to servers located in China. More specifically, the backdoor firmware was hidden in a built-in application named com.adups.fota (Firmware Over-The-Air) and could collect SMS messages, call history, address books, application lists and phone hardware identifiers. It was also able to install new applications or update existing ones. In total, 700 million devices, most of which were low-performance, were affected.
Although the problem was solved with various upgrades and fixes, a new version of Adups appeared that cannot be deleted or disabled by the user unless they have root privileges. It is located in the services com.adups.fota.sysoper or com.fw.upgrade.sysoper that run from the FWUpgradeProvider.apk application. The good news in this case is that this application appears in software from not-so-well-known mobile manufacturers and does not collect sensitive information but has the ability to install and upgrade applications.
So far, no malicious activity has been detected through this application, however, if you want to remove it, as mentioned above, you will have to root your device. Of course, this is not recommended as a solution as this creates other security holes in the phone that can cause more problems. Malwarebytes has published a guide on how to do this on the following site (https://forums.malwarebytes.com/topic/216616-disabling-adups-via-debloater-fwupgradeproviderapk/ ).

