Xiaomi is currently the third-largest smartphone manufacturer worldwide.
They have personally unveiled this vulnerability to Xiaomi in January 2016.
All the applications with analytics package are vulnerable to remote code execution via the man-in-the-middle attack.

Therefore, the analytics package replaces itself with the attacker-supplied version via Androids DexClassLoader mechanism.

