Turning Citizens into Data Points: The Dark Side of Digital Surveillance
John Davies
Cybersecurity Writer at Malloc
Imagine a world where every action, every word, every choice is tracked — where your smartphone isn’t just a tool for convenience but a silent witness, feeding data to a system you can neither see nor challenge. This isn’t science fiction. For millions of people, it’s reality. Governments are increasingly using digital technology to monitor, influence, and control their citizens, turning them into little more than data points in a vast and opaque surveillance machine.
At the heart of this system lies the mobile phone. Once a symbol of personal freedom, it has become a powerful tool for authoritarian regimes. In today’s hyper-connected world, smartphones are essential to everyday life, providing governments with an unprecedented window into the social, familial, and personal lives of their citizens. With this access, regimes can push propaganda, manipulate public opinion, censor dissent, and even predict behavior.
China is a leading example of this new era of digital authoritarianism. Through apps like Xue Xi QiangGuo (Study Xi, Strong Nation) and Pinduoduo, the Chinese government has perfected the art of surveillance. The former is a mandatory app promoting party ideology while monitoring usage patterns, and the latter collects staggering amounts of user data under the guise of e-commerce. Together, they showcase how technology can be weaponized to shape entire societies, offering a chilling blueprint for other regimes looking to consolidate control.
The implications are profound. What starts as convenience — an app for shopping, a platform for education — can quickly become a tool for domination. Understanding these dynamics is critical, not just for those living under such systems, but for all of us navigating an increasingly digital and interconnected world.
Xue Xi QiangGuo App has a Backdoor
Background of Xue Xi QiangGuo App
The Xue Xi QiangGuo App, translated as ‘Study the Great Nation’ or ‘Study to Make China Strong,’ with the name XueXi being a pun that carries Chinese President Xi Jinping’s family name, is the official Chinese Communist Party propaganda app that was launched in 2019 and is heavily promoted as a way for Chinese citizens to study their great nation and prove their loyalty.
The app has news articles and videos about the CCP and Xi Jinping, and users earn points for reading articles, commenting, and completing quizzes, and they also appear on leaderboards. The app has over 100 million registered users, with millions of installs from the Apple App Store and 300 million installs from Huawei’s app store, and it is among the most downloaded apps in China due to the systematic pressure from the CCP to install and use the app. Daily interaction with the app is mandatory for party members, civil servants, and employees across various organizations, as points earned through the app impact job evaluation and salaries and determine professional success.
Xue Xi QiangGuo app gives backdoor access to CCP
The Xue Xi QiangGuo app has been accused of spying on its users, creating a mass surveillance system and violating the human rights of Chinese users.
An examination of the app code reveals its very unusual nature, as the app allows for the collection of vast amounts of data from users’ phones that the app does not require for its functionality and sends it back to the CCP.
The design of the app’s code is such that it thwarts attempts to dissect its functionality, but based on an examination of the app code by researchers, installing the app amounts to a backdoor on the phone that gives the ability to run arbitrary commands with ‘super-user’ privileges. It amounts to giving administrator-level access to the users’ phones, and such code can be considered malicious, as the app would have the ability to modify code, install any software, modify files and data, and log keystrokes.
The app can retrieve user files, photos, and videos, read every message, browse contacts, see internet history, activate the audio recorder inside the device, take photos and videos, transmit user location, dial phone numbers, and retrieve information from 960 other applications of all types, such as shopping, travel, and messaging platforms, connect to Wi-Fi, and turn on the flashlight.
The app collects and sends detailed log reports on a daily basis, containing a wealth of user data and app activity. To use the app, users must sign up with their real names and cellphone numbers, and as all the phone numbers are connected to a national identity card number in China, it provides the Chinese government complete information about the whereabouts of its citizens and enables it to create and maintain their detailed profiles.
When using the app, depending on the features and third-party tools users want to use, they will also have to hand over their fingerprints and ID numbers. The app is linked to Alibaba, as the Chinese e-commerce giant acknowledged that the Xue Xi QiangGuo app was built using its subsidiary and instant messaging service DingTalk’s software, and it might be complicit in the intrusive nature and weak security of the app. The app is part of the Chinese expansion of its propaganda and surveillance state ecosystem, which aims to influence and control the day-to-day life of its citizens.
Pinduoduo App contains malware
Background of Pinduoduo App
Pinduoduo was founded in 2015 in Shanghai by a former Google employee, Colin Huang. It registered steady growth by offering huge discounts to people in low-income rural households.
