A Dutch Computer Science student discovered the presence of a backdoor that could allow an attacker to silently install any app on the phone. Thijs Broenink, who analyzed his Xiaomi mobile device, discovered a mysterious pre-installed app, dubbed AnalyticsCore.apk, that runs 247 in the background and it is impossible to remove. The student hasnt discovered the real purpose of the AnalyticsCore app, it sounds like a sort of backdoor that opens million Xiaomi devices to cyber attack.”]
Source: http://securityaffairs.co/wordpress/51296/mobile-2/xiaomi-backdoor.html