Today, the app has a user base that accounts for 75% of China’s population. Temu is the sister app of Pinduoduo, and both are owned by Nasdaq-listed PDD, a multinational company with roots in China. Temu from PDD, which aims at expansion and dominance in the global markets, was only founded in 2022 in Boston, Massachusetts. It has registered an exceptionally high growth rate, going from 5.8 million US users in October 2022 to 104.2 million in April 2023, but it has been marred by controversies including worker exploitation, data theft accusations, intellectual property infringement, and poor quality/counterfeit products.
Temu has been the most downloaded app on Google and Apple Play Store, with a 42% market share in the US alone. Both Pinduoduo and Temu rely on aggressive marketing strategies, very persistent notifications, and tracking user activity to sell their products by offering steep app-exclusive discounts.
Malware in Pinduoduo App
According to CNN, after Pinduoduo’s growth began to slow down by the end of 2018, in 2020, the company set up a team of about 100 engineers and product managers to dig for vulnerabilities in Android phones and develop ways to exploit them to heavily track its users and turn that into profit. By collecting expansive data on user activities and using its improved machine learning algorithms, PDD and Pinduoduo were able to create comprehensive profiles of its users’ habits, engagements, interests, and preferences, thereby offering more personalized notifications and ads.
Malware in the Pinduoduo app was found by an Israeli cybersecurity firm and later confirmed by a Russia-based cybersecurity firm. The code was designed to achieve “privilege escalation” by exploiting the CVE-2023–20963 Android vulnerability. The app used these privileges to download malicious code and run it within a privileged environment. The app deployed a method that allowed it to push updates without an app store review process, which is meant to detect malicious applications. Researchers also identified plug-ins intended to obscure potentially malicious components by hiding them under legitimate system file names. Pinduoduo’s malware is said to have exploited about 50 Android system vulnerabilities and targeted different Android-based operating systems, including those used by Samsung, Huawei, Xiaomi, and Oppo. The exploits were tailor-made for customized parts known as the original equipment manufacturer (OEM) code, which is less often audited than the Android Open Source Project (AOSP). The malicious Pinduoduo app includes functionality that allows the app to be installed covertly with no ability to be uninstalled, uninstalling competitor apps, and stealing private data from users. The app also has the ability to access Wi-Fi and location information, track usage stats of installed apps, parse notifications, and add widgets to the infected devices.
Users who downloaded the app from the Apple App Store and Google Play Store were not affected, while those who downloaded the apps from third-party markets, including all the Chinese users and millions of users outside China, were impacted.
In March 2023, after malware was found in off-play versions of the Pinduoduo app, Google suspended the app from the Google Play Store, but its sister app Temu remains available.
While there is no direct evidence that Pinduoduo and PDD are sharing data of Chinese users or users outside of China with the Chinese government, considering the leverage that China has over domestic companies, it is a significant concern. The National Intelligence Law, which was passed in China in 2017, requires organizations and citizens to support, assist, and cooperate with state intelligence work. There are other laws such as the Cybersecurity Law (2017) and Security Law (2021), which form a framework and give the Chinese government broad powers to obtain data from companies operating within China. While Pinduoduo’s sister app Temu, meant for global markets, has not been implicated and has not been removed, it has raised suspicion and dangers of apps like Temu and TikTok, especially in the U.S.
The Bottom Line
The threat of mass surveillance through popular apps is real and growing. Governments and private industries exploit these apps to turn citizens into data points, using the collected information to shape social dynamics, influence individual behavior, and consolidate control. While most internet traffic today is encrypted, direct access to user devices via malware-prone applications allows for invasive data collection and activity monitoring, bypassing encryption safeguards.
Our app, Malloc, provides a solution to counter these threats. Available on iOS and Android, Malloc offers a suite of privacy-focused features to protect your digital life. These include tools to identify and remove malware (like the spyware linked to apps such as Pinduoduo), block trackers, safeguard internet traffic through VPN services, and monitor your microphone and camera to detect unauthorized eavesdropping by apps like Xue Xi QiangGuo. With Malloc, you can take back control of your privacy and stay protected from the growing risks of digital surveillance.
For those who face elevated risk, our high-risk individuals page explains how Malloc supports them.
References
- China’s popular education app is a ‘surveillance device in your pocket,’ advocacy group says — ABC News
- Xi’s ideology app has ‘backdoor’ that could let Beijing snoop: Report — CNBC
- China propaganda app fraught with security concerns, may be studying users back: Report — The Straits Times
- Chinese app on Xi Jinping’s ideology allows data access to 100 million users’ phones: Report — The Straits Times
- China’s Apps That Turn Citizens Into Data Points — Monitor
- Android app from China executed 0-day exploit on millions of devices — Ars Technica
- Pinduoduo App Malware Detailed by Cybersecurity Researchers at Kaspersky — Bloomberg
- ‘I’ve never seen anything like this:’ One of China’s most popular apps has the ability to spy on its users, say experts — CNN Business
Relevant tags:
Published on Medium